5 ms·
Does Solr 5.0 support password-protecting the admin interface yet without spending hours trying to wrangle custom XML files? It seems like a pretty basic requir
by thinkcomp 12y ago
Does Solr 5.0 support password-protecting the admin interface yet without spending hours trying to wrangle custom XML files? It seems like a pretty basic requirement for a web-based application.
I've tried things like this
http://community.zimbra.com/documentation/w/documentation/securing-solr-on-tomcat http://community.zimbra.com/documentation/w/documentation/se...
repeatedly. They never seem to work right.
- Tharkun 12y agoSolr is not a web-based application. You shouldn't directly expose your Solr instance to anyone. Regardless of whether or not you secure your admin interface. That's not Solr's core business, and I don't see why they should was their efforts on it. Have Solr listen on localhost and have your web app talk to Solr. If your Solr is visible to the world, you're doing it wrong. Edit: by saying that it's not a web-based application I mean that it shouldn't be on teh interwebz -- it's obviously a webapp in the sense that it mostly speaks HTTP.
- tomp 12y agoWell, regardless of whether it's web-facing or not, it's not unreasonable to want to limit the access to its admin panel (e.g. in a big company with different teams). I agree however that SOLR is best off doing one thing well, web page security can be implemented e.g. by Apache.
- imaginenore 12y agoSo limit it to only whitelisted IPs. That's why you have sysadmins.
- untog 12y agoOr use Nginx as a proxy, or something. It's frustrating, but I can see the argument for Solr to just delegate this kind of task to other projects that do it better.
- Tharkun 12y agoYou would be right if the Solr admin page were the only administrative interface. It's not. You could send delete queries, create additional indexes, etc all without using the admin page, simply by sending http requests to the relevant Solr components. Instead of adding overhead by securing each individual call, they leave it up to you. Or to whichever friendly consultant you decide to hire to help out with that. Wink wink. Nudge nudge.
- BonoboBoner 12y agoWhile you are technically right, that kind of thinking gave people access to a ton of MongoDB databases last week.
- gregors 12y agoThe admin is a web application I can tell this because I'm looking at my browser. ;) Not wanting to deal with the boring parts of web apps -- that's understandable but not business/user savvy.
- gchanan 12y agoDisclaimer: I work at Cloudera on Solr and related technologies. I don't think there's anything out of the box in Solr 5.0 that changes that. SOLR-4470[0] should be able to do that, but it hasn't been committed. Apache Sentry[1] adds role based access control to Solr, but it's only been tested up to Solr 4.10 and with kerberos (not basic password protection). It comes nicely integrated out-of-the-box with Solr as part of Cloudera Search[2]; otherwise, you'll have to do some manual setup to get it to work. [0] https://issues.apache.org/jira/browse/SOLR-4470 https://issues.apache.org/jira/browse/SOLR-4470 [1] https://sentry.incubator.apache.org/ https://sentry.incubator.apache.org/ [2] http://www.cloudera.com/content/cloudera/en/products-and-services/cdh/search.html http://www.cloudera.com/content/cloudera/en/products-and-ser...
- jonbaer 12y agoIf you need a solid easy-to-config security wrapped around Solr I would recommend taking a peek @ Fusion from Lucidworks, http://lucidworks.com/product/solr-enterprise/ http://lucidworks.com/product/solr-enterprise/
- ankit-singh 12y agoMake your solr listen to localhost, and put a reverse-proxy system like nginx to access it via web and control authentication from there.