Ranger安装和使用

Ranger部署

1.准备
1.1 编译

Ranger编译(已经编译过的话,直接看1.2)

1.1.1 准备到Ranger官网下载ranger的源码:http://ranger.apache.org/download.html

1.1.2 Ranger编译的过程实在非虚拟机环境下完成的,下载好ranger源码后并解压,然后进入源码解压目录执行如下命令进行编译:

cd /Users/fan/Downloads/apache-ranger-2.0.0 mvn clean compile package assembly:assembly install -Dmaven.test.skip=true mvn clean install -DskipTests -Denforcer.skip=true

1.1.3 将编译好的tar包上传到bigdb03

rsync -r share/ [email protected]:/data/fan/install/native/10.ranger/package/

1.2 数据库环境准备

1.2.1 登录mysql (之前安装hive时候装的那个mysql)

root@bigdb01 \~\]# docker exec -it mysql-hive bash root@bigdb01:/# mysql -uroot -phz310012 1.2.2 创建Ranger存储数据的数据库 mysql\> create database ranger; 1.2.3 创建用户 mysql> grant all privileges on ranger.* to ranger@'%' identified by '@#QWEASD123'; ##### 2.安装RangerAdmin ##### 2.1 解压软件 [root@bigdb01 ~]# rsync root@bigdb03:/data/fan/install/native/10.ranger/package/ranger-2.0.0-admin.tar.gz /opt/software [root@bigdb01 ~]# mkdir /opt/module/ranger [root@bigdb01 ~]# tar -zxvf /opt/software/ranger-2.0.0-admin.tar.gz -C /opt/module/ranger/ ##### 2.2 配置install.properties文件 [root@bigdb01 ~]# vim /opt/module/ranger/ranger-2.0.0-admin/install.properties 修改以下内容: ![](https://file.jishuzhan.net/article/1732446365616705537/8a86736f8ac62d839aac83011c8f4e27.webp) ##### ![](https://file.jishuzhan.net/article/1732446365616705537/de028e6321847770caefc0bfe2be19c5.webp) ##### 2.3 在root用户下,执行安装 注意:ranger2.0需要用python2执行,RHEL9自带python3.9,所以需要自己安装python2 [root@bigdb01 ~]# cd /opt/module/ranger/ranger-2.0.0-admin/ [root@bigdb01 ranger-2.0.0-admin]# ./setup.sh 出现以下字样,表示安装成功 ![](https://file.jishuzhan.net/article/1732446365616705537/a975bd7f7cbc067a065fad8d68806d96.webp) ##### 2.4 创建ranger的配置文件软连接到web下 \[root@bigdb01 ranger-2.0.0-admin\]# ./set_globals.sh usermod: no changes \[2023/08/18 15:53:49\]: \[I\] Soft linking /etc/ranger/admin/conf to ews/webapp/WEB-INF/classes/conf ##### 2.5 启动 RangerAdmin 2.5.1 配置RangerAdminweb应用的配置信息 \[root@bigdb01 \~\]# cd /etc/ranger/admin/conf/ \[root@bigdb01 conf\]# vim ranger-admin-site.xml 修改内容如下 ![](https://file.jishuzhan.net/article/1732446365616705537/7490f37be5478860f3eae234e66be3f6.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/3239ff8a791140527b7c8219efb12d90.webp) 2.5.2 启动 \[root@bigdb01 conf\]# ranger-admin start 启动成功 ![](https://file.jishuzhan.net/article/1732446365616705537/e9bc310e46637a969c9c1f66cb2f7283.webp) 2.5.3 查看启动后的进程 \[root@bigdb01 conf\]# jps 47556 EmbeddedServer 47621 Jps 2.5.4 停止 ranger \[root@bigdb01 conf\]# ranger-admin stop ##### 2.6 登录管理员用户 默认admin,密码@#QWEASD123 ![](https://file.jishuzhan.net/article/1732446365616705537/c5f160d2948d4eb927ea138abf546ec8.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/a2267b88db3ef20482dd32b1a11d6217.webp) ##### 3.安装RangerUsersync ##### 3.1 解压 \[root@bigdb01 \~\]# rsync root@bigdb03:/data/fan/install/native/10.ranger/package/ranger-2.0.0-usersync.tar.gz /opt/software \[root@bigdb01 \~\]# tar -zxvf /opt/software/ranger-2.0.0-usersync.tar.gz -C /opt/module/ranger/ ##### 3.2 配置 \[root@bigdb01 software\]# cd /opt/module/ranger/ranger-2.0.0-usersync/ \[root@bigdb01 ranger-2.0.0-usersync\]# vim install.properties 配置内容如下 ![](https://file.jishuzhan.net/article/1732446365616705537/d958daf19bea7d589284a02f72e85533.webp) ##### 3.3 使用root用户进行安装 \[root@bigdb01 ranger-2.0.0-usersync\]# ./setup.sh 出现如下信息,说明安装成功 ![](https://file.jishuzhan.net/article/1732446365616705537/6428669a1d51dd7e7c3626ab6156780e.webp) ##### 3.4 RangerUsersync 启动 3.4.1 启动前 ![](https://file.jishuzhan.net/article/1732446365616705537/040674fa2d9d0e283e385acfb884c2db.webp) 3.4.2 使用root启动 \[root@bigdb01 ranger-2.0.0-usersync\]# ./ranger-usersync-services.sh start ![](https://file.jishuzhan.net/article/1732446365616705537/1c2c77047f83dac959ea198bc1ea26ca.webp) 启动后再次查看用户信息 ![](https://file.jishuzhan.net/article/1732446365616705537/90c1357c194121a0c3eaeb7b95b8332b.webp) ##### 4.Ranger Hive-plugin ##### 4.1 安装 ##### 4.1.1 解压软件 [root@bigdb01 ~]# rsync root@bigdb03:/data/fan/install/native/10.ranger/package/ranger-2.0.0-hive-plugin.tar.gz /opt/software [root@bigdb01 ~]# tar -zxvf /opt/software/ranger-2.0.0-hive-plugin.tar.gz -C /opt/module/ranger/ ##### 4.1.2 配置软件 \[root@bigdb01 \~\]# vim /opt/module/ranger/ranger-2.0.0-hive-plugin/install.properties 配置内容如下 ![](https://file.jishuzhan.net/article/1732446365616705537/e6b3b717b5c07ff6585a95cf0c0367a5.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/485569ec6dccb8da72442c7aa1ce66ba.webp) ##### 4.1.3 引用hive配置文件 将hive的配置文件作为软连接安装到 Ranger Hive-plugin 目录下 \[root@bigdb01 ranger-2.0.0-hive-plugin\]# ln -s /opt/module/hive/conf/ conf ##### 4.1.4 启动 使用root用户启动Ranger Hive-plugin \[root@bigdb01 ranger-2.0.0-hive-plugin\]# ./enable-hive-plugin.sh ![](https://file.jishuzhan.net/article/1732446365616705537/a1c75b49ad01ce086a564e498bc29d32.webp) ##### 4.1.5 重启hive \[root@bigdb01 ranger-2.0.0-hive-plugin\]# [hiveservice.sh](http://hiveservice.sh "hiveservice.sh") restart ![](https://file.jishuzhan.net/article/1732446365616705537/86ededa393698144aa4b2ea47c46fd7f.webp) ##### 4.2 权限管理 [root@bigdb01 ~]# beeline beeline> !connect jdbc:hive2://bigdb01:10000 Connecting to jdbc:hive2://bigdb01:10000 Enter