[
https://issues.apache.org/jira/browse/SENTRY-2134?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16477366#comment-16477366
]
Lars Francke commented on SENTRY-2134:
--------------------------------------
I too would love to see this supported for the reasons mentioned above. I do
understand the current behaviour but it is not very obvious. I was surprised
when I found it.
I think the HDFS Sync is great because it saves me from defining the same
access rights two times (like I have to do in Ranger) but on the other hand I'd
rather stay in one system to define all permissions (like in Ranger) than going
to two different ones (HDFS & Sentry).
> Apply Hive URI grants recursively to subdirectories
> ---------------------------------------------------
>
> Key: SENTRY-2134
> URL: https://issues.apache.org/jira/browse/SENTRY-2134
> Project: Sentry
> Issue Type: Wish
> Components: Hive Binding
> Affects Versions: 1.8.0, 2.0.0, 1.7.1
> Reporter: Ruslan Dautkhanov
> Priority: Major
> Labels: hive, uri
>
> Currently we need to add direct grants for all Hive tables' LOCATIONs.
> Like, 'hdfs_staging/table1', 'hdfs_staging/table2', etc..
> It's not manageable this way. - we can't add grants for each and every table.
> It would be great if we could just do one grant -
> 'hdfs_staging/' so it would automatically be applied to
> 'hdfs_staging/table1', 'hdfs_staging/table2', and other subdirectories.
> There is probably a reason this wasn't implemented earlier? Thanks for
> considering this improvement.
> Also found another user's request on this -
> https://community.cloudera.com/t5/Interactive-Short-cycle-SQL/Impala-Sentry-GRANT-ALL-ON-URI-not-cascaded-down-through/td-p/39928
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)