[FEATURE] Support Apache Ranger as Group Provider
- Dominant language
- Scala
- Stars
- 2.4k
- Forks
- 1k
- PR merge metrics
- No merged PRs in 30d
Description
### Code of Conduct
- [x] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)
### Search before asking
- [x] I have searched in the [issues](https://github.com/apache/kyuubi/issues?q=is%3Aissue) and found no similar issues.
### Describe the feature
Apache Kyuubi currently supports the GROUP engine share level and integrates with Apache Ranger as an authorizer solution. Apache Ranger also maintains a user-group mapping store. This feature request proposes leveraging Apache Ranger's user-group mapping store to enhance Kyuubi's group provider functionality, enabling Kyuubi to extract and utilize user-group mappings directly from Ranger.
### Motivation
Integrating Apache Ranger as a group provider
### Describe the solution
_No response_
### Additional context
_No response_
### Are you willing to submit PR?
- [ ] Yes. I would be willing to submit a PR with guidance from the Kyuubi community to improve.
- [x] No. I cannot submit a PR at this time.
Contributor guide
Research direction
The issue names no files, tests, or entry points. Start by locating Kyuubi's existing group provider and Apache Ranger authorizer integrations, then clarify how Ranger's user-group mapping store should be accessed and used. Done should include an agreed design and verified user-group mapping behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- scala
- Domain
- authorization, backend
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100