manish-m-pillai-ksolves opened a new pull request, #4225: URL: https://github.com/apache/ambari/pull/4225
## Summary Adds an in-process periodic LDAP user/group sync to `ambari-server`, removing the need for external cron jobs holding Ambari admin credentials. Resolves [AMBARI-24045](https://issues.apache.org/jira/browse/AMBARI-24045). Disabled by default. ## Why Not Cron? Running `sync_ldap()` via external cron requires `--ldap-sync-admin-name` and `--ldap-sync-admin-password` (`ambari-server.py:621,627`), exposing admin credentials in crontabs, scripts, or `ps` output. Moving sync in-process eliminates this risk: the scheduler calls the controller directly without HTTP hops, credentials, or local TLS trust setup. This follows Ambari's existing pattern used by services like `AmbariServerAlertService` and `MetricsRetrievalService`. ## Implementation Details * **`LdapSyncScheduler` (New):** A Guava `AbstractScheduledService` annotated with `@AmbariService`. Auto-registered via classpath scanning (`ControllerModule:580,602-619`) with no wiring changes to `AmbariServer.java`. * **Execution Flow:** 1. Re-reads configuration; returns early if disabled (`ldap.sync.auto.enabled`). 2. Constructs `LdapSyncRequest` for users/groups. 3. Invokes `AmbariManagementController.synchronizeLdapUsersAndGroups()` (thread-safe, shared with the REST API). 4. Logs batch sync results (`LdapBatchDto`). * **Fixed Delay:** Uses `Scheduler.newFixedDelaySchedule` so long-running syncs never overlap. * **`Configuration`:** Added 5 new properties with `@Markdown` and fallback validation. ## Configuration | Property | Default | Re-read per Tick? | |---|---|---| | `ldap.sync.auto.enabled` | `false` | Yes | | `ldap.sync.auto.interval.minutes` | `60` | No (Requires Restart) | | `ldap.sync.auto.type` | `existing` | Yes (`existing` \| `all`) | | `ldap.sync.auto.initial.delay.minutes` | `5` | No (Requires Restart) | | `ldap.sync.auto.post.process.existing.users` | `false` | Yes | ## Resiliency & Compatibility * **Error Handling:** Unrecognized types fall back to `existing`. Invalid numeric intervals fall back to defaults. Exceptions during sync are caught and logged to prevent terminating the Guava service loop. * **Compatibility:** Fully backwards-compatible. Disabled by default; existing CLI commands (`sync-ldap`), REST endpoints (`/api/v1/ldap_sync_events`), and external cron jobs continue to function. Requires no DB schema changes or upgrade catalogs. ## Testing Ran targeted unit tests: ```bash mvn -pl ambari-server -Dtest=LdapSyncSchedulerTest,ConfigurationTest test ``` * **`LdapSyncSchedulerTest` (7 tests):** Verified disabled state, fallback logic (`type=all`, invalid types), error handling, and parameter pass-through. * **`ConfigurationTest` (+3 tests):** Verified invalid number fallbacks, custom properties, and secure defaults. * **Negative Control:** Confirmed scheduler tests fail with `NoSuchMethodError` against unmodified `Configuration.java`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
