[
https://issues.apache.org/jira/browse/RANGER-5705?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Yunye Zhang updated RANGER-5705:
--------------------------------
Description:
Introduce a new, side-car Maven module — {*}{{*}}`ranger-copilot`{{*}}{*} —
that turns
Apache Ranger into an assisted-governance platform. Copilot runs as an
independent Spring Boot 3.x service (no changes to `security-admin`), reads
policy metadata via Ranger REST, reads audit records through a pluggable
{*}{{*}}`AuditSource`{{*}}{*} abstraction with two implementations — direct
Elasticsearch (default, required for aggregation-based baselines) and
Ranger REST (`/service/xaudit/access_audit`) fallback for deployments
without direct ES access — and combines {*}{{*}}deterministic detectors{{*}}{*}
with
an {*}{{*}}LLM reasoning layer{{*}}{*} to produce explainable, auditable,
revertible
suggestions. Every AI output lands in a `PENDING` suggestion queue and is
only applied to Ranger after an administrator approves it — with a full
before/after policy snapshot and one-click rollback.
The Epic delivers {*}{{*}}six child issues{{*}}{*} — one bootstrap plus five
feature
sub-tasks — and can be merged incrementally: each sub-task carries an
independently-testable MVP and is gated behind a feature flag. The six
child issues are:
|Child issue|Scope|
|SUB-00|*Bootstrap* — module skeleton, `LlmClient` / `AuditSource` /
`PasswordDecoder` SPIs, `SuggestionWorkflowService` state machine, DDL.|
|SUB-01|*Audit Intelligence* — ES-backed anomaly detection + LLM explanation.|
|SUB-02|*Policy Recommendation* — least-privilege mining from audit
aggregations.|
|SUB-03|*Policy Governance* — redundancy / conflict / stale / risky-pattern
detection.|
|SUB-04|*NL2Policy* — natural-language authoring via LLM → JSON Schema → Ranger
`dryRun`.|
|SUB-05|*Automated Response* — Webhook / mail / ticketing adapters on
confidence-gated events.|
was:
Introduce a new, side-car Maven module — *{*}`ranger-copilot`{*}* — that turns
Apache Ranger into an assisted-governance platform. Copilot runs as an
independent Spring Boot 3.x service (no changes to `security-admin`), reads
policy metadata via Ranger REST, reads audit records through a pluggable
*{*}`AuditSource`{*}* abstraction with two implementations — direct
Elasticsearch (default, required for aggregation-based baselines) and
Ranger REST (`/service/xaudit/access_audit`) fallback for deployments
without direct ES access — and combines *{*}deterministic detectors{*}* with
an *{*}LLM reasoning layer{*}* to produce explainable, auditable, revertible
suggestions. Every AI output lands in a `PENDING` suggestion queue and is
only applied to Ranger after an administrator approves it — with a full
before/after policy snapshot and one-click rollback.
The Epic delivers *{*}six child issues{*}* — one bootstrap plus five feature
sub-tasks — and can be merged incrementally: each sub-task carries an
independently-testable MVP and is gated behind a feature flag. The six
child issues are:
|Child issue|Scope|
| | |
|SUB-00|*{*}Bootstrap{*}* — module skeleton, `LlmClient` / `AuditSource` /
`PasswordDecoder` SPIs, `SuggestionWorkflowService` state machine, DDL.|
|SUB-01|*{*}Audit Intelligence{*}* — ES-backed anomaly detection + LLM
explanation.|
|SUB-02|*{*}Policy Recommendation{*}* — least-privilege mining from audit
aggregations.|
|SUB-03|*{*}Policy Governance{*}* — redundancy / conflict / stale /
risky-pattern detection.|
|SUB-04|*{*}NL2Policy{*}* — natural-language authoring via LLM → JSON Schema →
Ranger `dryRun`.|
|SUB-05|*{*}Automated Response{*}* — Webhook / mail / ticketing adapters on
confidence-gated events.|
> Ranger Copilot — Governance-Grade AI Assistant for Apache Ranger
> ----------------------------------------------------------------
>
> Key: RANGER-5705
> URL: https://issues.apache.org/jira/browse/RANGER-5705
> Project: Ranger
> Issue Type: New Feature
> Components: Ranger
> Affects Versions: 2.6.0
> Reporter: Yunye Zhang
> Assignee: Yunye Zhang
> Priority: Major
> Original Estimate: 504h
> Remaining Estimate: 504h
>
> Introduce a new, side-car Maven module — {*}{{*}}`ranger-copilot`{{*}}{*} —
> that turns
> Apache Ranger into an assisted-governance platform. Copilot runs as an
> independent Spring Boot 3.x service (no changes to `security-admin`), reads
> policy metadata via Ranger REST, reads audit records through a pluggable
> {*}{{*}}`AuditSource`{{*}}{*} abstraction with two implementations — direct
> Elasticsearch (default, required for aggregation-based baselines) and
> Ranger REST (`/service/xaudit/access_audit`) fallback for deployments
> without direct ES access — and combines {*}{{*}}deterministic
> detectors{{*}}{*} with
> an {*}{{*}}LLM reasoning layer{{*}}{*} to produce explainable, auditable,
> revertible
> suggestions. Every AI output lands in a `PENDING` suggestion queue and is
> only applied to Ranger after an administrator approves it — with a full
> before/after policy snapshot and one-click rollback.
> The Epic delivers {*}{{*}}six child issues{{*}}{*} — one bootstrap plus five
> feature
> sub-tasks — and can be merged incrementally: each sub-task carries an
> independently-testable MVP and is gated behind a feature flag. The six
> child issues are:
> |Child issue|Scope|
> |SUB-00|*Bootstrap* — module skeleton, `LlmClient` / `AuditSource` /
> `PasswordDecoder` SPIs, `SuggestionWorkflowService` state machine, DDL.|
> |SUB-01|*Audit Intelligence* — ES-backed anomaly detection + LLM explanation.|
> |SUB-02|*Policy Recommendation* — least-privilege mining from audit
> aggregations.|
> |SUB-03|*Policy Governance* — redundancy / conflict / stale / risky-pattern
> detection.|
> |SUB-04|*NL2Policy* — natural-language authoring via LLM → JSON Schema →
> Ranger `dryRun`.|
> |SUB-05|*Automated Response* — Webhook / mail / ticketing adapters on
> confidence-gated events.|
--
This message was sent by Atlassian Jira
(v8.20.10#820010)