【zookeeper】zookeeper的ACL权限控制

x33g5p2x  于2022-05-11 转载在 Zookeeper  
字(17.7k)|赞(0)|评价(0)|浏览(777)

1.概述

转载并且补充:zookeeper的ACL权限控制

ACL:Access Control List 访问控制列表

关联文章:【zookeeper】ZooKeeper 权限管理与Curator增加权限验证

关联文章:【kafka】kerberos client is being asked for a password not available to garner authentication informa

1.1 简介

ACL 权限控制,使用:scheme:id:perm 来标识,主要涵盖 3 个方面:

  1.   权限模式(Scheme):授权的策略
  2.   授权对象(ID):授权的对象
  3.   权限(Permission):授予的权限

其特性如下:

  1. ZooKeeper的权限控制是基于每个znode节点的,需要对每个节点设置权限
  2. 每个znode支持设置多种权限控制方案和多个权限
  3. 子节点不会继承父节点的权限,客户端无权访问某节点,但可能可以访问它的子节点

例如:

  1. setAcl /test2 ip:128.0.0.1:crwda

1.2 scheme 采用何种方式授权

  1. world:默认方式,相当于全部都能访问
  2. auth:代表已经认证通过的用户(cli中可以通过addauth digest user:pwd 来添加当前上下文中的授权用户)
  3. digest:即用户名:密码这种方式认证,这也是业务系统中最常用的。用 username:password 字符串来产生一个MD5串,然后该串被用来作为ACL ID。认证是通过明文发送username:password 来进行的,当用在ACL时,表达式为username:base64 ,base64是password的SHA1摘要的编码。
  4. ip:使用客户端的主机IP作为ACL ID 。这个ACL表达式的格式为addr/bits ,此时addr中的有效位与客户端addr中的有效位进行比对。

1.3 ID 给谁授予权限

授权对象ID是指,权限赋予的用户或者一个实体,例如:IP 地址或者机器。授权模式 schema 与 授权对象 ID 之间

1.4 permission 授予什么权限

CREATE、READ、WRITE、DELETE、ADMIN 也就是 增、删、改、查、管理权限,这5种权限简写为crwda

注意:

这5种权限中,delete是指对子节点的删除权限,其它4种权限指对自身节点的操作权限

更详细的如下:

  1. CREATE c 可以创建子节点
  2. DELETE d 可以删除子节点(仅下一级节点)
  3. READ r 可以读取节点数据及显示子节点列表
  4. WRITE w 可以设置节点数据
  5. ADMIN a 可以设置节点访问控制列表权限

1.5 ACL 相关命令

  1. getAcl getAcl <path> 读取ACL权限
  2. setAcl setAcl <path> <acl> 设置ACL权限
  3. addauth addauth <scheme> <auth> 添加认证用户

2. 案例

2.1 测试zkCli设置权限

2.1.1 word方式

  1. [zk: localhost:2181(CONNECTED) 9] create /test1 test1-value
  2. Created /test1
  3. [zk: localhost:2181(CONNECTED) 10] getAcl /test1 #创建的默认是所有用户都可以进行cdrwa
  4. 'world,'anyone
  5. : cdrwa
  6. [zk: localhost:2181(CONNECTED) 11] setAcl /test1 world:anyone:acd #修改为所有人可以acd
  7. cZxid = 0x400000007
  8. ctime = Tue Mar 12 14:46:55 CST 2019
  9. mZxid = 0x400000007
  10. mtime = Tue Mar 12 14:46:55 CST 2019
  11. pZxid = 0x400000007
  12. cversion = 0
  13. dataVersion = 0
  14. aclVersion = 1
  15. ephemeralOwner = 0x0
  16. dataLength = 11
  17. numChildren = 0
  18. [zk: localhost:2181(CONNECTED) 12] getAcl /test1
  19. 'world,'anyone
  20. : cda

2.1.2 IP的方式

  1. [zk: localhost:2181(CONNECTED) 13] create /test2 test2-value
  2. Created /test2
  3. [zk: localhost:2181(CONNECTED) 14] setAcl /test2 ip:127.0.0.1:crwda #修改此IP具有所有权限
  4. cZxid = 0x400000009
  5. ctime = Tue Mar 12 14:51:58 CST 2019
  6. mZxid = 0x400000009
  7. mtime = Tue Mar 12 14:51:58 CST 2019
  8. pZxid = 0x400000009
  9. cversion = 0
  10. dataVersion = 0
  11. aclVersion = 1
  12. ephemeralOwner = 0x0
  13. dataLength = 11
  14. numChildren = 0
  15. [zk: localhost:2181(CONNECTED) 15] getAcl /test2
  16. 'ip,'127.0.0.1
  17. : cdrwa

