Slackbot
03/08/2023, 7:06 PMBen Krug
03/08/2023, 8:21 PMMichael Taranov
03/09/2023, 7:07 AMBen Krug
03/09/2023, 7:28 PMGian Merlino
03/10/2023, 2:09 AMallowAll in your chain at the end. this means that for people that don't attempt to authenticate at all, they'll get allowAllGian Merlino
03/10/2023, 2:09 AMallowAllMichael Taranov
03/12/2023, 11:27 AMdruid.auth.authenticatorChain=["metadata-auth", "ldap", "anonymous"],
druid.auth.authenticator.anonymous.type=anonymous
druid.auth.authenticator.anonymous.identity=defaultUser
druid.auth.authenticator.anonymous.authorizerName=allowAll
druid.auth.authorizers=["metadata-authz", "ldapauth", "allowAll"]
druid.auth.authorizer.allowAll.type=allowAll
Wasn’t sure about the escalator part
druid.escalator.type=noop
druid.escalator.authorizerName=allowAll
But in the end it is working even without escalator configuration at all
About
druid.auth.authorizer.allowAll.type=allowAll
Wasn’t sure why I needed to add it, but without it its not working
I tried this on one node cluster, but going to test this on multi-node staging clusterMichael Taranov
03/12/2023, 11:29 AMMichael Taranov
03/12/2023, 12:10 PMGian Merlino
03/13/2023, 9:09 PMMichael Taranov
03/14/2023, 8:30 AMallowAll to druid.auth.authorizers but needed to add also following line to make it work otherwise it was yelling on “missing type”
druid.auth.authorizer.allowAll.type=allowAll 🤷♂️Gian Merlino
03/15/2023, 2:25 AMGian Merlino
03/15/2023, 2:25 AMBen Krug
03/17/2023, 11:37 PMMichael Taranov
03/20/2023, 2:54 PMWARN [main] org.apache.druid.security.basic.authorization.db.cache.CoordinatorPollingBasicAuthorizerCacheManager - cachedSerializedGroupMappingMap is not available from the coordinator, skipping fetch of group mappings for now.
Maybe worth to add the order of service restarts, after Auth changes, to the documentation.Michael Taranov
03/22/2023, 6:38 AMMichael Taranov
03/22/2023, 6:38 AMBen Krug
03/24/2023, 1:57 PM