- ACL机制:
- Scheme
>World
>Auth
>Digest
>Ip
>Super
>Sasl(zk3.4.4,默认关闭)
- Id
>id与scheme配合使用
- Permissions
>Create(c)
>Delete(d)
>Read(r)
>Write(w)
>Admin(a)
>Delete(d)
>Read(r)
>Write(w)
>Admin(a)
- 代码例子:
import java.io.IOException;
import java.security.NoSuchAlgorithmException;
import java.util.ArrayList;
import java.util.List;
import org.apache.zookeeper.CreateMode;
import org.apache.zookeeper.KeeperException;
import org.apache.zookeeper.ZooDefs;
import org.apache.zookeeper.data.ACL;
import org.apache.zookeeper.data.Id;
import org.apache.zookeeper.server.auth.DigestAuthenticationProvider;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import com.sohu.zk.main.ZkUtils;
public class ZkTester {
private final static Logger LOG = LoggerFactory.getLogger(ZkTester.class);
public static final String zk_url = "10.11.156.226:2181";
public static final String zk_user = "prodev-v1";
public static final String zk_pwd = "1010abc102c0440eb424835a9aa4c16b";
public static final int zk_timeout = 5000;
public void createAuthByIp(ZkUtils z, String path, String data, String ip)
public void createAuthByAuth(ZkUtils z, String path, String data)
public void createAuthByWorld(ZkUtils z, String path, String data) {
try {
List<ACL> acls = new ArrayList<ACL>();
z.connect(zk_url, zk_timeout);
Id id = new Id("world", "anyone");
ACL acl = new ACL(ZooDefs.Perms.READ, id);
acls.add(acl);
z.createByIds(path, data.getBytes(), acls, CreateMode.PERSISTENT);
} catch (IOException e) {
e.printStackTrace();
} catch (KeeperException e) {
e.printStackTrace();
} catch (InterruptedException e) {
e.printStackTrace();
}
}
public void createAuthByDigest(ZkUtils z, String path, String data) {
try {
List<ACL> acls = new ArrayList<ACL>();
z.connectByAuth(zk_url, zk_user, zk_pwd, zk_timeout);
Id id1 = new Id("digest",
DigestAuthenticationProvider.generateDigest(String.format(
"%s:%s", zk_user, zk_pwd)));
ACL acl1 = new ACL(ZooDefs.Perms.ALL, id1);
acls.add(acl1);
z.createByIds(path, data.getBytes(), acls, CreateMode.PERSISTENT);
} catch (IOException e) {
e.printStackTrace();
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (KeeperException e) {
e.printStackTrace();
} catch (InterruptedException e) {
e.printStackTrace();
}
}
public static void main(String arg[]) throws InterruptedException{
ZkUtils z = new ZkUtils();
// 添加第一个id,采用用户名密码形式
new ZkTester().createAuthByDigest(z, "/services", "digest");
// 添加第二个id,所有用户可读权限
new ZkTester().createAuthByWorld(z, "/services123", "world");
z.close();
}
}
import java.io.IOException;
import java.util.List;
import java.util.concurrent.CountDownLatch;
import org.apache.zookeeper.CreateMode;
import org.apache.zookeeper.KeeperException;
import org.apache.zookeeper.WatchedEvent;
import org.apache.zookeeper.Watcher;
import org.apache.zookeeper.Watcher.Event.KeeperState;
import org.apache.zookeeper.ZooDefs.Ids;
import org.apache.zookeeper.ZooKeeper;
import org.apache.zookeeper.data.ACL;
import org.apache.zookeeper.data.Stat;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class ZkUtils implements Watcher {
private final static Logger LOG = LoggerFactory.getLogger(ZkUtils.class);
private ZooKeeper zooKeeper;
protected CountDownLatch countDownLatch = new CountDownLatch(1);
public void connectByAuth(String hosts, String user, String pwd,
int sessiontime) throws IOException, InterruptedException {
zooKeeper = new ZooKeeper(hosts, sessiontime, this);
zooKeeper.addAuthInfo("digest", (user + ":" + pwd).getBytes());
countDownLatch.await();
}
public void connect(String hosts, int sessiontime) throws IOException,
InterruptedException {
zooKeeper = new ZooKeeper(hosts, sessiontime, this);
countDownLatch.await();
}
/**
* 创建持久态的znode,比支持多层创建.比如在创建/parent/child的情况下,无/parent.无法通过.
*
* @param path
* eg: /parent/child1
* @param data
* @throws InterruptedException
* @throws KeeperException
*/
public void create(String path, byte[] data) throws KeeperException,
InterruptedException {
this.zooKeeper.create(path, data, Ids.CREATOR_ALL_ACL,
CreateMode.PERSISTENT/* 此处创建的为持久态的节点,可为瞬态 */);
}
public void createByIds(String path, byte[] data, List<ACL> acls,
CreateMode mode) throws KeeperException, InterruptedException {
this.zooKeeper.create(path, data, acls, mode);
}
public void setACL(String path, List<ACL> acls, int version) throws KeeperException, InterruptedException{
this.zooKeeper.setACL(path, acls, version);
}
/**
* 获取节点的孩子信息
*
* @param path
* @throws KeeperException
* @throws InterruptedException
*/
public void getChild(String path) throws KeeperException,
InterruptedException {
try {
List<String> children = this.zooKeeper.getChildren(path, false);
if (children.isEmpty()) {
LOG.info("zk [%s] not node.", path);
return;
} else {
LOG.info("zk [%s] node.", path);
for (String child : children) {
System.out.println(child);
}
}
} catch (KeeperException.NoNodeException e) {
LOG.error("zk [%s] NoNodeException.", path);
throw e;
}
}
public byte[] getData(String path) throws KeeperException,
InterruptedException {
return this.zooKeeper.getData(path, false, null);
}
public List<ACL> getAcl(String path) throws KeeperException,
InterruptedException {
return this.zooKeeper.getACL(path, new Stat());
}
public void process(WatchedEvent event) {
if (event.getState() == KeeperState.SyncConnected) {
countDownLatch.countDown();
}
}
public void close() throws InterruptedException {
zooKeeper.close();
}
}
Zookeeper的ACL(Access Control List)机制用于实现细粒度的权限控制,包括Scheme、Id和Permissions三个核心概念。Scheme定义了认证方式,如digest、world、auth等;Id是特定认证的身份标识,如用户名和密码;Permissions则规定了允许的操作,如读、写、创建、删除等。通过结合使用这些元素,Zookeeper可以确保数据的安全访问。在实际应用中,可以通过代码示例设置和验证不同的ACL策略。
428

被折叠的 条评论
为什么被折叠?



