Skip to content

RANGER-5723: Plugin SPIFFE outbound auth for audit-server destination - #1139

Merged
ramackri merged 18 commits into
apache:masterfrom
ramackri:RANGER-5723-patch
Aug 22, 2026
Merged

RANGER-5723: Plugin SPIFFE outbound auth for audit-server destination#1139
ramackri merged 18 commits into
apache:masterfrom
ramackri:RANGER-5723-patch

Conversation

@ramackri

@ramackri ramackri commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Plugin outbound SPIFFE authentication for RANGER-5655 audit delivery.

JIRA: RANGER-5723

Split from closed #1135. Self-contained — compiles and tests against master without #1137.

Changes (7 files)

Area Files Purpose
SPIFFE utilities (common-utils) PluginHeaderAuthConfig, SpiffeIdentityResolver, tests Read audit XML auth props; resolve SPIFFE ID (value → file → env)
REST client (agents-common) RangerRESTClient.java setTrustedAuthHeaders() — apply X-Spiffe-Id on every outbound request
Audit destination RangerAuditServerDestination.java, test, pom.xml Wire SPIFFE headers on init when authn.header.enabled=true

Aligned with RANGER-5700 / #1096: auth is configured on the audit destination prefix, not per-plugin security XML.

Audit XML properties (plugin → ingestor)

Prefix: xasecure.audit.destination.auditserver

Property Required? Default Purpose
authn.header.enabled Yes (to enable) false Master switch
authn.header.spiffe No X-Spiffe-Id Header name for workload SPIFFE ID
authn.spiffe.value No (unset) Explicit SPIFFE ID (highest priority)
authn.spiffe.file No /var/run/secrets/spiffe.io/identity/spiffe SPIRE/agent identity file

Resolution order: authn.spiffe.valueauthn.spiffe.fileSPIFFE_ID env.

Minimum enable:

<property>
  <name>xasecure.audit.destination.auditserver.authn.header.enabled</name>
  <value>true</value>
</property>

Also required (unchanged): xasecure.audit.destination.auditserver=true and .url.

Safety: defaults to disabled; no install-template changes. E2E ingestor validation requires RANGER-5722 (AuditHeaderAuthFilter).

Related PRs

PR JIRA Scope
#1137 RANGER-5719 Partition plan library (parallel)
#1138 RANGER-5720 DB patch 078 (parallel)
This PR RANGER-5723 SPIFFE outbound for audit-server destination
(future) RANGER-5722 Ingestor inbound SPIFFE

Test plan

  • mvn -pl agents-audit/dest-auditserver -am test -Dtest=RangerAuditServerDestinationTest
  • mvn -pl common-utils test -Dtest=PluginHeaderAuthConfigTest
  • CI: build-17, plugins-docker-build

Add PluginHeaderAuthConfig, SpiffeIdentityResolver, and
RangerRESTClient.setTrustedAuthHeaders(); wire SPIFFE headers into
RangerAuditServerDestination when audit XML authn.header.enabled=true.
ramackri pushed a commit to ramackri/ranger that referenced this pull request Aug 6, 2026
…uting

Add agents-common partition plan model, allocator, validator, routing helpers,
and PolicyDownloadAuthUsersUtil for RANGER-5655. SPIFFE header utilities
move to RANGER-5723 (apache#1139).
@ramackri
ramackri force-pushed the RANGER-5723-patch branch from aa1a2e3 to 143fa62 Compare August 6, 2026 03:15
ramk added 2 commits August 6, 2026 14:11
Drop configPrefixForServiceType, resolveEnabledConfigPrefix, and
RANGER_CONFIG_PREFIX; audit destination passes an explicit config prefix to
buildSpiffeAuthHeaders.
@ramackri
ramackri requested a review from kumaab August 7, 2026 17:15
Remove redundant SPIFFE ID trim, add misconfiguration and REST client
header tests, and document that SPIFFE header auth is additive to authn.type.
Add blank line between javax and java import groups required by
dev-support/checkstyle.xml ImportOrder rule.
Fix SpiffeIdentityResolver checkstyle violations, rename buildSpiffeAuthHeaders
to buildTrustedAuthHeaders, and add generic authn.header.headers slot-based
configuration with file:/env: value resolution.
Expand PluginHeaderAuthConfig Javadoc for legacy SPIFFE and generic slot
configuration, including file:/env:/literal value spec examples.
Address PR review: configure outbound trusted headers as
authn.header.{Header-Name}=value specs (file:/env:/literal) instead
of slot-based or legacy SPIFFE properties.
@ramackri
ramackri force-pushed the RANGER-5723-patch branch 2 times, most recently from 1b9ff79 to 23f4e51 Compare August 16, 2026 17:23
ramk and others added 3 commits August 16, 2026 23:43
Address PR review: trusted outbound headers pass resolved values
through without SPIFFE format checks; remove SpiffeIdentityResolver
and obsolete tests for the old authn.spiffe.* resolution model.
…config.

HTTP header order does not affect auth; iterate props directly per review feedback.
@ramackri
ramackri merged commit 8e7716c into apache:master Aug 22, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants