- Platform Release 6.5
- Privacera Platform Release 6.5
- Enhancements and updates in Privacera Access Management 6.5 release
- Enhancements and updates in Privacera Discovery 6.5 release
- Enhancements and updates in Privacera Encryption 6.5 release
- Deprecation of older version of PolicySync
- Upgrade Prerequisites
- Supported versions of third-party systems
- Documentation changelog
- Known Issues 6.5
- Platform - Supported Versions of Third-Party Systems
- Platform Support Policy and End-of-Support Dates
- Privacera Platform Release 6.5
- Privacera Platform Installation
- About Privacera Manager (PM)
- Install overview
- Prerequisites
- Installation
- Default services configuration
- Component services configurations
- Access Management
- Data Server
- UserSync
- Privacera Plugin
- Databricks
- Spark standalone
- Spark on EKS
- Portal SSO with PingFederate
- Trino Open Source
- Dremio
- AWS EMR
- AWS EMR with Native Apache Ranger
- GCP Dataproc
- Starburst Enterprise
- Privacera services (Data Assets)
- Audit Fluentd
- Grafana
- Ranger Tagsync
- Discovery
- Encryption & Masking
- Privacera Encryption Gateway (PEG) and Cryptography with Ranger KMS
- AWS S3 bucket encryption
- Ranger KMS
- AuthZ / AuthN
- Security
- Access Management
- Reference - Custom Properties
- Validation
- Additional Privacera Manager configurations
- Upgrade Privacera Manager
- Troubleshooting
- How to validate installation
- Possible Errors and Solutions in Privacera Manager
- Unable to Connect to Docker
- Terminate Installation
- 6.5 Platform Installation fails with invalid apiVersion
- Ansible Kubernetes Module does not load
- Unable to connect to Kubernetes Cluster
- Common Errors/Warnings in YAML Config Files
- Delete old unused Privacera Docker images
- Unable to debug error for an Ansible task
- Unable to upgrade from 4.x to 5.x or 6.x due to Zookeeper snapshot issue
- Storage issue in Privacera UserSync & PolicySync
- Permission Denied Errors in PM Docker Installation
- Unable to initialize the Discovery Kubernetes pod
- Portal service
- Grafana service
- Audit server
- Audit Fluentd
- Privacera Plugin
- How-to
- Appendix
- AWS topics
- AWS CLI
- AWS IAM
- Configure S3 for real-time scanning
- Install Docker and Docker compose (AWS-Linux-RHEL)
- AWS S3 MinIO quick setup
- Cross account IAM role for Databricks
- Integrate Privacera services in separate VPC
- Securely access S3 buckets ssing IAM roles
- Multiple AWS account support in Dataserver using Databricks
- Multiple AWS S3 IAM role support in Dataserver
- Azure topics
- GCP topics
- Kubernetes
- Microsoft SQL topics
- Snowflake configuration for PolicySync
- Create Azure resources
- Databricks
- Spark Plug-in
- Azure key vault
- Add custom properties
- Migrate Ranger KMS master key
- IAM policy for AWS controller
- Customize topic and table names
- Configure SSL for Privacera
- Configure Real-time scan across projects in GCP
- Upload custom SSL certificates
- Deployment size
- Service-level system properties
- PrestoSQL standalone installation
- AWS topics
- Privacera Platform User Guide
- Introduction to Privacera Platform
- Settings
- Data inventory
- Token generator
- System configuration
- Diagnostics
- Notifications
- How-to
- Privacera Discovery User Guide
- What is Discovery?
- Discovery Dashboard
- Scan Techniques
- Processing order of scan techniques
- Add and scan resources in a data source
- Start or cancel a scan
- Tags
- Dictionaries
- Patterns
- Scan status
- Data zone movement
- Models
- Disallowed Tags policy
- Rules
- Types of rules
- Example rules and classifications
- Create a structured rule
- Create an unstructured rule
- Create a rule mapping
- Export rules and mappings
- Import rules and mappings
- Post-processing in real-time and offline scans
- Enable post-processing
- Example of post-processing rules on tags
- List of structured rules
- Supported scan file formats
- Data Source Scanning
- Data Inventory
- TagSync using Apache Ranger
- Compliance Workflow
- Data zones and workflow policies
- Workflow Policies
- Alerts Dashboard
- Data Zone Dashboard
- Data zone movement
- Workflow policy use case example
- Discovery Health Check
- Reports
- How-to
- Privacera Encryption Guide
- Overview of Privacera Encryption
- Install Privacera Encryption
- Encryption Key Management
- Schemes
- Encryption with PEG REST API
- Privacera Encryption REST API
- PEG API endpoint
- PEG REST API encryption endpoints
- PEG REST API authentication methods on Privacera Platform
- Common PEG REST API fields
- Construct the datalist for the /protect endpoint
- Deconstruct the response from the /unprotect endpoint
- Example data transformation with the /unprotect endpoint and presentation scheme
- Example PEG API endpoints
- /authenticate
- /protect with encryption scheme
- /protect with masking scheme
- /protect with both encryption and masking schemes
- /unprotect without presentation scheme
- /unprotect with presentation scheme
- /unprotect with masking scheme
- REST API response partial success on bulk operations
- Audit details for PEG REST API accesses
- Make encryption API calls on behalf of another user
- Troubleshoot REST API Issues on Privacera Platform
- Privacera Encryption REST API
- Encryption with Databricks, Hive, Streamsets, Trino
- Databricks UDFs for encryption and masking on PrivaceraPlatform
- Hive UDFs for encryption on Privacera Platform
- StreamSets Data Collector (SDC) and Privacera Encryption on Privacera Platform
- Trino UDFs for encryption and masking on Privacera Platform
- Privacera Access Management User Guide
- Privacera Access Management
- How Polices are evaluated
- Resource policies
- Policies overview
- Creating Resource Based Policies
- Configure Policy with Attribute-Based Access Control
- Configuring Policy with Conditional Masking
- Tag Policies
- Entitlement
- Service Explorer
- Users, groups, and roles
- Permissions
- Reports
- Audit
- Security Zone
- Access Control using APIs
- AWS User Guide
- Overview of Privacera on AWS
- Configure policies for AWS services
- Using Athena with data access server
- Using DynamoDB with data access server
- Databricks access manager policy
- Accessing Kinesis with data access server
- Accessing Firehose with Data Access Server
- EMR user guide
- AWS S3 bucket encryption
- Getting started with Minio
- Plugins
- How to Get Support
- Coordinated Vulnerability Disclosure (CVD) Program of Privacera
- Shared Security Model
- Privacera Platform documentation changelog
PEG
PEG
The following table contains the list of custom properties that can be configured for PEG. To use a custom property from the table, just add it to the following YML file in the custom-vars
folder configured as per your environment:
vars.peg.yml
Property | Description | Values | Default Value |
---|---|---|---|
PEG_IMAGE_NAME | |||
PEG_IMAGE_TAG | |||
USERSYNC_IMAGE_NAME | |||
PEG_ENABLE | |||
PEG_SSL_ENABLE | |||
PEG_SSL_SELF_SIGNED | |||
USERSYNC_RANGER_URL | |||
PEG_INTERNAL_PORT | |||
PEG_PORT | Property to change the default port number for PEG. | 6869 | |
PEG_PROTOCOL | |||
PEG_PROTOCOL_URL | |||
USERSYNC_SYNC_LDAP_USER_SEARCH_BASE | |||
PEG_SERVICE_NAME | |||
USERSYNC_SYNC_LDAP_OBJECT_CLASS | |||
PEG_HOST_NAME | |||
USERSYNC_SYNC_LDAP_USER_EMAIL_ADDRESS_ATTRIBUTE | |||
PEG_SVC_IP | |||
PEG_EXTERNAL_HOST | |||
USERSYNC_SYNC_LDAP_SSL_ENABLED | |||
PEG_URL | |||
USERSYNC_SYNC_LDAP_SSL_TRUSTSTORE_FILE | |||
PEG_EXTERNAL_URL | |||
USERSYNC_SYNC_LDAP_SSL_TRUSTSTORE_PASSWORD | |||
PEG_URL_IP | |||
PEG_PORTAL_USERNAME | Username used by PEG to access Privacera Portal. | padmin | |
PEG_PORTAL_PASSWORD | Password used by PEG to access Privacera Portal. | {{PORTAL_PADMIN_PASSWORD}} | |
PEG_USERNAME | Username of PEG API credentials to access the PEG API services. | padmin | |
PEG_PASSWORD | Password of PEG API credentials to access the PEG API services. | ||
PEG_LOG4J_LEVEL | |||
PEG_TOMCAT_BASE_DIR | |||
PEG_SSL_KEY_STORE | |||
PEG_SSL_TRUST_STORE | |||
PEG_KEYSTORE_PASSWORD | |||
PEG_TRUSTSTORE_PASSWORD | |||
PEG_KEYSTORE_ALIAS | |||
PEG_SSL_KEYSTORETYPE | |||
USERSYNC_SYNC_GROUP_OBJECT_CLASS | |||
PEG_PORTAL_AUTH | |||
PEG_METRICS_ENABLE | |||
PEG_METRICS_ENABLE_GRAPHITE | |||
PEG_METRICS_ENABLE_JVM | |||
USERSYNC_SYNC_PAGED_RESULTS_SIZE | |||
PEG_INMEM_AUTH | |||
PEG_SSL_SIGNED_PEM_FULL_CHAIN | |||
PEG_SSL_SIGNED_PEM_PRIVATE_KEY | |||
PEG_SSL_PKCS12_PASSWORD | |||
PEG_SSL_SIGNED_CERT_FORMAT | |||
PEG_SSL_SIGNED_PKCS12_ALIAS | |||
PEG_SSL_SIGNED_PKCS12_FILE | |||
PEG_AUTHORIZATION_ENABLED | |||
PEG_AUTHORIZER_IMPL | |||
USERSYNC_KERBEROS_KEYTAB | |||
PEG_ENCRYPT_SECRETS | |||
PEG_SECURE_JCEKS_FILE_PATHS | |||
PEG_SECURE_JCEKS_KEYS | |||
PEG_SECURE_JCEKS_KEYPREFIX | |||
PEG_ENCRYPT_PROPS_LIST | |||
PEG_K8S_PVC_NAME | |||
PEG_K8S_PVC_STORAGE_SIZE_MB | |||
PEG_K8S_PVC_STORAGE_SIZE | |||
PEG_K8S_STORAGE_PROVISIONER | |||
PEG_K8S_SC_NAME | |||
PEG_K8S_PV_ENCRYPTED | |||
PEG_K8S_PV_KEY | |||
USERSYNC_AZUREAD_PASSWORD | |||
PEG_REPLICAS_MIN | |||
PEG_REPLICAS_MAX | |||
PEG_K8S_LOADBALANCER_EXTERNAL | |||
PEG_K8S_ANNOTATION_LOADBALANCER_ANNOTATION | |||
PEG_K8S_MEM_LIMITS | |||
PEG_K8S_MEM_REQUESTS | |||
PEG_K8S_CPU_LIMITS | |||
PEG_K8S_CPU_REQUESTS | |||
SYNC_AZUREAD_USER_SERVICE_PRINCIPAL_ENABLED | |||
SYNC_AZUREAD_USER_SERVICE_PRINCIPAL_USERNAME_RETRIVAL_FROM | |||
USERSYNC_RANGER_USERSYNC_COOKIE | |||
USERSYNC_LOGDIR | |||
USERSYNC_ENCRYPT_SECRETS | |||
USERSYNC_SECRETS_FILE | |||
USERSYNC_SECRETS_KEYSTORE_PASSWORD | |||
USERSYNC_ENCRYPT_PROPS_LIST | |||
USERSYNC_AUTH_ADD_ETCHOST | |||
USERSYNC_AUTH_IP | |||
USERSYNC_AUTH_HOST | |||
USERSYNC_K8S_MEM_LIMITS | |||
USERSYNC_K8S_MEM_REQUESTS | |||
USERSYNC_K8S_CPU_LIMITS | |||
USERSYNC_K8S_CPU_REQUESTS | |||
USERSYNC_PASSWORDS_LIST | |||
Memory Variables | |||
PEG_HEAP_MIN_MEMORY_MB | Minimum Java Heap memory in MB used by PEG. For example, PEG_HEAP_MIN_MEMORY_MB: "1024" | ||
PEG_HEAP_MIN_MEMORY | Minimum Java Heap memory used by PEG. Setting this value will override PEG_HEAP_MIN_MEMORY_MB. For example, PEG_HEAP_MIN_MEMORY: "1g" | ||
PEG_HEAP_MAX_MEMORY_MB | Maximum Java Heap memory in MB used by PEG. For example, PEG_HEAP_MAX_MEMORY_MB: "1024" | ||
PEG_HEAP_MAX_MEMORY | Maximum Java Heap memory used by PEG. Setting this value will override PEG_HEAP_MAX_MEMORY_MB. For example, PEG_HEAP_MAX_MEMORY: "1g" | ||
PEG_K8S_MEM_REQUESTS_MB | Minimum amount of Kubernetes memory in MB to be requested by PEG. For example, PEG_K8S_MEM_REQUESTS_MB: "1024" | ||
PEG_K8S_MEM_REQUESTS | Minimum amount of Kubernetes memory to be used by PEG. Setting this value will override PEG_K8S_MEM_REQUESTS_MB. For example, PEG_K8S_MEM_REQUESTS: "1G" | ||
PEG_K8S_MEM_LIMITS_MB | Maximum amount of Kubernetes memory in MB to be requested by PEG. For example, PEG_K8S_MEM_LIMITS_MB: "1024" | ||
PEG_K8S_MEM_LIMITS | Maximum amount of Kubernetes memory to be used by PEG. Setting this value will override PEG_K8S_MEM_LIMITS_MB. For example, PEG_K8S_MEM_LIMITS: "1G" | ||
PEG_CPU_MIN | Minimum amount of Kubernetes CPU to be requested by PEG. For example, PEG_CPU_MIN: "0.5" | ||
PEG_CPU_MAX | Maximum amount of Kubernetes CPU to be used by PEG. For example, PEG_CPU_MAX: "0.5" |