当然可以设置IP的时候使用多个ip的方式,比如:

  1. [zk: localhost:2181(CONNECTED) 42] setAcl /t3 ip:192.168.0.164:cdwra,ip:127.0.0.1:cdwra
  2. cZxid = 0x400000018
  3. ctime = Tue Mar 12 15:12:59 CST 2019
  4. mZxid = 0x400000018
  5. mtime = Tue Mar 12 15:12:59 CST 2019
  6. pZxid = 0x400000018
  7. cversion = 0
  8. dataVersion = 0
  9. aclVersion = 1
  10. ephemeralOwner = 0x0
  11. dataLength = 2
  12. numChildren = 0
  13. [zk: localhost:2181(CONNECTED) 43] getAcl /t3
  14. 'ip,'192.168.0.164
  15. : cdrwa
  16. 'ip,'127.0.0.1
  17. : cdrwa

2.1.3 Auth

  1. [zk: localhost:2181(CONNECTED) 44] create /t4 44
  2. Created /t4
  3. [zk: localhost:2181(CONNECTED) 45] addauth digest qlq:111222 #增加授权用户,明文用户名和密码
  4. [zk: localhost:2181(CONNECTED) 46] setAcl /t4 auth:qlq:cdwra  #授予权限
  5. cZxid = 0x40000001d
  6. ctime = Tue Mar 12 15:16:56 CST 2019
  7. mZxid = 0x40000001d
  8. mtime = Tue Mar 12 15:16:56 CST 2019
  9. pZxid = 0x40000001d
  10. cversion = 0
  11. dataVersion = 0
  12. aclVersion = 1
  13. ephemeralOwner = 0x0
  14. dataLength = 2
  15. numChildren = 0
  16. [zk: localhost:2181(CONNECTED) 48] getAcl /t4
  17. 'digest,'qlq:JWNEexxIoeVompjU7O5pZzTU+VQ=
  18. : cdrwa

如果重新连接之后获取会报没权限,需要添加授权用户:

  1. [zk: localhost:2181(CONNECTED) 4] get /t4
  2. Authentication is not valid : /t4
  3. [zk: localhost:2181(CONNECTED) 6] addauth digest qlq:111222
  4. [zk: localhost:2181(CONNECTED) 7] get /t4
  5. 44
  6. cZxid = 0x40000001d
  7. ctime = Tue Mar 12 15:16:56 CST 2019
  8. mZxid = 0x40000001d
  9. mtime = Tue Mar 12 15:16:56 CST 2019
  10. pZxid = 0x40000001d
  11. cversion = 0
  12. dataVersion = 0
  13. aclVersion = 1
  14. ephemeralOwner = 0x0
  15. dataLength = 2
  16. numChildren = 0

2.1.3 Digest

  1. etAcl /test digest:用户名:密码:权限

密码是用户名和密码加密后的字符串。

2.1.3.1 生成密码:sha1加密之后base64编码
  1. package zd.dms.test;
  2. import java.security.MessageDigest;
  3. import java.security.NoSuchAlgorithmException;
  4. import org.apache.commons.codec.binary.Base64;
  5. public class Test {
  6. public static void main(String[] args) throws NoSuchAlgorithmException {
  7. String usernameAndPassword = "user:123456";
  8. byte digest[] = MessageDigest.getInstance("SHA1").digest(usernameAndPassword.getBytes());
  9. Base64 base64 = new Base64();
  10. String encodeToString = base64.encodeToString(digest);
  11. System.out.println(encodeToString);
  12. }
  13. }

