ResourceSchemas compatíveis
O Security Center fornece ResourceSchemas integrados para tipos comuns de recursos, incluindo: MaxCompute, EMR_ON_ECS_HIVE, SEVERLESS_STARROCKS, HOLOGRES, DATAWORKS_ENTITY, DLF_V1, DLF_NEXT e LINDORM.
Configuração do método de autorização
Cada campo authMethods em um ResourceSchema define os métodos de autorização compatíveis com o tipo de recurso:
{ "authMethods": [ { "name": "default", "displayName": "Native Authorization", "isDefault": true } ] }
Convenções:
Todos os ResourceSchemas integrados incluem pelo menos o método de autorização
default.O método
defaultrepresenta a autorização nativa do tipo de recurso. O sistema o mapeia para umPermissionGrantServiceespecífico com base nodefSchema.Se você não especificar
authMethodou passardefault, o sistema usará automaticamente o método de autorização nativo.
Mapeamentos entre método de autorização e tipo de recurso:
|
Tipo de recurso |
Mapeamento padrão |
Outros métodos de autorização |
Descrição |
|
SEVERLESS_STARROCKS |
ranger |
starrocksManager |
SEVERLESS_STARROCKS é o único tipo de recurso que aceita múltiplos métodos de autorização. O Ranger é usado por padrão, e o StarRocks Manager está disponível como alternativa. |
|
HOLOGRES |
hologres |
- |
Apenas a autorização nativa é compatível. |
|
DLF_V1 |
dlfV1 |
- |
Somente a autorização DLF 1.0 é compatível. |
|
EMR_ON_ECS_HIVE |
ranger |
- |
Exclusivamente a autorização Ranger é compatível. |
|
LINDORM |
ranger |
- |
Restrito à autorização Ranger. |
|
DATAWORKS_ENTITY |
default |
- |
Apenas a autorização padrão é compatível. |
|
MaxCompute |
default |
Autorização não compatível |
O MaxCompute possui um sistema de permissões independente. |
|
DLF_NEXT |
default |
Autorização não compatível |
O DLF 3.0 possui um sistema de permissões independente. |
As seções a seguir apresentam a definição de cada ResourceSchema:
MaxCompute
{
"name": "MaxCompute",
"displayName": "MaxCompute Resource",
"version": "v1.0.0",
"authPrincipal": [
"RAM_USER",
"RAM_ROLE"
],
"authMethods": [],
"resources": [
{
"level": 0,
"name": "tenant",
"type": "string",
"label": "DATAWORKS_TENANT_ID",
"parent": "",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 1,
"name": "workspace",
"type": "string",
"label": "DATAWORKS_WORKSPACE_ID",
"parent": "tenant",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [
"workspaceId",
"workspaceName",
"ownerBaseId"
],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 2,
"name": "project",
"type": "string",
"label": "PROJECT",
"parent": "workspace",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 3,
"name": "schema",
"type": "string",
"label": "SCHEMA",
"parent": "project",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 4,
"name": "table",
"type": "string",
"label": "TABLE",
"parent": "schema",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": true,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select",
"update",
"download",
"describe",
"alter",
"drop"
]
},
{
"level": 4,
"name": "resource",
"type": "string",
"label": "RESOURCE",
"parent": "schema",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"read",
"write",
"delete",
"all"
]
},
{
"level": 4,
"name": "udf",
"type": "string",
"label": "UDF",
"parent": "schema",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"read",
"write",
"delete",
"execute",
"all"
]
},
{
"level": 5,
"name": "column",
"type": "string",
"label": "COLUMN",
"parent": "table",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select",
"update",
"download"
]
}
]
}
hive
{
"name": "EMR_ON_ECS_HIVE",
"displayName": "Emr On Ecs Hive Resource",
"version": "v1.0.0",
"authPrincipal": [
"RAM_USER"
],
"authMethods": [],
"resources": [
{
"level": 0,
"name": "tenant",
"type": "string",
"label": "DATAWORKS_TENANT_ID",
"parent": "",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 1,
"name": "instance",
"type": "string",
"label": "INSTANCE_ID",
"parent": "tenant",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [
"workspaceId",
"workspaceName",
"ownerBaseId"
],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 2,
"name": "database",
"type": "string",
"label": "DATABASE",
"parent": "instance",
"mandatory": true,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"create",
"update",
"alter",
