[
https://issues.apache.org/jira/browse/RANGER-5705?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Yunye Zhang updated RANGER-5705:
--------------------------------
Description:
Introduce a new, side-car Maven module — *{*}`ranger-copilot`{*}* — that turns
Apache Ranger into an assisted-governance platform. Copilot runs as an
independent Spring Boot 3.x service (no changes to `security-admin`), reads
policy metadata via Ranger REST, reads audit records through a pluggable
*{*}`AuditSource`{*}* abstraction with two implementations — direct
Elasticsearch (default, required for aggregation-based baselines) and
Ranger REST (`/service/xaudit/access_audit`) fallback for deployments
without direct ES access — and combines *{*}deterministic detectors{*}* with
an *{*}LLM reasoning layer{*}* to produce explainable, auditable, revertible
suggestions. Every AI output lands in a `PENDING` suggestion queue and is
only applied to Ranger after an administrator approves it — with a full
before/after policy snapshot and one-click rollback.
The Epic delivers *{*}six child issues{*}* — one bootstrap plus five feature
sub-tasks — and can be merged incrementally: each sub-task carries an
independently-testable MVP and is gated behind a feature flag. The six
child issues are:
|Child issue|Scope|
| | |
|SUB-00|*{*}Bootstrap{*}* — module skeleton, `LlmClient` / `AuditSource` /
`PasswordDecoder` SPIs, `SuggestionWorkflowService` state machine, DDL.|
|SUB-01|*{*}Audit Intelligence{*}* — ES-backed anomaly detection + LLM
explanation.|
|SUB-02|*{*}Policy Recommendation{*}* — least-privilege mining from audit
aggregations.|
|SUB-03|*{*}Policy Governance{*}* — redundancy / conflict / stale /
risky-pattern detection.|
|SUB-04|*{*}NL2Policy{*}* — natural-language authoring via LLM → JSON Schema →
Ranger `dryRun`.|
|SUB-05|*{*}Automated Response{*}* — Webhook / mail / ticketing adapters on
confidence-gated events.|
was:
Introduce a new, side-car Maven module — **`ranger-copilot`** — that turns
Apache Ranger into an assisted-governance platform. Copilot runs as an
independent Spring Boot 3.x service (no changes to `security-admin`), reads
policy metadata via Ranger REST, reads audit records through a pluggable
**`AuditSource`** abstraction with two implementations — direct
Elasticsearch (default, required for aggregation-based baselines) and
Ranger REST (`/service/xaudit/access_audit`) fallback for deployments
without direct ES access — and combines **deterministic detectors** with
an **LLM reasoning layer** to produce explainable, auditable, revertible
suggestions. Every AI output lands in a `PENDING` suggestion queue and is
only applied to Ranger after an administrator approves it — with a full
before/after policy snapshot and one-click rollback.
The Epic delivers **six child issues** — one bootstrap plus five feature
sub-tasks — and can be merged incrementally: each sub-task carries an
independently-testable MVP and is gated behind a feature flag. The six
child issues are:
| Child issue | Scope |
|-------------|----------------------------------------------------------------------------------------------------------------------------------------------|
| SUB-00 | **Bootstrap** — module skeleton, `LlmClient` / `AuditSource` /
`PasswordDecoder` SPIs, `SuggestionWorkflowService` state machine, DDL. |
| SUB-01 | **Audit Intelligence** — ES-backed anomaly detection + LLM
explanation. |
| SUB-02 | **Policy Recommendation** — least-privilege mining from audit
aggregations. |
| SUB-03 | **Policy Governance** — redundancy / conflict / stale /
risky-pattern detection. |
| SUB-04 | **NL2Policy** — natural-language authoring via LLM → JSON Schema →
Ranger `dryRun`. |
| SUB-05 | **Automated Response** — Webhook / mail / ticketing adapters on
confidence-gated events. |
> Ranger Copilot — Governance-Grade AI Assistant for Apache Ranger
> ----------------------------------------------------------------
>
> Key: RANGER-5705
> URL: https://issues.apache.org/jira/browse/RANGER-5705
> Project: Ranger
> Issue Type: New Feature
> Components: Ranger
> Affects Versions: 2.6.0
> Reporter: Yunye Zhang
> Assignee: Yunye Zhang
> Priority: Major
> Original Estimate: 504h
> Remaining Estimate: 504h
>
> Introduce a new, side-car Maven module — *{*}`ranger-copilot`{*}* — that turns
> Apache Ranger into an assisted-governance platform. Copilot runs as an
> independent Spring Boot 3.x service (no changes to `security-admin`), reads
> policy metadata via Ranger REST, reads audit records through a pluggable
> *{*}`AuditSource`{*}* abstraction with two implementations — direct
> Elasticsearch (default, required for aggregation-based baselines) and
> Ranger REST (`/service/xaudit/access_audit`) fallback for deployments
> without direct ES access — and combines *{*}deterministic detectors{*}* with
> an *{*}LLM reasoning layer{*}* to produce explainable, auditable, revertible
> suggestions. Every AI output lands in a `PENDING` suggestion queue and is
> only applied to Ranger after an administrator approves it — with a full
> before/after policy snapshot and one-click rollback.
> The Epic delivers *{*}six child issues{*}* — one bootstrap plus five feature
> sub-tasks — and can be merged incrementally: each sub-task carries an
> independently-testable MVP and is gated behind a feature flag. The six
> child issues are:
> |Child issue|Scope|
> | | |
> |SUB-00|*{*}Bootstrap{*}* — module skeleton, `LlmClient` / `AuditSource` /
> `PasswordDecoder` SPIs, `SuggestionWorkflowService` state machine, DDL.|
> |SUB-01|*{*}Audit Intelligence{*}* — ES-backed anomaly detection + LLM
> explanation.|
> |SUB-02|*{*}Policy Recommendation{*}* — least-privilege mining from audit
> aggregations.|
> |SUB-03|*{*}Policy Governance{*}* — redundancy / conflict / stale /
> risky-pattern detection.|
> |SUB-04|*{*}NL2Policy{*}* — natural-language authoring via LLM → JSON Schema
> → Ranger `dryRun`.|
> |SUB-05|*{*}Automated Response{*}* — Webhook / mail / ticketing adapters on
> confidence-gated events.|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)