Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Support Questions

Find answers, ask questions, and share your expertise
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

HiveAccessControlException: Permission denied: user [...] does not have [READ] privilege on [s3a:

avatar
Explorer

Hi,

 

i am having the error message in the title, but I am stuck as I have already checked the followings:

 

* ranger permissions: cm_s3 / all - bucket, path -- the user in the the list for read / write / all permissions

* IDBroker role: user has a cdp-datalake-admin-role, which has a cdp-datalake-admin-policy-s3access

 

any other idea and what to check?

thanks

 

1 ACCEPTED SOLUTION

avatar
Explorer

Hi @aakulov ,

 

thanks for your reply.

 

In the last few days we had it fixed, thanks to CE support' help.

Not sure why, but he decided to reinstall Hive from scratch,  and replace it with **Hive_on_Tez**.

The sqoop commands now seems to run fine, after updating the --hs2-url parameter accordingly (and upon regeneration of kerberos tickets for hive)

 

thanks anyway for your suggestions -- hope my answer will be useful to someone 

 

kind regards,

gr

View solution in original post

2 REPLIES 2

avatar
Master Collaborator

HiveAccessControlException suggests you are accessing this s3 location through a SQL engine (Hive or Impala perhaps). Check in Ranger, under Hadoop SQL, if the policies are set properly there to access the table you are looking at.

 

Also, is this a RAZ-enabled environment, by any chance? If it is, please see here for RAZ setup specific to Hive table access: https://docs.cloudera.com/management-console/cloud/fine-grained-access-control-aws/topics/raz-aws-cr...

 

 

Hope this helps,

Alex

avatar
Explorer

Hi @aakulov ,

 

thanks for your reply.

 

In the last few days we had it fixed, thanks to CE support' help.

Not sure why, but he decided to reinstall Hive from scratch,  and replace it with **Hive_on_Tez**.

The sqoop commands now seems to run fine, after updating the --hs2-url parameter accordingly (and upon regeneration of kerberos tickets for hive)

 

thanks anyway for your suggestions -- hope my answer will be useful to someone 

 

kind regards,

gr