Ranger GCS Plugin Known Limitations

Consider the following limitations when you use the Ranger GCS plugin:

  • Operation logging is not available: The plugin does not currently provide active logging for operations performed on GCS buckets.

  • Ranger and IAM user names must match: Ranger user names must exactly match the corresponding Google Cloud IAM user names.

  • Ranger groups are not supported: Ranger group mappings to GCS are not currently supported.

  • Ranger roles are not supported: Ranger roles cannot be mapped to Google Cloud IAM roles.

  • Supported GCS actions are limited: The plugin currently supports BucketsList, BucketsGet, ObjectsList, ObjectsGet, ObjectsCreate, and ObjectsDelete.

  • Bucket creation is not supported: You cannot create new GCS buckets from Ranger.

  • Only one policy is supported for a resource combination: Only one Ranger policy can exist for a specific resource combination.

  • Reverse synchronization is not supported: Ranger cannot automatically import existing GCS bucket policies or ACLs.

  • Existing GCS permissions can be overwritten: When Ranger manages a GCS resource, it overwrites the existing resource-based GCS ACLs or policies for that resource based on the Ranger policy configuration.

Review existing GCS permissions before you enable Ranger policy synchronization. Synchronization can change or remove existing resource-based permissions.


  Last updated