如何阻止Zeppelin用户查看shiro.ini文件内容?
Great question—this is a critical security gap many Zeppelin users run into, since sensitive auth configs like shiro.ini need to be accessible to the Zeppelin service but shouldn’t be readable by arbitrary users running code in notebooks. Your post-startup permission fix works, but here are more elegant, sustainable solutions:
1. Run Interpreters as a Low-Privilege User
The core issue is that your Python interpreter runs with the same permissions as the Zeppelin service itself. By isolating interpreters to a restricted user, you can deny them access to shiro.ini while keeping it readable by the main Zeppelin process:
- Create a dedicated low-privilege user (e.g.,
zeppelin-interp) with no access to Zeppelin’s config directory:useradd -m zeppelin-interp chmod o-rwx <path_to_zeppelin_folder>/conf - Open Zeppelin’s interpreter settings for Python, set the
runAsproperty tozeppelin-interp, and save the configuration. - Set
shiro.inipermissions to only allow the main Zeppelin service user to read it:chmod 600 <path_to_zeppelin_folder>/conf/shiro.ini chown zeppelin:zeppelin <path_to_zeppelin_folder>/conf/shiro.ini
Now the Python interpreter runs as a user who can’t read shiro.ini, while the Zeppelin service still has access to load auth settings.
2. Remove Sensitive Data from shiro.ini Using Environment Variables
Shiro supports injecting values from environment variables, so you can move all sensitive content (like password hashes) out of shiro.ini entirely:
- Modify your
shiro.inito reference environment variables instead of hardcoding sensitive data:[users] admin = ${ADMIN_PWD_HASH}, admin editor = ${EDITOR_PWD_HASH}, editor [main] # Keep non-sensitive configs here - Before starting Zeppelin, export the environment variables with your pre-hashed passwords (use Shiro’s password hashing tool to generate these):
export ADMIN_PWD_HASH="your-shiro-hashed-password" export EDITOR_PWD_HASH="another-shiro-hashed-password" ./bin/zeppelin-daemon.sh start
Even if someone reads shiro.ini now, it only contains variable references—no actual credentials.
3. Restrict Dangerous Functions in the Python Interpreter
You can block access to system command functions in the Python interpreter to prevent users from executing cat or other file-reading commands. Add an initialization script to the Python interpreter’s settings:
- In Zeppelin’s Python interpreter config, find the
zeppelin.python.initproperty and set it to a script path (e.g.,/opt/zeppelin/python_restrict.py). - Create the script with code to disable risky functions/modules:
import os import sys # Disable direct system command calls del os.system del os.popen # Block subprocess module entirely if 'subprocess' in sys.modules: del sys.modules['subprocess'] sys.modules['subprocess'] = None
This adds a layer of defense against trivial attempts to read system files. Note: Determined users might find workarounds, so combine this with the other methods above.
4. Use File System ACLs for Granular Access Control
If your OS supports POSIX ACLs (most modern Linux distros do), you can set precise permissions that only allow the Zeppelin service user to read shiro.ini, even if interpreters run under the same user group:
# Set base permissions to 600 chmod 600 <path_to_zeppelin_folder>/conf/shiro.ini # Add ACL rule granting read access only to the zeppelin service user setfacl -m u:zeppelin:r <path_to_zeppelin_folder>/conf/shiro.ini # Remove all access for other users/groups setfacl -m g::- <path_to_zeppelin_folder>/conf/shiro.ini setfacl -m o::- <path_to_zeppelin_folder>/conf/shiro.ini
This ensures no other user (even those in the same group) can read the file, while Zeppelin’s main process still has the access it needs.
内容的提问来源于stack exchange,提问作者MetallicPriest

