apache / apache/kyuubi

[FEATURE] Add Kyuubi Flink AuthZ Extension

Open
#6,714 0 comments 0 reactions 0 assignees View on GitHub
kind:feature priority:major
Dominant language
Scala
Stars
2.4k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

### Code of Conduct

- [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

### Search before asking

- [X] I have searched in the [issues](https://github.com/apache/kyuubi/issues?q=is%3Aissue) and found no similar issues.

### Describe the feature

We propose the addition of a Kyuubi Flink AuthZ (Authorization) extension to enhance fine-grained access control and security for users running Flink workloads through Kyuubi. This feature would extend Kyuubi’s existing authorization capabilities to better integrate with Apache Flink and manage user permissions more effectively.

### Motivation

_No response_

### Describe the solution

_No response_

### Additional context

_No response_

### Are you willing to submit PR?

- [ ] Yes. I would be willing to submit a PR with guidance from the Kyuubi community to improve.
- [X] No. I cannot submit a PR at this time.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or implementation entry points. Start by reviewing Kyuubi’s existing authorization capabilities and Flink integration, then clarify the proposed design, permission model, and scope with the community. Done should include an agreed implementation plan and corresponding tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
scala
Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.