Repository navigation
Conversation
grantforge-agent-core runs on Java 8 inside the systems GrantForge protects. GrantForgeAgent sends heartbeats, downloads the service's snapshot when the policy version changes, checks its Ed25519 signature with Bouncy Castle, builds a policy engine from it with Jackson 2 and keeps the last good snapshot on disk for starts without the server. Decisions add the roles and groups the snapshot gives the user; access events go out in batches and are spooled to disk while the server is away.
At a million accounts every user list page sorted the whole tenant and counted it again. An index on tenant, creation time and id lets the database walk the newest accounts, and the search first reads up to 1000 matches unordered: that many or fewer are ordered in memory and counted for free, so a rare match no longer runs the ordered scan through the whole table. The console application's id is kept per catalog version, which application changes now raise, removing a query from every API call.
A search for accounts whose name, display name or address contains the text scanned every account; at a million that took 250-400 ms. On PostgreSQL the migration enables pg_trgm where the database allows it and adds trigram indexes matching the search's expressions, which brings the search to a few tens of milliseconds. Without the extension, and on the other databases, nothing changes.
The hdfs service type declares paths, matched as paths and optionally with everything below them, with read, write and execute. Testing a connection and looking up paths go through WebHDFS or HttpFS with the JDK's HTTP client, so no Hadoop client is needed and any Hadoop version works; several NameNode addresses are tried in turn, skipping standby ones. The plugin is packaged with its own Jackson and the release unpacks it into plugins/hdfs.
Dependency ReviewThe following issues were found:
License Issuespom.xml
core/grantforge-agent-core/pom.xml
core/grantforge-plugin-host/pom.xml
plugins/grantforge-agent-hdfs/pom.xml
plugins/grantforge-plugin-hdfs/pom.xml
OpenSSF ScorecardScorecard details
Scanned Files
|
The architecture rules forbid Optional.get, which the account page used, so every test job failed on the identity module's architecture test.
Every API call reads the console snapshot; the evaluator only reads, so its transactions skip flushing and dirty checking. The cached path's p99 was 1.014 ms against a 1 ms limit.
A server started from an IDE runs from build output folders and has no plugins folder, so no plugin loaded. Without an explicit grantforge.plugins.directory and without a plugins folder in the working directory, the host now uses the plugins folder of the repository its classes were built in, and a built plugin module loads from target/classes with the dependencies its build copied to target/plugin-lib. Server and service tests keep an empty plugins folder.
The HDFS service type used WebHDFS only. It now uses Hadoop's shaded client, so a service names its cluster as Hadoop does (hdfs:// with HA nameservices, webhdfs://, swebhdfs://, viewfs://), takes Ranger's settings under their names, and signs the lookup user in with simple authentication or Kerberos by keytab or password. A real KDC tests the Kerberos logins.
The example plugin, a test fixture, showed up as a service type in IDE runs and was picked by mistake. A module now loads as a plugin only when its build copied its libraries to target/plugin-lib, as installable plugins do.
The server declared the plugin's zip as a dependency, which exists only from the package phase on, so every CI job that stops at test failed to resolve it. The root pom now builds the plugin before the server, which unpacks the zip at prepare-package for the release.
The Bouncy Castle Licence is the MIT license under its own name; the review reported it as non-standard.
A push reports the branch's previous tip as the range start; after a force push that commit is gone from the clone, and the check crashed on an invalid range. It now checks the branch from where it left the default branch, as for a pull request, or the head alone without one.
Lookups can start from a configured directory (lookup.path) for users who may not list the root, and stop with an error above lookup.max.entries instead of scanning huge folders. Cluster URIs, authentication and the additional properties are validated as Hadoop will use them, and the whole call is serialized because UGI keeps its security settings in static state. Lookup input may be as long as a policy resource value.
An agent that denies access without a matching policy still enforces GrantForge's rules, so its access events say so. The undetermined decision before a snapshot is now public for agents to use.
grantforge-agent-hdfs authorizes HDFS access inside the NameNode with the signed local policies of the agent core and ships access events; snapshot paths are also checked against the paths they copy. The release carries it in agents/hdfs, and the documentation has a page on deploying it.
| // Lock the whole call: serializing just the login allows another service to change UGI's static | ||
| // authentication and auth-to-local settings before this service opens its own file system. | ||
| // Waiting is interruptible so the host's call timeout can cancel a queued lookup. | ||
| LOGIN.lockInterruptibly(); |
script/release/tag.sh checks the tree and the branch, sets the version everywhere, tags v<version> and pushes it, and can move the branch on to the next version; --dry-run only previews. The GitHub release notes are now every commit since the previous release, grouped by type with links, instead of a changelog page; AuthX's bare version tags such as 1.0.6 count as releases, marker tags do not.
The release profile adds sources, Javadoc and GPG signatures; the release workflow deploys them to GitHub Packages and, when the Central Portal token and the GPG key are set as secrets, to Maven Central through the central profile. That profile publishes only with -Dcentral.skip=false, so a local build with Central credentials in settings.xml uploads nothing. The example plugin, a test fixture, is never published.
The database jobs build a few modules with -pl, which leaves out the HDFS agent, so the server's prepare-package could not copy it and every database job failed. grantforge.bundle.skip turns the plugin and agent bundling off; the database tests set it, full builds keep bundling.
The HDFS agent brings hadoop-shaded-protobuf_3_25, licensed under Apache-2.0, BSD-3-Clause, MIT and protobuf's BSD-style licence, all permissive; dependency review rejected the combination.
The README describes the rebuilt platform in English, with the same content in README.zh-CN.md, and links the documentation at grantforge.devlive.org, where the site is now published.
maven-javadoc-plugin, which writes the release's Javadoc jars and is never shipped, combines Apache-2.0 with BSD, MIT and public domain parts, which dependency review rejected.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changelog category (leave one)
Changelog entry (Details of this change)
Affected version