Zookeeper's ACL (Access Control List) permissions are especially important in production environments, so this chapter provides a special introduction.

ACL permissions can set related read/write permissions for nodes to ensure data security.

permissions can specify different permission scopes and roles.

ACL Command Line

  • getAcl command: Get the ACL permission information of a node.
  • setAcl command: Set the ACL permission information of a node.
  • addauth command: Enter authentication and authorization information. Enter the plaintext password during registration, and it is saved in encrypted form.

ACL Composition

Zookeeper's ACL consists of[scheme:id:permissions]to form the permission list.

  • 1、scheme: Represents the permission mechanism adopted, including world, auth, digest, ip, super.
  • 2、id: Represents the users allowed to access.
  • 3、permissions: Permission combination string, composed of cdrwa, where each letter represents a different permission: create permission (c), delete permission (d), read permission (r), write permission (w), admin permission (a).

world Example

Check the default node permissions, then update the node's permissions section to crwa. As a result, deleting the node fails. Here, world represents open permissions.

$ getAcl /example/child
$ setAcl /example/child world:anyone:crwa
$ delete /example/child

auth Example

auth is used to grant permissions. Note that you need to create a user first.

$ setAcl /example/child auth:user1:123456:cdrwa
$ addauth digest user1:123456
$ setAcl /example/child auth:user1:123456:cdrwa
$ getAcl /example/child

digest Example

Log out of the current user, reconnect to the terminal. digest can be used for account/password login and verification.

$ ls /example
$ create /example/child01 example
$ getAcl /example/child01
$ setAcl /example/child01 digest:user1:HYGa7IZRm2PUBFiFFu8xY2pPP/s=:cdra
$ getAcl /example/child01
$ addauth digest user1:123456
$ getAcl /example/child01

Note:The encrypted password is the one created in the previous step.

IP Example

Restrict IP address access permissions. After setting permissions to IP address 192.168.3.7, the IP 192.168.3.38 no longer has access permissions.

$ create /example/ip 0
$ getAcl /example/ip
$ setAcl /example/ip ip:192.168.3.7:cdrwa
$ get /example/ip