<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: accessing s3guard with hadoop cli in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/accessing-s3guard-with-hadoop-cli/m-p/307315#M223188</link>
    <description>&lt;P&gt;Those two things together did the trick. Added a proper IAM role to the IDbroker mapping and logged in with my workload user. Thanks for the helpful insight!&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 16:13:41 GMT</pubDate>
    <dc:creator>kueyama</dc:creator>
    <dc:date>2020-12-09T16:13:41Z</dc:date>
    <item>
      <title>accessing s3guard with hadoop cli</title>
      <link>https://community.cloudera.com/t5/Support-Questions/accessing-s3guard-with-hadoop-cli/m-p/307199#M223157</link>
      <description>&lt;P&gt;I'm trying to learn more about s3guard and was attempting to follow along with some of the CLI examples in the CDP documentation. Any command I try results in a warning:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;WARN impl.MetricsConfig: Cannot locate configuration: tried hadoop-metrics2-s3a-file-system.properties,hadoop-metrics2.properties&lt;/LI-CODE&gt;&lt;P&gt;followed by an error:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;java.lang.IllegalStateException: Authentication with IDBroker failed.  Please ensure you have a Kerberos token by using kinit.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;When I try running kinit I see:&lt;/P&gt;&lt;PRE&gt;Client 'cloudbreak@[FQDN]' not found in Kerberos database while getting initial credentials&lt;/PRE&gt;&lt;P&gt;Where "FQDN" corresponds to the VM I am ssh into. I've tried a couple machines in both my Data Hub and Data Lake clusters. Does anyone have insight on how to properly interact with my environment's s3guard setup?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 18:35:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/accessing-s3guard-with-hadoop-cli/m-p/307199#M223157</guid>
      <dc:creator>kueyama</dc:creator>
      <dc:date>2020-12-08T18:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: accessing s3guard with hadoop cli</title>
      <link>https://community.cloudera.com/t5/Support-Questions/accessing-s3guard-with-hadoop-cli/m-p/307208#M223163</link>
      <description>&lt;P&gt;The reason why doing these operations as &lt;EM&gt;cloudbreak&lt;/EM&gt; user fail is because this is a service user for accessing the cluster's machines only and performing admin tasks on them. this user does not have access to the data (no kerberos principal and no IDBroker mapping).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead, you can SSH to your cluster's EC2 machines with your username and &lt;A href="https://docs.cloudera.com/management-console/cloud/user-management/topics/mc-setting-the-ipa-password.html" target="_self"&gt;workload password&lt;/A&gt;. That way you will have a kerberos principal working. Another thing to check is to make sure your user has IDBroker mapping to access S3 resources and potentially to access DynamoDB resources as well, since S3Guard relies on Dynamo.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 21:53:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/accessing-s3guard-with-hadoop-cli/m-p/307208#M223163</guid>
      <dc:creator>aakulov</dc:creator>
      <dc:date>2020-12-08T21:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: accessing s3guard with hadoop cli</title>
      <link>https://community.cloudera.com/t5/Support-Questions/accessing-s3guard-with-hadoop-cli/m-p/307315#M223188</link>
      <description>&lt;P&gt;Those two things together did the trick. Added a proper IAM role to the IDbroker mapping and logged in with my workload user. Thanks for the helpful insight!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 16:13:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/accessing-s3guard-with-hadoop-cli/m-p/307315#M223188</guid>
      <dc:creator>kueyama</dc:creator>
      <dc:date>2020-12-09T16:13:41Z</dc:date>
    </item>
  </channel>
</rss>

