<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Using HiveContext with Sentry and proxy-user in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Using-HiveContext-with-Sentry-and-proxy-user/m-p/46337#M43629</link>
    <description>&lt;P&gt;We are using HiveContext in a Spark Application and running it on a secure cluster with Sentry enabled. We are on CDH 5.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our use case we are using proxy-user for impersonation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;spark-submit \&lt;/P&gt;&lt;P&gt;--class&amp;nbsp;&lt;SPAN&gt;fire.execute.WorkflowExecuteFromFile&lt;/SPAN&gt; \&lt;BR /&gt;--keytab /disk01/sparkflows/release/fire-ui/sparkflows.keytab \&lt;BR /&gt;--proxy-user cloudera --master yarn \&lt;BR /&gt;--deploy-mode client \&lt;BR /&gt;&lt;SPAN&gt;/disk01/sparkflows/release/fire/core/target/fire-core-1.3.0-jar-with-dependencies.jar&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running into the exception below. Though &lt;SPAN&gt;SPARK-13478 is in CDH 5.7.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://archive.cloudera.com/cdh5/cdh/5/spark-1.6.0-cdh5.7.0.releasenotes.html" target="_blank"&gt;http://archive.cloudera.com/cdh5/cdh/5/spark-1.6.0-cdh5.7.0.releasenotes.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://issues.apache.org/jira/browse/SPARK-13478" target="_blank"&gt;https://issues.apache.org/jira/browse/SPARK-13478&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;org.apache.hadoop.hive.shims.Hadoop23Shims for Hadoop version 2.6.0-cdh5.7.0&lt;/SPAN&gt;&lt;SPAN&gt; 16/10/15 12:15:56 INFO hive.metastore: Trying to connect to metastore with URI thrift://venice.hadoop:9083&lt;/SPAN&gt;&lt;SPAN&gt; 16/10/15 12:15:56 ERROR transport.TSaslTransport: SASL negotiation failure&lt;/SPAN&gt;&lt;SPAN&gt; javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]&lt;/SPAN&gt;&lt;SPAN&gt; at com.sun.security.sasl.gsskerb.GssKrb5Client.evaluateChallenge(GssKrb5Client.java:212)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.thrift.transport.TSaslClientTransport.handleSaslStartMessage(TSaslClientTransport.java:94)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.thrift.transport.TSaslTransport.open(TSaslTransport.java:271)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.thrift.transport.TSaslClientTransport.open(TSaslClientTransport.java:37)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.hadoop.hive.thrift.client.TUGIAssumingTransport$1.run(TUGIAssumingTransport.java:52)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.hadoop.hive.thrift.client.TUGIAssumingTransport$1.run(TUGIAssumingTransport.java:49)&lt;/SPAN&gt;&lt;SPAN&gt; at java.security.AccessController.doPrivileged(Native Method)&lt;/SPAN&gt;&lt;SPAN&gt; at javax.security.auth.Subject.doAs(Subject.java:415)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1693)&lt;/SPAN&gt;&lt;SPAN&gt; at &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To ensure everything else is good on the cluster, we tested SparkPi. It runs successfully&amp;nbsp;without any issues:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;spark-submit \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--class org.apache.spark.examples.SparkPi \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--keytab /disk01/sparkflows/release/fire-ui/sparkflows.keytab \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--proxy-user cloudera --master yarn \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--deploy-mode client \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/opt/cloudera/parcels/CDH-5.7.0-1.cdh5.7.0.p0.45/jars/spark-examples-1.6.0-cdh5.7.0-hadoop2.6.0-cdh5.7.0.jar 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jayant&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 10:44:33 GMT</pubDate>
    <dc:creator>jayantshekhar</dc:creator>
    <dc:date>2022-09-16T10:44:33Z</dc:date>
    <item>
      <title>Using HiveContext with Sentry and proxy-user</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Using-HiveContext-with-Sentry-and-proxy-user/m-p/46337#M43629</link>
