[#8674] fix(authz): Isolate Ranger catalog owner roles by catalog ID (#12517) ### What changes were proposed in this pull request? Pass the stable catalog entity ID to authorization plugins and use it to create catalog-specific Ranger owner roles. Catalog owner roles now follow this format: `GRAVITINO_CATALOG_OWNER_ROLE_<catalog_id>` The chained authorization plugin also propagates the catalog ID to its child plugins. ### Why are the changes needed? Ranger previously used one shared `GRAVITINO_CATALOG_OWNER_ROLE` for every catalog. As a result, the owner of one catalog could receive owner permissions on other catalogs using the same Ranger service. Using the stable catalog ID isolates role membership without depending on the mutable catalog name. Fix: #8674 ### Does this PR introduce _any_ user-facing change? Yes. Ranger creates a separate catalog owner role for each catalog using the catalog ID as the role-name suffix. No user-configurable property is added. ### How was this patch tested? - Added unit tests for passing catalog IDs to authorization plugins. - Added unit tests for generating and creating catalog-specific Ranger owner roles. - Updated the Ranger integration test expectation. - Ran Spotless successfully.
Apache Gravitino is a high-performance, geo-distributed, and federated metadata lake. It manages metadata directly in different sources, types, and regions, providing users with unified metadata access for data and AI assets.
The latest Gravitino documentation is available at gravitino.apache.org/docs/latest.
This README provides a basic overview; visit the site for full installation, configuration, and development documentation.
Gravitino provides a Docker Compose–based playground for a full-stack experience.
Clone or download the Gravitino Playground repository and follow its README.
conf/gravitino.conf to configure settings../bin/gravitino.sh start
./bin/gravitino.sh stop
By default, Gravitino uses the Web V2 UI.
To switch back to the legacy v1 UI at runtime, edit conf/gravitino-env.sh (or set the environment variable before starting) and set GRAVITINO_USE_WEB_V2 to false:
export GRAVITINO_USE_WEB_V2=false ./bin/gravitino.sh restart
GRAVITINO_USE_WEB_V2=true.Gravitino provides a native Iceberg REST catalog service.
See: Iceberg REST catalog service
Gravitino provides a native Lance REST catalog service.
See: Lance REST catalog service
Gravitino includes a Trino connector for federated metadata access.
See: Using Trino with Gravitino
Gravitino uses Gradle. Windows is not currently supported.
Clean build without tests:
./gradlew clean build -x test
Build a distribution:
./gradlew compileDistribution -x test
Skip building and packaging both Web UIs:
./gradlew compileDistribution -PskipWebBuild=true -x test
Or compressed package:
./gradlew assembleDistribution -x test
Artifacts are output to the distribution/ directory.
More build options: How to build Gravitino
We welcome all kinds of contributions—code, documentation, testing, connectors, and more!
To get started, please read our CONTRIBUTING.md guide.
Apache Gravitino is licensed under the Apache License, Version 2.0.
See the LICENSE file for details.
Apache®, Apache Gravitino™, Apache Hadoop®, Apache Hive™, Apache Iceberg™, Apache Kafka®, Apache Spark™, Apache Submarine™, Apache Thrift™, and Apache Zeppelin™ are trademarks of the Apache Software Foundation in the United States and/or other countries.