Presto仅为集群外部访问配置认证方案求助
解决方案:Presto集群内部无认证、外部访问需认证的配置方案
我之前也碰到过类似的场景——既要让集群内部节点/用户方便访问Presto不用输凭证,又要保障外部访问的安全性,给你两个可行的解决方案,亲测有效:
方案一:反向代理层做认证隔离(推荐,配置简单)
核心思路是用反向代理(比如Nginx)把外部流量和内部流量分开:内部直接访问Presto的内网端口,外部必须经过代理并通过认证。
步骤:
- 调整Presto绑定IP:修改Presto coordinator节点的
config.properties,让它只绑定内网IP,避免直接暴露给外部:http-server.http.port=8080 http-server.http.address=192.168.0.10 # 替换成你的coordinator内网IP - 配置Nginx反向代理:在有公网IP的节点上部署Nginx,配置如下(记得替换成你的实际信息):
server { listen 80; # 外部访问的端口,也可以用443配HTTPS server_name your-presto-public-domain; # 或者公网IP # 开启HTTP Basic认证,也可以换成LDAP/OAuth等更复杂的认证 auth_basic "Presto External Access"; auth_basic_user_file /etc/nginx/.htpasswd; location / { proxy_pass http://192.168.0.10:8080; # 指向Presto coordinator的内网地址 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } } - 生成认证账号:用
htpasswd命令生成认证文件:
执行后输入密码即可,后续加用户去掉htpasswd -c /etc/nginx/.htpasswd external-user-c参数。
方案二:Presto内置认证+IP白名单
如果不想加代理层,可以直接用Presto的认证和访问控制功能,通过IP段区分内部/外部请求。
步骤:
- 启用Presto认证:修改coordinator节点的
config.properties:# 开启密码认证,也可以换成LDAP等 http-server.authentication.type=PASSWORD http-server.authentication.password.file=/etc/presto/password.db # 允许未认证请求,后续通过访问控制限制 http-server.authentication.allow-unauthenticated=true # 启用文件型访问控制 access-control.name=file security.config-file=/etc/presto/security.json - 生成认证密码文件:同样用
htpasswd生成:htpasswd -c -B /etc/presto/password.db external-user - 配置IP白名单规则:创建
/etc/presto/security.json,允许内网IP无认证访问,外部IP必须认证:{ "rules": [ { "resource": "server", "action": "access", "condition": { "ipAddress": "192.168.0.0/16" # 替换成你的内网IP段 }, "effect": "ALLOW" }, { "resource": "server", "action": "access", "condition": { "authenticated": true }, "effect": "ALLOW" }, { "resource": "server", "action": "access", "effect": "DENY" } ] } - 重启Presto coordinator:让配置生效。
为什么Hadoop Impersonation没解决问题?
你之前尝试的Hadoop impersonation是用来处理Presto访问Hadoop服务(HDFS/YARN等)时的身份模拟,比如让Presto以某个用户身份去读取HDFS数据,和Presto自身的客户端访问认证完全是两回事,所以方向不对哦。
内容的提问来源于stack exchange,提问作者JMN
相关产品推荐
相关产品推荐