输出:6DY5WhzOfGsWQ1XFuIyzxkpwdPo=

2.1.3.2. 设置权限
  1. [zk: localhost:2181(CONNECTED) 7] setAcl /t6 digest:user:6DY5WhzOfGsWQ1XFuIyzxkpwdPo=:crwda #授权
  2. cZxid = 0x400000028
  3. ctime = Tue Mar 12 15:50:02 CST 2019
  4. mZxid = 0x400000028
  5. mtime = Tue Mar 12 15:50:02 CST 2019
  6. pZxid = 0x400000028
  7. cversion = 0
  8. dataVersion = 0
  9. aclVersion = 1
  10. ephemeralOwner = 0x0
  11. dataLength = 4
  12. numChildren = 0
  13. [zk: localhost:2181(CONNECTED) 8] getAcl /t6
  14. 'digest,'user:6DY5WhzOfGsWQ1XFuIyzxkpwdPo=
  15. : cdrwa

直接删除会不允许,也必须增加摘要之后才能删除

  1. [zk: localhost:2181(CONNECTED) 1] rmr /t6 #直接删除没权限
  2. Authentication is not valid : /t6
  3. [zk: localhost:2181(CONNECTED) 2] addauth digest user:123456 #增加认证用户
  4. [zk: localhost:2181(CONNECTED) 3] rmr /t6
  5. [zk: localhost:2181(CONNECTED) 4] ls /
  6. [t4, curator, test2, zookeeper, test1, t3]

2.2 Java原生的zookeperAPI的ACL

2.2.1 创建节点回顾

原来我们创建节点的时候如下:

  1. package zookeper;
  2. import java.io.IOException;
  3. import java.util.concurrent.CountDownLatch;
  4. import org.apache.zookeeper.CreateMode;
  5. import org.apache.zookeeper.KeeperException;
  6. import org.apache.zookeeper.WatchedEvent;
  7. import org.apache.zookeeper.Watcher;
  8. import org.apache.zookeeper.Watcher.Event.KeeperState;
  9. import org.apache.zookeeper.ZooDefs;
  10. import org.apache.zookeeper.ZooKeeper;
  11. public class BaseAPI {
  12. private static ZooKeeper zoo;
  13. final static CountDownLatch connectedSignal = new CountDownLatch(1);
  14. public static ZooKeeper connect(String host) throws IOException, InterruptedException {
  15. zoo = new ZooKeeper(host, 5000, new Watcher() {
  16. public void process(WatchedEvent event) {
  17. if (event.getState() == KeeperState.SyncConnected) {
  18. connectedSignal.countDown();
  19. }
  20. }
  21. });
  22. connectedSignal.await();
  23. return zoo;
  24. }
  25. public void close() throws InterruptedException {
  26. zoo.close();
  27. }
  28. public static void create(String path, byte[] data) throws KeeperException, InterruptedException {
  29. zoo.create(path, data, ZooDefs.Ids.OPEN_ACL_UNSAFE, CreateMode.PERSISTENT);
  30. }
  31. public static void main(String[] args) throws IOException, InterruptedException, KeeperException {
  32. final String path = "/t7";
  33. final ZooKeeper connect = connect("127.0.0.1:2181,127.0.0.1:2182,127.0.0.1:2183");
  34. connect.create(path, "777".getBytes(), ZooDefs.Ids.OPEN_ACL_UNSAFE, CreateMode.PERSISTENT);
  35. Thread.sleep(10 * 1000);
  36. }
  37. }

可以看到create方法的第三个参数就是ACL集合,使用的是与zkCli方式一样的word:anyone:crwda 默认方式

如下:

  1. /**
  2. * This is a completely open ACL .
  3. */
  4. public final ArrayList<ACL> OPEN_ACL_UNSAFE = new ArrayList<ACL>(
  5. Collections.singletonList(new ACL(Perms.ALL, ANYONE_ID_UNSAFE)));
  6. public interface Perms {
  7. int READ = 1 << 0;
  8. int WRITE = 1 << 1;
  9. int CREATE = 1 << 2;
  10. int DELETE = 1 << 3;
  11. int ADMIN = 1 << 4;
  12. int ALL = READ | WRITE | CREATE | DELETE | ADMIN;
  13. }
  14. public interface Ids {
  15. public final Id ANYONE_ID_UNSAFE = new Id("world", "anyone");
  16. public final Id AUTH_IDS = new Id("auth", "");
  17. public final ArrayList<ACL> OPEN_ACL_UNSAFE = new ArrayList<ACL>(
  18. Collections.singletonList(new ACL(Perms.ALL, ANYONE_ID_UNSAFE)));
  19. public final ArrayList<ACL> CREATOR_ALL_ACL = new ArrayList<ACL>(
  20. Collections.singletonList(new ACL(Perms.ALL, AUTH_IDS)));
  21. public final ArrayList<ACL> READ_ACL_UNSAFE = new ArrayList<ACL>(
  22. Collections
  23. .singletonList(new ACL(Perms.READ, ANYONE_ID_UNSAFE)));
  24. }

自己手动写一个采用IP的方式设置ACL的方法:

  1. package zookeper;
  2. import java.io.IOException;
  3. import java.util.ArrayList;
  4. import java.util.List;
  5. import java.util.concurrent.CountDownLatch;
  6. import org.apache.zookeeper.CreateMode;
  7. import org.apache.zookeeper.KeeperException;
  8. import org.apache.zookeeper.WatchedEvent;
  9. import org.apache.zookeeper.Watcher;
  10. import org.apache.zookeeper.Watcher.Event.KeeperState;
  11. import org.apache.zookeeper.ZooDefs;
  12. import org.apache.zookeeper.ZooDefs.Perms;
  13. import org.apache.zookeeper.ZooKeeper;
  14. import org.apache.zookeeper.data.ACL;
  15. import org.apache.zookeeper.data.Id;
  16. public class BaseAPI {
  17. private static ZooKeeper zoo;
  18. final static CountDownLatch connectedSignal = new CountDownLatch(1);
  19. public static ZooKeeper connect(String host) throws IOException, InterruptedException {
  20. zoo = new ZooKeeper(host, 5000, new Watcher() {
  21. public void process(WatchedEvent event) {
  22. if (event.getState() == KeeperState.SyncConnected) {
  23. connectedSignal.countDown();
  24. }
  25. }
  26. });
  27. connectedSignal.await();
  28. return zoo;
  29. }
  30. public void close() throws InterruptedException {
  31. zoo.close();
  32. }
  33. public static void create(String path, byte[] data) throws KeeperException, InterruptedException {
  34. zoo.create(path, data, ZooDefs.Ids.OPEN_ACL_UNSAFE, CreateMode.PERSISTENT);
  35. }
  36. public static void main(String[] args) throws IOException, InterruptedException, KeeperException {
  37. final String path = "/t9";
  38. final ZooKeeper connect = connect("127.0.0.1:2181,127.0.0.1:2182,127.0.0.1:2183");
  39. // 创建ACL
  40. ACL acl = new ACL();
  41. // 创建Id,也可以设置构造方法传入scheme和id
  42. Id id = new Id("ip", "192.168.0.164");
  43. acl.setId(id);
  44. acl.setPerms(Perms.ALL);
  45. List<ACL> acls = new ArrayList<>();
  46. acls.add(acl);
  47. connect.create(path, "777".getBytes(), acls, CreateMode.PERSISTENT);
  48. Thread.sleep(10 * 1000);
  49. }
  50. }

获取ACL:

  1. package zookeper;
  2. import java.io.IOException;
  3. import java.util.ArrayList;
  4. import java.util.List;
  5. import java.util.concurrent.CountDownLatch;
  6. import org.apache.zookeeper.CreateMode;
  7. import org.apache.zookeeper.KeeperException;
  8. import org.apache.zookeeper.WatchedEvent;
  9. import org.apache.zookeeper.Watcher;
  10. import org.apache.zookeeper.Watcher.Event.KeeperState;
  11. import org.apache.zookeeper.ZooDefs;
  12. import org.apache.zookeeper.ZooDefs.Perms;
  13. import org.apache.zookeeper.ZooKeeper;
  14. import org.apache.zookeeper.data.ACL;
  15. import org.apache.zookeeper.data.Id;
  16. public class BaseAPI {
  17. private static ZooKeeper zoo;
  18. final static CountDownLatch connectedSignal = new CountDownLatch(1);
  19. public static ZooKeeper connect(String host) throws IOException, InterruptedException {
  20. zoo = new ZooKeeper(host, 5000, new Watcher() {
  21. public void process(WatchedEvent event) {
  22. if (event.getState() == KeeperState.SyncConnected) {
  23. connectedSignal.countDown();
  24. }
  25. }
  26. });
  27. connectedSignal.await();
  28. return zoo;
  29. }
  30. public void close() throws InterruptedException {
  31. zoo.close();
  32. }
  33. public static void create(String path, byte[] data) throws KeeperException, InterruptedException {
  34. zoo.create(path, data, ZooDefs.Ids.OPEN_ACL_UNSAFE, CreateMode.PERSISTENT);
  35. }
  36. public static void main(String[] args) throws IOException, InterruptedException, KeeperException {
  37. final String path = "/t9";
  38. final ZooKeeper connect = connect("127.0.0.1:2181,127.0.0.1:2182,127.0.0.1:2183");
  39. List<ACL> acls = connect.getACL("/t9", connect.exists("/t9", false));
  40. for (ACL acl : acls) {
  41. System.out.println(acl.getPerms());
  42. System.out.println(acl.getId());
  43. }
  44. }
  45. }
  1. 结果:
  2. 31
  3. 'ip,'192.168.0.164

2.2.2 ckCli客户端进行验证:

  1. [zk: localhost:2181(CONNECTED) 7] getAcl /t9
  2. 'ip,'192.168.0.164
  3. : cdrwa

补充:权限的计算方法:

<<:左移位,在低位处补0; &与(AND),对两个整型操作数中对应位执行布尔代数,两个位都为1时输出1,否则0。

  1. 1
  2. 10
  3. 100
  4. 1000
  5. 10000

按位与之后是:11111 也就是十进制的31.

2.2.3 修改ACL

修改节点 /t10 节点的acl访问方式采用digest:user:111222

  1. package zookeper;
  2. import java.io.IOException;
  3. import java.util.ArrayList;
  4. import java.util.List;
  5. import java.util.concurrent.CountDownLatch;
  6. import org.apache.zookeeper.CreateMode;
  7. import org.apache.zookeeper.KeeperException;
  8. import org.apache.zookeeper.WatchedEvent;
  9. import org.apache.zookeeper.Watcher;
  10. import org.apache.zookeeper.Watcher.Event.KeeperState;
  11. import org.apache.zookeeper.ZooDefs;
  12. import org.apache.zookeeper.ZooDefs.Perms;
  13. import org.apache.zookeeper.ZooKeeper;
  14. import org.apache.zookeeper.data.ACL;
  15. import org.apache.zookeeper.data.Id;
  16. import org.apache.zookeeper.data.Stat;
  17. public class BaseAPI {
  18. private static ZooKeeper zoo;
  19. final static CountDownLatch connectedSignal = new CountDownLatch(1);
  20. public static ZooKeeper connect(String host) throws IOException, InterruptedException {
  21. zoo = new ZooKeeper(host, 5000, new Watcher() {
  22. public void process(WatchedEvent event) {
  23. if (event.getState() == KeeperState.SyncConnected) {
  24. connectedSignal.countDown();
  25. }
  26. }
  27. });
  28. connectedSignal.await();
  29. return zoo;
  30. }
  31. public void close() throws InterruptedException {
  32. zoo.close();
  33. }
  34. public static void create(String path, byte[] data) throws KeeperException, InterruptedException {
  35. zoo.create(path, data, ZooDefs.Ids.OPEN_ACL_UNSAFE, CreateMode.PERSISTENT);
  36. }
  37. public static void main(String[] args) throws IOException, InterruptedException, KeeperException {
  38. final String path = "/t10";
  39. final ZooKeeper connect = connect("127.0.0.1:2181,127.0.0.1:2182,127.0.0.1:2183");
  40. // 创建ACL
  41. ACL acl = new ACL();
  42. // 创建Id,也可以设置构造方法传入scheme和id
  43. Id id = new Id("digest", "user:6DY5WhzOfGsWQ1XFuIyzxkpwdPo=");
  44. acl.setId(id);
  45. acl.setPerms(Perms.ALL);
  46. List<ACL> acls = new ArrayList<>();
  47. acls.add(acl);
  48. // 修改ACL
  49. Stat setACL = connect.setACL(path, acls, connect.exists(path, false).getAversion());
  50. // 获取Acl
  51. System.out.println(connect.getACL(path, setACL));
  52. }
  53. }
  1. 结果:
  2. [31,s{'digest,'user:6DY5WhzOfGsWQ1XFuIyzxkpwdPo=}
  3. ]
  4. zkCli客户端进行验证:
  5. [zk: localhost:2181(CONNECTED) 26] getAcl /t10
  6. 'digest,'user:6DY5WhzOfGsWQ1XFuIyzxkpwdPo=
  7. : cdrwa

2.2.4 访问上面的节点会报错没权限

  1. package zookeper;
  2. import java.io.IOException;
  3. import java.util.ArrayList;
  4. import java.util.List;
  5. import java.util.concurrent.CountDownLatch;
  6. import org.apache.zookeeper.CreateMode;
  7. import org.apache.zookeeper.KeeperException;
  8. import org.apache.zookeeper.WatchedEvent;
  9. import org.apache.zookeeper.Watcher;
  10. import org.apache.zookeeper.Watcher.Event.KeeperState;
  11. import org.apache.zookeeper.ZooDefs;
  12. import org.apache.zookeeper.ZooDefs.Perms;
  13. import org.apache.zookeeper.ZooKeeper;
  14. import org.apache.zookeeper.data.ACL;
  15. import org.apache.zookeeper.data.Id;
  16. import org.apache.zookeeper.data.Stat;
  17. public class BaseAPI {
  18. private static ZooKeeper zoo;
  19. final static CountDownLatch connectedSignal = new CountDownLatch(1);
  20. public static ZooKeeper connect(String host) throws IOException, InterruptedException {
  21. zoo = new ZooKeeper(host, 5000, new Watcher() {
  22. public void process(WatchedEvent event) {
  23. if (event.getState() == KeeperState.SyncConnected) {
  24. connectedSignal.countDown();
  25. }
  26. }
  27. });
  28. connectedSignal.await();
  29. return zoo;
  30. }
  31. public void close() throws InterruptedException {
  32. zoo.close();
  33. }
  34. public static void create(String path, byte[] data) throws KeeperException, InterruptedException {
  35. zoo.create(path, data, ZooDefs.Ids.OPEN_ACL_UNSAFE, CreateMode.PERSISTENT);
  36. }
  37. public static void main(String[] args) throws IOException, InterruptedException, KeeperException {
  38. final String path = "/t10";
  39. final ZooKeeper connect = connect("127.0.0.1:2181,127.0.0.1:2182,127.0.0.1:2183");
  40. byte[] data = connect.getData(path, false, null);
  41. System.out.println(new String(data, "UTF-8"));
  42. }
  43. }
  1. 结果:
  2. log4j:WARN No appenders could be found for logger (org.apache.zookeeper.ZooKeeper).
  3. log4j:WARN Please initialize the log4j system properly.
  4. log4j:WARN See http://logging.apache.org/log4j/1.2/faq.html#noconfig for more info.
  5. Exception in thread "main" org.apache.zookeeper.KeeperException$NoAuthException: KeeperErrorCode = NoAuth for /t10
  6. at org.apache.zookeeper.KeeperException.create(KeeperException.java:113)
  7. at org.apache.zookeeper.KeeperException.create(KeeperException.java:51)
  8. at org.apache.zookeeper.ZooKeeper.getData(ZooKeeper.java:1212)
  9. at org.apache.zookeeper.ZooKeeper.getData(ZooKeeper.java:1241)
  10. at zookeper.BaseAPI.main(BaseAPI.java:42)

解决办法:连接的connection增加用户信息

  1. package zookeper;
  2. import java.io.IOException;
  3. import java.util.concurrent.CountDownLatch;
  4. import org.apache.zookeeper.CreateMode;
  5. import org.apache.zookeeper.KeeperException;
  6. import org.apache.zookeeper.WatchedEvent;
  7. import org.apache.zookeeper.Watcher;
  8. import org.apache.zookeeper.Watcher.Event.KeeperState;
  9. import org.apache.zookeeper.ZooDefs;
  10. import org.apache.zookeeper.ZooKeeper;
  11. public class BaseAPI {
  12. private static ZooKeeper zoo;
  13. final static CountDownLatch connectedSignal = new CountDownLatch(1);
  14. public static ZooKeeper connect(String host) throws IOException, InterruptedException {
  15. zoo = new ZooKeeper(host, 5000, new Watcher() {
  16. public void process(WatchedEvent event) {
  17. if (event.getState() == KeeperState.SyncConnected) {
  18. connectedSignal.countDown();
  19. }
  20. }
  21. });
  22. connectedSignal.await();
  23. return zoo;
  24. }
  25. public void close() throws InterruptedException {
  26. zoo.close();
  27. }
  28. public static void create(String path, byte[] data) throws KeeperException, InterruptedException {
  29. zoo.create(path, data, ZooDefs.Ids.OPEN_ACL_UNSAFE, CreateMode.PERSISTENT);
  30. }
  31. public static void main(String[] args) throws IOException, InterruptedException, KeeperException {
  32. final String path = "/t10";
  33. final ZooKeeper connect = connect("127.0.0.1:2181,127.0.0.1:2182,127.0.0.1:2183");
  34. // 会话添加用户和密码信息
  35. connect.addAuthInfo("digest", "user:123456".getBytes());
  36. byte[] data = connect.getData(path, false, null);
  37. System.out.println(new String(data, "UTF-8"));
  38. }
  39. }