"select"
]
},
{
"level": 3,
"name": "table",
"type": "string",
"label": "TABLE",
"parent": "database",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select",
"drop",
"update",
"alter",
"all"
]
}
]
}
starrocks
{ "name": "SEVERLESS_STARROCKS", "displayName": "Serverless Starrocks Resource", "version": "v1.0.0", "authPrincipal": [ "RAM_USER", "RAM_ROLE" ], "authMethods": [ { "name": "ranger", "displayName": "Ranger", "isDefault": true }, { "name": "starrocksManager", "displayName": "StarRocks Manager", "isDefault": false } ], "resources": [ { "level": 0, "name": "tenant", "type": "string", "label": "DATAWORKS_TENANT_ID", "parent": "", "mandatory": false, "extendedInfo": {}, "recursiveSupported": false, "enricherFields": [], "isValidLeaf": false, "accessTypeRestrictions": [] }, { "level": 1, "name": "instance", "type": "string", "label": "INSTANCE_ID", "parent": "tenant", "mandatory": true, "extendedInfo": {}, "enricherFields": [], "isValidLeaf": false, "accessTypeRestrictions": [] }, { "level": 2, "name": "internalCatalog", "type": "string", "label": "INTERNAL_CATALOG", "parent": "instance", "mandatory": false, "extendedInfo": {}, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "usage", "create database", "drop", "alter"] } ] }, { "level": 2, "name": "hiveCatalog", "type": "string", "label": "EXTERNAL_HIVE_CATALOG", "parent": "instance", "mandatory": false, "extendedInfo": {}, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "usage", "create database", "drop", "alter"] } ] }, { "level": 3, "name": "database", "type": "string", "label": "DATABASE", "parent": "internalCatalog", "mandatory": false, "extendedInfo": {}, "recursiveSupported": true, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [ "create table", "drop", "alter", "create view", "create function", "create materialized view" ], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "alter", "drop", "create table", "create view", "create function", "create materialized view", "create pipe"] }, { "authMethod": "ranger", "accessTypes": ["create table", "drop", "alter", "create view", "create function", "create materialized view"] } ] }, { "level": 3, "name": "hiveDatabase", "type": "string", "label": "EXTERNAL_HIVE_DATABASE", "parent": "hiveCatalog", "mandatory": false, "extendedInfo": {}, "recursiveSupported": true, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [ "create", "update", "alter", "select" ], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "alter", "drop", "create table", "create view", "create function", "create materialized view", "create pipe"] }, { "authMethod": "ranger", "accessTypes": ["create", "update", "alter", "select"] } ] }, { "level": 4, "name": "table", "type": "string", "label": "TABLE", "parent": "database", "mandatory": false, "extendedInfo": { "constraints": { "enabled": true, "supportedTypes": ["rowFilter"], "maxConstraints": 1, "definitions": { "rowFilter": { "description": "Row-level filter condition, SQL WHERE clause", "type": "string", "required": false, "example": "ID > 3 AND Name = 'test'", "authMethods": ["ranger"], "restrictedAccessTypes": ["select"] } } } }, "recursiveSupported": false, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [ "delete", "drop", "insert", "select", "alter", "export", "update" ], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "alter", "drop", "select", "insert", "update", "export", "delete"] }, { "authMethod": "ranger", "accessTypes": ["delete", "drop", "insert", "select", "alter", "export", "update"] } ] }, { "level": 4, "name": "view", "type": "string", "label": "VIEW", "parent": "database", "mandatory": false, "extendedInfo": {}, "recursiveSupported": false, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "select", "alter", "drop"] } ] }, { "level": 4, "name": "materializedView", "type": "string", "label": "MATERIALIZED_VIEW", "parent": "database", "mandatory": false, "extendedInfo": {}, "recursiveSupported": false, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "select", "alter", "refresh", "drop"] } ] }, { "level": 4, "name": "hiveTable", "type": "string", "label": "EXTERNAL_HIVE_TABLE", "parent": "hiveDatabase", "mandatory": false, "extendedInfo": {}, "recursiveSupported": false, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [ "select" ], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "alter", "drop", "select", "insert", "update", "export", "delete"] }, { "authMethod": "ranger", "accessTypes": ["select"] } ] }, { "level": 4, "name": "hiveView", "type": "string", "label": "EXTERNAL_HIVE_VIEW", "parent": "hiveDatabase", "mandatory": false, "extendedInfo": {}, "recursiveSupported": false, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "select", "alter", "drop"] } ] }, { "level": 4, "name": "hiveMaterializedView", "type": "string", "label": "EXTERNAL_HIVE_MATERIALIZED_VIEW", "parent": "hiveDatabase", "mandatory": false, "extendedInfo": {}, "recursiveSupported": false, "enricherFields": [], "isValidLeaf": true, "accessTypeRestrictions": [], "authMethodAccessTypes": [ { "authMethod": "starrocksManager", "accessTypes": ["all", "select", "alter", "refresh", "drop"] } ] } ] }
Diferenças entre os métodos de autorização do StarRocks:
|
Nível de recurso |
ranger (padrão) |
starrocksManager |
Descrição |
|
internalCatalog |
❌ Não compatível |
✅ Compatível |
Não é um nó folha no Ranger |
|
database |
✅ Compatível |
✅ Compatível |
O accessType difere |
|
table |
✅ Compatível |
✅ Compatível |
O Ranger aceita restrições rowFilter |
|
view |
❌ Não compatível |
✅ Compatível |
Compatível apenas com o StarRocks Manager |
|
materializedView |
❌ Não compatível |
✅ Compatível |
Compatível apenas com o StarRocks Manager |
|
hiveCatalog |
❌ Não compatível |
✅ Compatível |
Não é um nó folha no Ranger |
|
hiveDatabase |
✅ Compatível |
✅ Compatível |
O accessType difere |
|
hiveTable |
✅ Compatível (apenas select) |
✅ Compatível |
O Ranger aceita somente select |
|
hiveView |
❌ Não compatível |
✅ Compatível |
Compatível apenas com o StarRocks Manager |
|
hiveMaterializedView |
❌ Não compatível |
✅ Compatível |
Compatível apenas com o StarRocks Manager |
Suporte a restrições:
|
Nível de recurso |
Tipo de restrição |
Métodos de autorização compatíveis |
Restrições de accessType |
Descrição |
|
table |
rowFilter |
ranger |
|
Condição de filtro no nível de linha, cláusula SQL WHERE. Quando rowFilter é declarado, apenas |
hologres
{
"name": "HOLOGRES",
"displayName": "Hologres Resource",
"version": "v1.0.0",
"authPrincipal": [
"RAM_USER"
],
"authMethods": [
{
"name": "hologres",
"displayName": "Hologres",
"isDefault": true
}
],
"resources": [
{
"level": 0,
"name": "tenant",
"type": "string",
"label": "DATAWORKS_TENANT_ID",
"parent": "",
"mandatory": false,
"extendedInfo": {},
"enricherFields": [],
"recursiveSupported": false,
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 1,
"name": "instance",
"type": "string",
"label": "INSTANCE_ID",
"parent": "tenant",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 2,
"name": "database",
"type": "string",
"label": "DATABASE",
"parent": "instance",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 3,
"name": "schema",
"type": "string",
"label": "SCHEMA",
"parent": "database",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 4,
"name": "table",
"type": "string",
"label": "TABLE",
"parent": "schema",
"mandatory": true,
"extendedInfo": {},
"recursiveSupported": true,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select",
"insert",
"update",
"delete",
"truncate",
"all"
]
},
{
"level": 5,
"name": "column",
"type": "string",
"label": "COLUMN",
"parent": "table",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select",
"insert",
"update"
]
}
]
}
Permissões no nível de coluna do Hologres:
|
Item de configuração |
Descrição |
|
|
Aceita o método de autorização |
|
Sub-recurso |
Um sub-recurso de nível 5 abaixo da tabela. Especifique o nome da coluna com o campo |
|
Tipos de acesso para permissões de coluna |
Apenas |
dlf-legacy
{
"name": "DLF_V1",
"displayName": "Dlf 1.0 Resource",
"version": "v1.0.0",
"authPrincipal": [
"RAM_USER",
"RAM_ROLE"
],
"authMethods": [],
"resources": [
{
"level": 0,
"name": "tenant",
"type": "string",
"label": "DATAWORKS_TENANT_ID",
"parent": "",
"mandatory": false,
"extendedInfo": {},
"enricherFields": [],
"recursiveSupported": false,
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 1,
"name": "catalog",
"type": "string",
"label": "CATALOG",
"parent": "tenant",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 2,
