Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created 05-04-2017 08:12 PM
Team,
I am getting below error when i am trying to consume kafka messages from kerberized HDP cluster (where Kafka clients are installed ) from non-kerberized HDF (NIFI).
failed to process session due to org.apache.kafka.common.KafkaException: Failed to construct kafka consumer: org.apache.kafka.common.KafkaException: Failed to construct kafka consumer
Please let me know if there are any steps that i need to follow .
Regards
Bharadwaj
Created 05-04-2017 09:03 PM
Whether you are using the ConsumeKafka or PublishKafka processors, if Kafka is kerberized you will need to setup a JAAS file in your NiFi which provides the keytab and principal used to establish that secured connection.
By default the /etc/krb5.conf will be used, but you can also tell NiFi to use a different krb5.conf file via a property in the nifi.properties (nifi.kerberos.krb5.file=).
You will need to create a JAAS file (example: kafka-jaas.conf) that contains the following (Update to use appropriate keytab and principal for your user):
KafkaClient{
com.sun.security.auth.module.Krb5LoginModule required
useKeyTab=true
storeKey=true
keyTab="nifi.keytab"
serviceName="kafka"
principal="nifi@DOMAIN";
};Add the following line to NiFi's bootstrap.conf file (make sure arg number 20 is not already being used, if so change to an unused number):
java.arg.20=-Djava.security.auth.login.config=/<path-to>/kafka-jaas.conf
Update the following configuration properties in your ConsumeKafka processor:
SecurityProtocol= SASL_PLAINTEXT ServiceName= kafka
Basically you are setting up the Kafka client kerberos environment for your NiFi JVM.
If this is a NiFi cluster, you will need to to the above on every node.
You will need to restart NiFi for these changes to take affect.
Thanks,
Matt
Created 05-04-2017 09:03 PM
Whether you are using the ConsumeKafka or PublishKafka processors, if Kafka is kerberized you will need to setup a JAAS file in your NiFi which provides the keytab and principal used to establish that secured connection.
By default the /etc/krb5.conf will be used, but you can also tell NiFi to use a different krb5.conf file via a property in the nifi.properties (nifi.kerberos.krb5.file=).
You will need to create a JAAS file (example: kafka-jaas.conf) that contains the following (Update to use appropriate keytab and principal for your user):
KafkaClient{
com.sun.security.auth.module.Krb5LoginModule required
useKeyTab=true
storeKey=true
keyTab="nifi.keytab"
serviceName="kafka"
principal="nifi@DOMAIN";
};Add the following line to NiFi's bootstrap.conf file (make sure arg number 20 is not already being used, if so change to an unused number):
java.arg.20=-Djava.security.auth.login.config=/<path-to>/kafka-jaas.conf
Update the following configuration properties in your ConsumeKafka processor:
SecurityProtocol= SASL_PLAINTEXT ServiceName= kafka
Basically you are setting up the Kafka client kerberos environment for your NiFi JVM.
If this is a NiFi cluster, you will need to to the above on every node.
You will need to restart NiFi for these changes to take affect.
Thanks,
Matt
Created 05-05-2017 02:43 AM
Thanks Matt .. it worked .
Created 10-30-2017 10:53 PM
@Matt Clarke, Does the nifi.kerberos.krb5.file= should have the /<path-to>/kafka-jaas.conf?
Created 11-07-2017 07:43 PM
@Matt, Even after i configure as per the instructions... Am still getting the same error...