mneethiraj commented on code in PR #1120:
URL: https://github.com/apache/ranger/pull/1120#discussion_r3687855721
##########
security-admin/src/main/java/org/apache/ranger/rest/RangerHealthREST.java:
##########
@@ -54,4 +62,26 @@ public RangerServerHealth getRangerServerHealth() {
return rangerServerHealthUtil.getRangerServerHealth(dbVersion);
}
+
+ @GET
+ @Path("/health/readiness")
+ @Produces("application/json")
+ @Transactional(propagation = Propagation.NOT_SUPPORTED)
+ public RangerServerHealth getRangerServerReadiness(@Context
HttpServletRequest request) {
+ List<RangerServiceDef> serviceDefs =
serviceREST.getServiceDefs(request).getServiceDefs();
Review Comment:
Instead of retrieving `RangerServiceDef` objects from the database, I
suggest to retrieve only service-def names from the database using a new JPA
query.
Also update `RangerServerHealthUtil.serviceUpWithAvailableServiceDefs()` to
return the name list instead of sertializing entire service-defs.
##########
security-admin/db/postgres/optimized/current/ranger_core_db_postgres.sql:
##########
@@ -1997,6 +1997,11 @@ INSERT INTO
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_N
INSERT INTO
x_portal_user_role(CREATE_TIME,UPDATE_TIME,USER_ID,USER_ROLE,STATUS)VALUES(current_timestamp,current_timestamp,getXportalUIdByLoginId('rangertagsync'),'ROLE_SYS_ADMIN',1);
INSERT INTO
x_user(CREATE_TIME,UPDATE_TIME,user_name,status,descr)VALUES(current_timestamp,current_timestamp,'rangertagsync',0,'rangertagsync');
+-- Built-in health-check user for the /service/actuator/health/readiness
endpoint. It authenticates via trusted header (Istio/trusted proxy) only; no
usable password is set, so password login is effectively disabled. It is
granted read access only.
+INSERT INTO
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_NAME,LOGIN_ID,PASSWORD,EMAIL,STATUS)VALUES(current_timestamp,current_timestamp,'healthcheck','','healthcheck','healthcheck','*disabled-header-auth-only*','healthcheck',1);
Review Comment:
Database scripts for other flavors (example: MySQL, Oracle) should be
updated as well.
##########
security-admin/db/postgres/optimized/current/ranger_core_db_postgres.sql:
##########
@@ -1997,6 +1997,11 @@ INSERT INTO
x_portal_user(CREATE_TIME,UPDATE_TIME,FIRST_NAME,LAST_NAME,PUB_SCR_N
INSERT INTO
x_portal_user_role(CREATE_TIME,UPDATE_TIME,USER_ID,USER_ROLE,STATUS)VALUES(current_timestamp,current_timestamp,getXportalUIdByLoginId('rangertagsync'),'ROLE_SYS_ADMIN',1);
INSERT INTO
x_user(CREATE_TIME,UPDATE_TIME,user_name,status,descr)VALUES(current_timestamp,current_timestamp,'rangertagsync',0,'rangertagsync');
+-- Built-in health-check user for the /service/actuator/health/readiness
endpoint. It authenticates via trusted header (Istio/trusted proxy) only; no
usable password is set, so password login is effectively disabled. It is
granted read access only.
Review Comment:
"It authenticates via trusted header (Istio/trusted proxy) only;" => this is
not correct. The user can still authenticate via Kerberos or JWT. I suggest
updating the comment to only retain the first sentence.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]