"name": "database",
"type": "string",
"label": "DATABASE",
"parent": "catalog",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"describe",
"alter",
"drop",
"createTable",
"createFunction",
"list"
]
},
{
"level": 3,
"name": "table",
"type": "string",
"label": "TABLE",
"parent": "database",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": true,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select",
"update",
"describe",
"alter",
"drop"
]
},
{
"level": 4,
"name": "column",
"type": "string",
"label": "COLUMN",
"parent": "table",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select"
]
}
]
}
dlfNext
{
"name": "DLF_NEXT",
"displayName": "Dlf Next Resource",
"version": "v1.0.0",
"authPrincipal": [
"RAM_USER",
"RAM_ROLE",
"DLF_ROLE"
],
"authMethods": [],
"resources": [
{
"level": 0,
"name": "tenant",
"type": "string",
"label": "DATAWORKS_TENANT_ID",
"parent": "",
"mandatory": false,
"extendedInfo": {},
"enricherFields": [],
"recursiveSupported": false,
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 1,
"name": "catalog",
"type": "string",
"label": "CATALOG",
"parent": "tenant",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 2,
"name": "database",
"type": "string",
"label": "DATABASE",
"parent": "catalog",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"describe",
"list",
"alter",
"drop",
"createTable",
"createFunction",
"createView",
"grant",
"all"
]
},
{
"level": 3,
"name": "table",
"type": "string",
"label": "TABLE",
"parent": "database",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": true,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select",
"update",
"alter",
"drop",
"grant",
"all"
]
},
{
"level": 4,
"name": "column",
"type": "string",
"label": "COLUMN",
"parent": "table",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"select"
]
}
]
}
DATAWORKS_ENTITY
{
"name": "DATAWORKS_ENTITY",
"displayName": "Dataworks Entity",
"version": "v1.0.0",
"authPrincipal": [
"RAM_USER",
"RAM_ROLE",
"DATAWORKS_WORKSPACE_ROLE",
"DATAWORKS_WORKSPACE_MEMBER"
],
"authMethods": [],
"resources": [
{
"level": 0,
"name": "tenant",
"type": "string",
"label": "DATAWORKS_TENANT_ID",
"parent": "",
"mandatory": false,
"extendedInfo": {},
"enricherFields": [],
"recursiveSupported": false,
"isValidLeaf": false,
"accessTypeRestrictions": []
},{
"level": 1,
"name": "tenantRole",
"type": "string",
"label": "DATAWORKS_TENANT_ROLE_CODE",
"parent": "tenant",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [
"roleName"
],
"isValidLeaf": true,
"accessTypeRestrictions": [
"joinIn"
],
"authPrincipalRestrictions": [
"RAM_USER",
"RAM_ROLE"
]
},
{
"level": 1,
"name": "workspace",
"type": "string",
"label": "DATAWORKS_WORKSPACE_ID",
"parent": "tenant",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [
"workspaceId",
"workspaceName",
"ownerBaseId"
],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 2,
"name": "workspaceRole",
"type": "string",
"label": "DATAWORKS_WORKSPACE_ROLE_CODE",
"parent": "workspace",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"joinIn"
],
"authPrincipalRestrictions": [
"RAM_USER",
"RAM_ROLE"
]
}
]
}
Lindorm
{
"name": "LINDORM",
"displayName": "Lindorm",
"version": "v1.0.0",
"authPrincipal": [
"RAM_USER"
],
"authMethods": [],
"resources": [
{
"level": 0,
"name": "tenant",
"type": "string",
"label": "DATAWORKS_TENANT_ID",
"parent": "",
"mandatory": false,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": []
},
{
"level": 1,
"name": "instance",
"type": "string",
"label": "INSTANCE_ID",
"parent": "tenant",
"mandatory": true,
"extendedInfo": {},
"enricherFields": [
"instanceName"
],
"isValidLeaf": false,
"accessTypeRestrictions": [
"write",
"read",
"admin",
"trash",
"system",
"all"
]
},
{
"level": 2,
"name": "database",
"type": "string",
"label": "DATABASE",
"parent": "instance",
"mandatory": true,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": false,
"accessTypeRestrictions": [
"write",
"read",
"admin",
"trash",
"system",
"all"
]
},
{
"level": 3,
"name": "table",
"type": "string",
"label": "TABLE",
"parent": "database",
"mandatory": true,
"extendedInfo": {},
"recursiveSupported": false,
"enricherFields": [],
"isValidLeaf": true,
"accessTypeRestrictions": [
"write",
"read",
"admin",
"trash",
"all"
]
}
]
}