Class OMTenantCreateRequest

All Implemented Interfaces:
RequestAuditor

public class OMTenantCreateRequest extends OMVolumeRequest
Handles OMTenantCreate request. Extends OMVolumeRequest but not OMClientRequest since tenant creation involves volume creation. Ratis execution flow for OMTenantCreate - preExecute (perform checks and init) - Check tenant name validity (again) - If name is invalid, throw exception to client; else continue - validateAndUpdateCache (update DB) - Grab VOLUME_LOCK write lock - Check volume existence - If tenant already exists, throw exception to client; else continue - Check tenant existence by checking tenantStateTable keys - If tenant already exists, throw exception to client; else continue - tenantStateTable: New entry - Key: tenant name. e.g. finance - Value: new OmDBTenantState for the tenant - tenantId: finance - bucketNamespaceName: finance - accountNamespaceName: finance - userPolicyGroupName: finance-users - bucketPolicyGroupName: finance-buckets - tenantPolicyTable: Generate default policies for the new tenant - K: finance-Users, V: finance-users-default - K: finance-Buckets, V: finance-buckets-default - Grab USER_LOCK write lock - Create volume finance (See OMVolumeCreateRequest) - Release VOLUME_LOCK write lock - Release USER_LOCK write lock - Queue Ranger policy sync that pushes default policies: OMMultiTenantManager#createTenant
  • Constructor Details

    • OMTenantCreateRequest

      public OMTenantCreateRequest(org.apache.hadoop.ozone.protocol.proto.OzoneManagerProtocolProtos.OMRequest omRequest)
  • Method Details

    • preExecute

      public org.apache.hadoop.ozone.protocol.proto.OzoneManagerProtocolProtos.OMRequest preExecute(OzoneManager ozoneManager) throws IOException
      Description copied from class: OMClientRequest
      Perform pre-execute steps on a OMRequest. Called from the RPC context, and generates a OMRequest object which has all the information that will be either persisted in RocksDB or returned to the caller once this operation is executed.
      Overrides:
      preExecute in class OMClientRequest
      Returns:
      OMRequest that will be serialized and handed off to Ratis for consensus.
      Throws:
      IOException
    • validateAndUpdateCache

      public OMClientResponse validateAndUpdateCache(OzoneManager ozoneManager, ExecutionContext context)
      Description copied from class: OMClientRequest
      Validate the OMRequest and update the cache. This step should verify that the request can be executed, perform any authorization steps and update the in-memory cache. This step does not persist the changes to the database. To coders and reviewers, CAUTION: Do NOT bring external dependencies into this method, doing so could potentially cause divergence in OM DB states in HA. If you have to, be extremely careful. e.g. Do NOT invoke ACL check inside validateAndUpdateCache, which can use Ranger plugin that relies on external DB.
      Specified by:
      validateAndUpdateCache in class OMClientRequest
      Returns:
      the response that will be returned to the client.
    • getUserName

      public String getUserName() throws IOException
      Throws:
      IOException