username for jdbc:hive2://bigdb01:10000: admin Enter password for jdbc:hive2://bigdb01:10000: hz310012 Connected to: Apache Hive (version 3.1.2) Driver: Hive JDBC (version 3.1.2) Transaction isolation: TRANSACTION_REPEATABLE_READ 0: jdbc:hive2://bigdb01:10000> 如果报以下错误,要修改/tmp权限 ![](https://file.jishuzhan.net/article/1732446365616705537/324b0b6771cfe36dca7bdd93ce78b9ad.webp) ##### 4.2.1 读写权限 为zion用户配置dd库student表的读的权限。 ![](https://file.jishuzhan.net/article/1732446365616705537/f6308f4ebbb38559288dbdc3b1eddd60.webp) [root@bigdb01 ~]# beeline beeline> !connect jdbc:hive2://bigdb01:10000 Enter username for jdbc:hive2://bigdb01:10000: zion Enter password for jdbc:hive2://bigdb01:10000: **** 0: jdbc:hive2://bigdb01:10000> use dd; 0: jdbc:hive2://bigdb01:10000> select * from student; 0: jdbc:hive2://bigdb01:10000> select sname,sbirth from student; 看下效果 ![](https://file.jishuzhan.net/article/1732446365616705537/1b9506a078750d2bb273597cc8fd690d.webp) ##### 4.2.2 脱敏操作 注意要配合的用户或者用户组必须已具备查看权限 ![](https://file.jishuzhan.net/article/1732446365616705537/c33f28a823eeab03f84db26abeff631b.webp) 看下效果 ![](https://file.jishuzhan.net/article/1732446365616705537/158eaed6151221b77b9bd932484000c0.webp) ##### 4.2.3 行级别过滤 注意 过滤条件中的字段必须是当前用户有权限查看的。 ![](https://file.jishuzhan.net/article/1732446365616705537/be2875eaf30ace20e0b312f0cedd1026.webp) 看下效果 ![](https://file.jishuzhan.net/article/1732446365616705537/a3043f597815ecadae953233bf561e8d.webp) ##### 5.Ranger yarn-plugin ##### 5.1安装 ##### 5.1.1 解压软件 [root@bigdb01 ~]# rsync root@bigdb03:/data/fan/install/native/10.ranger/package/ranger-2.0.0-yarn-plugin.tar.gz /opt/software [root@bigdb01 ~]# tar -zxvf /opt/software/ranger-2.0.0-yarn-plugin.tar.gz -C /opt/module/ranger/ ##### 5.1.2 修改配置文件 [root@bigdb01 ~]# cd /opt/module/ranger/ranger-2.0.0-yarn-plugin/ [root@bigdb01 ranger-2.0.0-yarn-plugin]# vim install.properties ![](https://file.jishuzhan.net/article/1732446365616705537/3724933cef5b593b57ba24755a660364.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/9b01b67d6929ff3ef0a23001c625d14e.webp) ##### 5.1.3 使yarn-plugin生效 \[root@bigdb01 ranger-2.0.0-yarn-plugin\]# ./enable-yarn-plugin.sh ![](https://file.jishuzhan.net/article/1732446365616705537/5dd26325432abc3caeb16a5d67d6d6f8.webp) 5.1.4 重启yarn \[root@bigdb01 \~\]# [hdp.sh](http://hdp.sh "hdp.sh") stop \[root@bigdb01 \~\]# [hdp.sh](http://hdp.sh "hdp.sh") start 5.1.5 页面配置 ![](https://file.jishuzhan.net/article/1732446365616705537/bd0f136328707109ab0ac13995b79cbc.