结果:

10

这里可能遇到这个问题:

  1. org.apache.zookeeper.KeeperException$AuthFailedException: KeeperErrorCode = AuthFailed for /baas
  2. at org.apache.zookeeper.KeeperException.create(KeeperException.java:130)
  3. at org.apache.zookeeper.KeeperException.create(KeeperException.java:54)
  4. at org.apache.zookeeper.ZooKeeper.exists(ZooKeeper.java:2021)
  5. at org.apache.zookeeper.ZooKeeper.exists(ZooKeeper.java:2049)
  6. at org.apache.curator.utils.ZKPaths.mkdirs(ZKPaths.java:215)
  7. at org.apache.curator.utils.EnsurePath$InitialHelper$1.call(EnsurePath.java:148)
  8. at org.apache.curator.RetryLoop.callWithRetry(RetryLoop.java:107)
  9. at org.apache.curator.utils.EnsurePath$InitialHelper.ensure(EnsurePath.java:141)
  10. at org.apache.curator.utils.EnsurePath.ensure(EnsurePath.java:99)
  11. at org.apache.curator.framework.recipes.cache.NodeCache.start(NodeCache.java:159)
  12. at org.apache.curator.framework.recipes.cache.NodeCache.start(NodeCache.java:145)
  13. at com.zookeeper.ZkCuratorFramework.addListenerForEachePath(ZkCuratorFramework.java:173)
  14. at com.zookeeper.ZkCuratorFramework.useCuratorFramework(ZkCuratorFramework.java:128)
  15. at com.zookeeper.ZookeeperKerberosCase.main(ZookeeperKerberosCase.java:33)

此处可以参考文章:【Kafka】Kakfa KeeperErrorCode = AuthFailed for /consumers

这个需要

  1. kerberos验证通过,没有的话跳过
  2. 设置用户名和密码
  3. 操作前设置权限

操作路径前,必须设置ack权限

使用下面这两种授权方式都可以

  1. //
  2. // SetACLBuilder setACLBuilder = zkClient.setACL();
  3. //
  4. // List<ACL> aclList = new ArrayList<>();
  5. // ACL acl = new ACL();
  6. // String pwd = "xxx";
  7. // // 创建Id,也可以设置构造方法传入scheme和id
  8. // Id id = new Id("digest", "zkroot:"+pwd);
  9. // acl.setId(id);
  10. // acl.setPerms(ZooDefs.Perms.ALL);
  11. //
  12. // aclList.add(acl);
  13. // setACLBuilder.withACL(aclList);

第二种

  1. SetACLBuilder setACLBuilder = zkClient.setACL();
  2. List<ACL> aclList = new ArrayList<>();
  3. ACL acl = new ACL();
  4. // 创建Id,也可以设置构造方法传入scheme和id
  5. Id id = new Id("digest", "xxx");
  6. acl.setId(id);
  7. acl.setPerms(ZooDefs.Perms.ALL);
  8. aclList.add(acl);
  9. setACLBuilder.withACL(aclList);

正常的结果如下

  1. 打印acl:/baas/flink/security_events/correlation
  2. 权限:31
  3. 权限:'world,'anyone
  4. 启动:/baas/flink/security_events/correlation
  5. 启动路径成功:/baas/flink/security_events/correlation
  6. 完毕:/baas/flink/security_events/correlation
  7. 添加监听完毕

2022深度学习开发者峰会

5月20日13:00让我们相聚云端,共襄盛会!

相关文章