manish-m-pillai-ksolves opened a new pull request, #4225:
URL: https://github.com/apache/ambari/pull/4225

   ## Summary
   
   Adds an in-process periodic LDAP user/group sync to `ambari-server`, 
removing the need for external cron jobs holding Ambari admin credentials.
   
   Resolves [AMBARI-24045](https://issues.apache.org/jira/browse/AMBARI-24045). 
Disabled by default.
   
   
   ## Why Not Cron?
   
   Running `sync_ldap()` via external cron requires `--ldap-sync-admin-name` 
and `--ldap-sync-admin-password` (`ambari-server.py:621,627`), exposing admin 
credentials in crontabs, scripts, or `ps` output. 
   
   Moving sync in-process eliminates this risk: the scheduler calls the 
controller directly without HTTP hops, credentials, or local TLS trust setup. 
This follows Ambari's existing pattern used by services like 
`AmbariServerAlertService` and `MetricsRetrievalService`.
   
   
   ## Implementation Details
   
   * **`LdapSyncScheduler` (New):** A Guava `AbstractScheduledService` 
annotated with `@AmbariService`. Auto-registered via classpath scanning 
(`ControllerModule:580,602-619`) with no wiring changes to `AmbariServer.java`.
   * **Execution Flow:**
     1. Re-reads configuration; returns early if disabled 
(`ldap.sync.auto.enabled`).
     2. Constructs `LdapSyncRequest` for users/groups.
     3. Invokes `AmbariManagementController.synchronizeLdapUsersAndGroups()` 
(thread-safe, shared with the REST API).
     4. Logs batch sync results (`LdapBatchDto`).
   * **Fixed Delay:** Uses `Scheduler.newFixedDelaySchedule` so long-running 
syncs never overlap.
   * **`Configuration`:** Added 5 new properties with `@Markdown` and fallback 
validation.
   
   
   ## Configuration
   
   | Property | Default | Re-read per Tick? |
   |---|---|---|
   | `ldap.sync.auto.enabled` | `false` | Yes |
   | `ldap.sync.auto.interval.minutes` | `60` | No (Requires Restart) |
   | `ldap.sync.auto.type` | `existing` | Yes (`existing` \| `all`) |
   | `ldap.sync.auto.initial.delay.minutes` | `5` | No (Requires Restart) |
   | `ldap.sync.auto.post.process.existing.users` | `false` | Yes |
   
   
   
   ## Resiliency & Compatibility
   
   * **Error Handling:** Unrecognized types fall back to `existing`. Invalid 
numeric intervals fall back to defaults. Exceptions during sync are caught and 
logged to prevent terminating the Guava service loop.
   * **Compatibility:** Fully backwards-compatible. Disabled by default; 
existing CLI commands (`sync-ldap`), REST endpoints 
(`/api/v1/ldap_sync_events`), and external cron jobs continue to function. 
Requires no DB schema changes or upgrade catalogs.
   
   
   
   ## Testing
   
   Ran targeted unit tests:
   
   ```bash
   mvn -pl ambari-server -Dtest=LdapSyncSchedulerTest,ConfigurationTest test
   ```
   
   * **`LdapSyncSchedulerTest` (7 tests):** Verified disabled state, fallback 
logic (`type=all`, invalid types), error handling, and parameter pass-through.
   * **`ConfigurationTest` (+3 tests):** Verified invalid number fallbacks, 
custom properties, and secure defaults.
   * **Negative Control:** Confirmed scheduler tests fail with 
`NoSuchMethodError` against unmodified `Configuration.java`.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to