      <description>&lt;P&gt;We are using HiveContext in a Spark Application and running it on a secure cluster with Sentry enabled. We are on CDH 5.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our use case we are using proxy-user for impersonation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;spark-submit \&lt;/P&gt;&lt;P&gt;--class&amp;nbsp;&lt;SPAN&gt;fire.execute.WorkflowExecuteFromFile&lt;/SPAN&gt; \&lt;BR /&gt;--keytab /disk01/sparkflows/release/fire-ui/sparkflows.keytab \&lt;BR /&gt;--proxy-user cloudera --master yarn \&lt;BR /&gt;--deploy-mode client \&lt;BR /&gt;&lt;SPAN&gt;/disk01/sparkflows/release/fire/core/target/fire-core-1.3.0-jar-with-dependencies.jar&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running into the exception below. Though &lt;SPAN&gt;SPARK-13478 is in CDH 5.7.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://archive.cloudera.com/cdh5/cdh/5/spark-1.6.0-cdh5.7.0.releasenotes.html" target="_blank"&gt;http://archive.cloudera.com/cdh5/cdh/5/spark-1.6.0-cdh5.7.0.releasenotes.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://issues.apache.org/jira/browse/SPARK-13478" target="_blank"&gt;https://issues.apache.org/jira/browse/SPARK-13478&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;org.apache.hadoop.hive.shims.Hadoop23Shims for Hadoop version 2.6.0-cdh5.7.0&lt;/SPAN&gt;&lt;SPAN&gt; 16/10/15 12:15:56 INFO hive.metastore: Trying to connect to metastore with URI thrift://venice.hadoop:9083&lt;/SPAN&gt;&lt;SPAN&gt; 16/10/15 12:15:56 ERROR transport.TSaslTransport: SASL negotiation failure&lt;/SPAN&gt;&lt;SPAN&gt; javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]&lt;/SPAN&gt;&lt;SPAN&gt; at com.sun.security.sasl.gsskerb.GssKrb5Client.evaluateChallenge(GssKrb5Client.java:212)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.thrift.transport.TSaslClientTransport.handleSaslStartMessage(TSaslClientTransport.java:94)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.thrift.transport.TSaslTransport.open(TSaslTransport.java:271)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.thrift.transport.TSaslClientTransport.open(TSaslClientTransport.java:37)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.hadoop.hive.thrift.client.TUGIAssumingTransport$1.run(TUGIAssumingTransport.java:52)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.hadoop.hive.thrift.client.TUGIAssumingTransport$1.run(TUGIAssumingTransport.java:49)&lt;/SPAN&gt;&lt;SPAN&gt; at java.security.AccessController.doPrivileged(Native Method)&lt;/SPAN&gt;&lt;SPAN&gt; at javax.security.auth.Subject.doAs(Subject.java:415)&lt;/SPAN&gt;&lt;SPAN&gt; at org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1693)&lt;/SPAN&gt;&lt;SPAN&gt; at &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To ensure everything else is good on the cluster, we tested SparkPi. It runs successfully&amp;nbsp;without any issues:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;spark-submit \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--class org.apache.spark.examples.SparkPi \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--keytab /disk01/sparkflows/release/fire-ui/sparkflows.keytab \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--proxy-user cloudera --master yarn \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;--deploy-mode client \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/opt/cloudera/parcels/CDH-5.7.0-1.cdh5.7.0.p0.45/jars/spark-examples-1.6.0-cdh5.7.0-hadoop2.6.0-cdh5.7.0.jar 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jayant&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:44:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Using-HiveContext-with-Sentry-and-proxy-user/m-p/46337#M43629</guid>
      <dc:creator>jayantshekhar</dc:creator>
      <dc:date>2022-09-16T10:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Using HiveContext with Sentry and proxy-user</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Using-HiveContext-with-Sentry-and-proxy-user/m-p/46558#M43630</link>
      <description>&lt;P&gt;To close the loop, the problem was on our side!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this specific scenario we had also set master to "local" in the code in error. Fixing it solved the issue!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 21:02:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Using-HiveContext-with-Sentry-and-proxy-user/m-p/46558#M43630</guid>
      <dc:creator>jayantshekhar</dc:creator>
      <dc:date>2016-10-21T21:02:16Z</dc:date>
    </item>
  </channel>
</rss>

