Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created 07-31-2018 09:40 AM
Hello All,
We have synced AD users in Zeppelin using shiro.ini file. User is able to login using entire domain name eg: '[email protected]'
All notebook have owners set to '[email protected]'
Now, we have synced AD users in Zeppelin using SaMAcoountName. Hence User is able to login using SaMAcoountName only eg: 'bhushan-kandalkar'
But problem is user 'bhushan-kandalkar' is not able to view notebooks created by '[email protected]' though its an same user.
How should I change owners of all notebooks from '[email protected]' to 'bhushan-kandalkar'?
Please suggest.
Thanks,
Bhushan
Created 07-31-2018 03:04 PM
To recover and and change notebook permissions manually you should do the following:
1. Login to zeppelin server host and switch to zeppelin user. If kerberized, kinit as zeppelin principal using zeppelin keytab
2. Make a backup of the following hdfs file
hdfs dfs -cp /user/zeppelin/conf/notebook-authorization.json /user/zeppelin/conf/notebook-authorization.json.orig
3. Get the file from hdfs to local file system
hdfs dfs -get /user/zeppelin/conf/notebook-authorization.json /tmp/notebook-authorization.json
4. Edit the file and replate all occurences of the username
sed -i -e 's/[email protected]/bhushan-kandalkar/g' /tmp/notebook-authorization.json
5. Upload the file to hdfs
hdfs dfs -put -f /tmp/notebook-authorization.json /user/zeppelin/conf/
6. Restart zeppelin server using ambari
Let me know if that works for you.
HTH
*** If you found this answer addressed your question, please take a moment to login and click the "accept" link on the answer.
Created 07-31-2018 03:04 PM
To recover and and change notebook permissions manually you should do the following:
1. Login to zeppelin server host and switch to zeppelin user. If kerberized, kinit as zeppelin principal using zeppelin keytab
2. Make a backup of the following hdfs file
hdfs dfs -cp /user/zeppelin/conf/notebook-authorization.json /user/zeppelin/conf/notebook-authorization.json.orig
3. Get the file from hdfs to local file system
hdfs dfs -get /user/zeppelin/conf/notebook-authorization.json /tmp/notebook-authorization.json
4. Edit the file and replate all occurences of the username
sed -i -e 's/[email protected]/bhushan-kandalkar/g' /tmp/notebook-authorization.json
5. Upload the file to hdfs
hdfs dfs -put -f /tmp/notebook-authorization.json /user/zeppelin/conf/
6. Restart zeppelin server using ambari
Let me know if that works for you.
HTH
*** If you found this answer addressed your question, please take a moment to login and click the "accept" link on the answer.
Created 07-31-2018 05:15 PM
Thanks @Felix Albani
I already did that. But note permission for every notebook is still showing '[email protected]' as owner, reader and writer.
Also, when I tried to change owner name to 'bhushan-kandalkar' its giving permission denied error.
Please suggest.
Created 07-31-2018 07:00 PM
Could you be more precise as to what step of the ones I provided above is giving you the permission denied error?
Thanks!
Created 08-01-2018 12:49 PM
I performed all these steps. I can see that user 'bhushan-kandalkar' is able to view notebooks created by '[email protected]' user. That's good news.
But in Zeppelin Notebook UI, I am still getting '[email protected]' user. Attached screenshot notebook-permission.png. I am not getting ''bhushan-kandalkar' user.
Also, when I share notebook to other user, that notebook is removed from the user who has shared that notebook. That should not happen.
Please suggest.
Created 08-01-2018 08:41 PM
Can you login to Zeppelin as 'bhushan-kandalkar' instead of '[email protected]'? You may need to set "activeDirectoryRealm.principalSuffix = @test.com" if you are using "org.apache.zeppelin.realm.ActiveDirectoryGroupRealm".
With this set, you should be able to login as 'bhushan-kandalkar' and same would appear in notebook permission.
Hope this helps.
Created 07-31-2018 08:25 PM
Please let us know the value of "zeppelin.notebook.storage" property in Zeppelin. If you can attach your zeppelin-site.xml from Zeppelin node ("after scrubbing your env. specific details"), that will be even better.
What Felix is suggesting here, may actually work if done correctly.
Created 08-02-2018 07:09 AM
I am logging in using bhushan-kandalkar user but in Zeppelin Notebook UI, I am still getting '[email protected]' user for every notebook permission.