Hi,
Is there an existing approach for exposing management functions to users other
than the application creator? Most management operations validate the
existence of a cluster definition in the cluster directory, which is by default
under the creator’s home directory (e.g.
/users/username/.slider/cluster/clusterName). That check will fail if a user
other than the creator attempts a management operation (e.g. stop) even if an
authorization policy is in place to allow the operation (assuming RPC ACLs or
Ranger is leveraged). Do we:
- Expect users to leverage the “slider.base.path” property to designate
a location accessible to all management users (with appropriate permissions set
for that directory)?
- Move the default base path to one accessible to more users (the users
designated as authorized to manage application instances), e.g. /apps/slider?
— Jon
--
CONFIDENTIALITY NOTICE
NOTICE: This message is intended for the use of the individual or entity to
which it is addressed and may contain information that is confidential,
privileged and exempt from disclosure under applicable law. If the reader
of this message is not the intended recipient, you are hereby notified that
any printing, copying, dissemination, distribution, disclosure or
forwarding of this communication is strictly prohibited. If you have
received this communication in error, please contact the sender immediately
and delete it from your system. Thank You.