mneethiraj commented on code in PR #1120:
URL: https://github.com/apache/ranger/pull/1120#discussion_r3687855721


##########
security-admin/src/main/java/org/apache/ranger/rest/RangerHealthREST.java:
##########
@@ -54,4 +62,26 @@ public RangerServerHealth getRangerServerHealth() {
 
         return rangerServerHealthUtil.getRangerServerHealth(dbVersion);
     }
+
+    @GET
+    @Path("/health/readiness")
+    @Produces("application/json")
+    @Transactional(propagation = Propagation.NOT_SUPPORTED)
+    public RangerServerHealth getRangerServerReadiness(@Context 
HttpServletRequest request) {
+        List<RangerServiceDef> serviceDefs = 
serviceREST.getServiceDefs(request).getServiceDefs();

Review Comment:
   Instead of retrieving `RangerServiceDef` objects from the database, I 
suggest to retrieve only service-def names from the database using a new JPA 
query.
   
   Also update `RangerServerHealthUtil.serviceUpWithAvailableServiceDefs()` to 
return the name list instead of sertializing entire service-defs.



##########
security-admin/db/postgres/optimized/current/ranger_core_db_postgres.sql:
##########
@@ -1997,6 +1997,11 @@ INSERT INTO 
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_N
 INSERT INTO 
x_portal_user_role(CREATE_TIME,UPDATE_TIME,USER_ID,USER_ROLE,STATUS)VALUES(current_timestamp,current_timestamp,getXportalUIdByLoginId('rangertagsync'),'ROLE_SYS_ADMIN',1);
 INSERT INTO 
x_user(CREATE_TIME,UPDATE_TIME,user_name,status,descr)VALUES(current_timestamp,current_timestamp,'rangertagsync',0,'rangertagsync');
 
+-- Built-in health-check user for the /service/actuator/health/readiness 
endpoint. It authenticates via trusted header (Istio/trusted proxy) only; no 
usable password is set, so password login is effectively disabled. It is 
granted read access only.
+INSERT INTO 
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_NAME,LOGIN_ID,PASSWORD,EMAIL,STATUS)VALUES(current_timestamp,current_timestamp,'healthcheck','','healthcheck','healthcheck','*disabled-header-auth-only*','healthcheck',1);

Review Comment:
   Database scripts for other flavors (example: MySQL, Oracle) should be 
updated as well.



##########
security-admin/db/postgres/optimized/current/ranger_core_db_postgres.sql:
##########
@@ -1997,6 +1997,11 @@ INSERT INTO 
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_N
 INSERT INTO 
x_portal_user_role(CREATE_TIME,UPDATE_TIME,USER_ID,USER_ROLE,STATUS)VALUES(current_timestamp,current_timestamp,getXportalUIdByLoginId('rangertagsync'),'ROLE_SYS_ADMIN',1);
 INSERT INTO 
x_user(CREATE_TIME,UPDATE_TIME,user_name,status,descr)VALUES(current_timestamp,current_timestamp,'rangertagsync',0,'rangertagsync');
 
+-- Built-in health-check user for the /service/actuator/health/readiness 
endpoint. It authenticates via trusted header (Istio/trusted proxy) only; no 
usable password is set, so password login is effectively disabled. It is 
granted read access only.

Review Comment:
   "It authenticates via trusted header (Istio/trusted proxy) only;" => this is 
not correct. The user can still authenticate via Kerberos or JWT. I suggest 
updating the comment to only retain the first sentence.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to