<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question How do you achieve high availability in HDFS when Ranger KMS is down or the metastore is down? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-do-you-achieve-high-availability-in-HDFS-when-Ranger-KMS/m-p/137064#M43841</link>
    <description />
    <pubDate>Tue, 18 Oct 2016 22:42:00 GMT</pubDate>
    <dc:creator>hduraiswamy</dc:creator>
    <dc:date>2016-10-18T22:42:00Z</dc:date>
    <item>
      <title>How do you achieve high availability in HDFS when Ranger KMS is down or the metastore is down?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-do-you-achieve-high-availability-in-HDFS-when-Ranger-KMS/m-p/137064#M43841</link>
      <description />
      <pubDate>Tue, 18 Oct 2016 22:42:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-do-you-achieve-high-availability-in-HDFS-when-Ranger-KMS/m-p/137064#M43841</guid>
      <dc:creator>hduraiswamy</dc:creator>
      <dc:date>2016-10-18T22:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do you achieve high availability in HDFS when Ranger KMS is down or the metastore is down?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-do-you-achieve-high-availability-in-HDFS-when-Ranger-KMS/m-p/137065#M43842</link>
      <description>&lt;P&gt;Scenario 1:  Ranger KMS DB is down but Node is Up&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The keys are cached for a time.  You can still read the data in the encrypted folder.  HDFS has knowledge of the encryption zone key&lt;/LI&gt;&lt;LI&gt;I assume that The Ranger KMS Service is still up, while the DB/ metastore is down.&lt;/LI&gt;&lt;LI&gt;If you know the database cannot be recovered, and you don¹t have a back up of the keystore, you immediately begin to remove the encryption zone.  &lt;/LI&gt;&lt;LI&gt; You log in as an authorized user, or hdfs and begin copying the files to an unencrypted area and then remove the encrypted zone.&lt;/LI&gt;&lt;LI&gt;I just tested this on my cluster&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;
Scenario 2:  The entire node was down.  This means BOTH the Ranger DB and the Ranger KMS Service is down.
&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The Encryption Zone key is the Ranger KMS DB (Metastore) and you can also export and save to a file.&lt;/LI&gt;&lt;LI&gt;You should back up and also make the Ranger KMS DB highly available.&lt;/LI&gt;&lt;LI&gt;Once you export to a keystore file, you back up the file.&lt;/LI&gt;&lt;LI&gt;If the cluster node goes down, you restore the Ranger KMS DB again from backup.&lt;/LI&gt;&lt;LI&gt;If you cannot restore Ranger KMS DB from back up,  you create a completely new Ranger KMS Db and get the backup Keystore file and as a special user run a script to import the key back to the  newly created database.  &lt;/LI&gt;&lt;LI&gt;You can associate once again the encryption zone folder with the key using HDFS commands.&lt;/LI&gt;&lt;LI&gt;If you Don¹t have BOTH the Keystore file and the Ranger KMS DB to restore  then you don¹t have any option.  The file remains encrypted.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;
See this article for script to export and import keys:  &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/51909/how-to-copy-encrypted-data-between-two-hdp-cluster.html" target="_blank"&gt;https://community.hortonworks.com/articles/51909/how-to-copy-encrypted-data-between-two-hdp-cluster.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 22:57:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-do-you-achieve-high-availability-in-HDFS-when-Ranger-KMS/m-p/137065#M43842</guid>
      <dc:creator>amcbarnett</dc:creator>
      <dc:date>2016-10-18T22:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do you achieve high availability in HDFS when Ranger KMS is down or the metastore is down?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-do-you-achieve-high-availability-in-HDFS-when-Ranger-KMS/m-p/137066#M43843</link>
      <description>&lt;P&gt;Thanks my friend!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 23:01:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-do-you-achieve-high-availability-in-HDFS-when-Ranger-KMS/m-p/137066#M43843</guid>
      <dc:creator>hduraiswamy</dc:creator>
      <dc:date>2016-10-18T23:01:07Z</dc:date>
    </item>
  </channel>
</rss>

