Uploaded image for project: 'Cookbooks'
  1. Cookbooks
  2. COOK-104

Properly initialize necessary Kerberos credentials for cdap::init

    Details

    • Type: Improvement
    • Status: Resolved
    • Priority: Critical
    • Resolution: Fixed
    • Component/s: cdap
    • Labels:
      None
    • Rank:
      1|hzzgmn:

      Description

      When Kerberos is enabled on a cluster, we only authenticate as the Kerberos admin user. However, HDFS directory checks are run as cdap['cdap-site']['hdfs.user'] rather than the Kerberos admin. Directory creation is done using cdap['fs_superuser'] which is normally "hdfs" user.

      The cookbook doesn't properly get kerberos tickets. Functionality is piggy-backed on the existing credentials from using the hadoop_wrapper cookbook in the same run_list.

      This causes the directories to be created every time.

        Attachments

          Activity

            People

            • Assignee:
              chris Chris Gianelloni
              Reporter:
              chris Chris Gianelloni
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: