Hi,

We are using ranger to authorize HDFS requests. And we find an issue that
if there is an HDFS path authorized to too many users (about hundreds of
users), it will take a long time to update the authorization rule (up to 10
seconds more). After reading the source code, it seems that ranger admin
will delete all the old rules, then insert newly configured  rules to
implement the update operation.

I'd like to ask if there is system design consideration here to use
delete-and-insert pattern to implement update operation, and if there are
some optimizations to  help us accelerate the operation ?

Thanks

Reply via email to