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/3e03de8554e2cd8ae0e3f68e12573d0d.webp) ##### 4.Ranger hdfs-plugin ##### 4.1安装 ##### 4.1.1 解压 [root@bigdb01 ~]# rsync root@bigdb03:/data/fan/install/native/10.ranger/package/ranger-2.0.0-hdfs-plugin.tar.gz /opt/software [root@bigdb01 ~]# tar -zxvf /opt/software/ranger-2.0.0-hdfs-plugin.tar.gz -C /opt/module/ranger/ ##### 4.1.2 配置 \[root@bigdb01 \~\]# vim /opt/module/ranger/ranger-2.0.0-hdfs-plugin/install.properties 修改一下内容 ![](https://file.jishuzhan.net/article/1732446365616705537/8d4069d5ce1467bef765921538f28dda.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/9aa10e1cf6d571cc042e1173556e31fc.webp) ##### 4.1.3 使hdfs-plugin生效 \[root@bigdb01 ranger-2.0.0-hdfs-plugin\]# ./enable-hdfs-plugin.sh ![](https://file.jishuzhan.net/article/1732446365616705537/a77fefe5472d7855aff0ac3cb1f5ba93.webp) 重启hadoop \[root@bigdb01 \~\]# [hdp.sh](http://hdp.sh "hdp.sh") stop \[root@bigdb01 \~\]# [hdp.sh](http://hdp.sh "hdp.sh") start ##### 4.2 测试 使用root在hdfs上创建一个文件夹rangertest,并且用root用户上传一个文件到该文件夹下,切换为zion用户去查看数据,可以查看,上传文件到改文件夹下,失败! ##### 4.2.1 上传文件 创建目录 /rangertest \[root@bigdb01 \~\]# hdfs dfs -mkdir /rangertest \[root@bigdb01 \~\]# hadoop fs -ls / 上传文件student.csv [root@bigdb01 ~]# hdfs dfs -put /data/dd/student.csv /rangertest [root@bigdb01 ~]# hadoop fs -ls /rangertest ![](https://file.jishuzhan.net/article/1732446365616705537/85c7b565bafc944b7e99771408031dac.webp) ##### 4.2.2 用zion用户操作 切换zion用户,并查看文件内容 \[root@bigdb01 \~\]# su zion \[root@bigdb01 \~\]# hdfs dfs -cat /rangertest/student.csv ![](https://file.jishuzhan.net/article/1732446365616705537/c822378b5bf6f4117537fcf1bd7f56df.webp) 通过用户zion上传文件到 /rangertest目录下 [root@bigdb01 ~]# su zion [zion@bigdb01 root]$ hdfs dfs -put /data/dd/teacher.csv /rangertest ![](https://file.jishuzhan.net/article/1732446365616705537/545ac6daf80bd646b3d98c793c024449.webp) ##### 4.2.3 页面配置hdfs-plugin参数 ![](https://file.jishuzhan.net/article/1732446365616705537/d5fe1ac0c8fd2676bec6ec5e1c6dcc81.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/9c00bfd05819b755e2717172a60d7e56.webp) ![](https://file.jishuzhan.net/article/1732446365616705537/a4b5112325897c0fa8bde4d5ccdfeac2.webp)

相关推荐
心碎土豆块2 小时前
MapReduce打包运行
大数据·mapreduce
元6336 小时前
Spark 缓存(Caching)
大数据·spark
麻芝汤圆7 小时前
MapReduce 入门实战:WordCount 程序
大数据·前端·javascript·ajax·spark·mapreduce
IvanCodes8 小时前
五、Hadoop集群部署:从零搭建三节点Hadoop环境(保姆级教程)
大数据·hadoop·分布式
富能量爆棚9 小时前
spark-local模式
大数据
lqlj22339 小时前
配置 Spark 以 YARN 模式
大数据·spark
AidLux9 小时前
端侧智能重构智能监控新路径 | 2025 高通边缘智能创新应用大赛第三场公开课来袭!
大数据·人工智能
炒空心菜菜10 小时前
SparkSQL 连接 MySQL 并添加新数据:实战指南
大数据·开发语言·数据库·后端·mysql·spark
富能量爆棚10 小时前
Hadoop和Spark生态系统
大数据
2401_8712905812 小时前
Spark的缓存
大数据·spark