[ 
https://issues.apache.org/jira/browse/RANGER-5720?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Ramachandran Krishnan resolved RANGER-5720.
-------------------------------------------
    Resolution: Fixed

> DB patch 078 for audit partition plan global state
> --------------------------------------------------
>
>                 Key: RANGER-5720
>                 URL: https://issues.apache.org/jira/browse/RANGER-5720
>             Project: Ranger
>          Issue Type: Sub-task
>          Components: Ranger
>            Reporter: Ramachandran Krishnan
>            Assignee: Ramachandran Krishnan
>            Priority: Major
>             Fix For: 3.0.0
>
>          Time Spent: 2h
>  Remaining Estimate: 0h
>
> Adds database support for Admin-managed audit partition routing so the 
> partition plan JSON can be stored, versioned, and upgraded safely on existing 
> Ranger deployments.
> Ranger Admin will persist the audit partition plan in 
> {{{}x_ranger_global_state{}}}. The current {{app_data}} column is too small 
> for the plan JSON, and the system needs a dedicated machine user for the 
> audit ingestor to download the plan from Admin over SPIFFE-authenticated REST.
> This PR delivers the schema and seed data changes only. Admin APIs, ingestor 
> polling, and plugin behavior come in later PRs.
> h3. What changes
>  * Widen {{x_ranger_global_state.app_data}} to a large text/CLOB type on all 
> supported databases so the partition plan JSON fits.
>  * Seed {{rangerauditserver}} portal user and {{ROLE_ADMIN_AUDITOR}} so the 
> audit ingestor can authenticate to Admin for plan download (SPIFFE path; no 
> password on that flow).
>  * Seed initial {{RangerAuditPartitionPlan}} in global state with a default 
> empty plan (default topic, buffer partitions, version 1).
>  * Register DB patch 078 in version history so upgrades from prior releases 
> apply the change once.
> h3. Upgrade vs fresh install
>  * Upgrade (e.g. Ranger 2.9 → 3.0): {{setup.sh}} applies patch 078 
> automatically when it is not already recorded in {{{}x_db_version_h{}}}.
>  * Fresh install: the same logic is included in the current core DB schema so 
> new clusters start with the correct column type and seed rows.
> Patch logic is idempotent: it alters the column only when still narrow, and 
> inserts users/roles/plan rows only when missing.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to