My Oracle Support Banner

Sentry on Oracle Big Data Appliance FAQ (Doc ID 1683834.1)

Last updated on NOVEMBER 04, 2019

Applies to:

Big Data Appliance Integrated Software - Version 2.5.0 and later
Linux x86-64

Purpose

Frequently Asked Questions for Sentry on the BDA.

Questions and Answers

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Purpose
Questions and Answers
 What is Apache Sentry?
 What is the best place to learn more about Sentry?
 Does the Mammoth install automatically configure Sentry?
 Can Apache Sentry authorization be enabled and disabled with mammoth-reconfig?
 Does Sentry require Kerberos?
 When installing Sentry, is a valid Sentry policy file required?
 Is there a recommended approach for configuring Sentry if you are upgrading from BDA 2.5 to BDA 3.*?
 Can Sentry be installed in BDA 3.* if Kerberos is already installed/configured?
 Does Sentry require HiveServer2?
 In CDH 5.0.1/BDA 3.0.1 does Sentry provide column-level security?
 What are the advantages of Sentry vs control using HDFS permissions?
 In CDH 5.0.1/BDA 3.0.1 does Sentry handle metadata authorization?
 Is it possible to change permissions of directories controlled by Sentry?
 In CDH 5.0.1/BDA 3.0.1 do commands which reference a URI require URI privilege?
 Does BDA V4.0.0 support Sentry as a service?
 Can Hive BDR replication be done with Sentry in place?
 If we use the recommended approach by Cloudera (use policy files & manually copy them) are we losing the possibility of using HDFS Sentry Plugin?
 We are able to replicate data and metadata not sentry permissions, is it correct that we cannot automate this now and will have to replicate Sentry permissions manually within datacenters for now?
 Sentry service is configured on BDA which is a single point of failure, can we enable HA on sentry service on BDA?
 Is it possible to see the "explain plan" in Sentry and Impala before executing the sql or only after running it?
 When using Sentry with hive on the BDA, if a user is granted ALL privileges, can that user drop the actual Hive database created under Sentry HDFS Path Prefixes and effectively remove the database so that no other users can access it?
 Is there any workaround which would grant users full access to a separate Hive database work area while still providing access to the Hive database under Sentry HDFS Path Prefixes?
References

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.