Support Questions
Find answers, ask questions, and share your expertise
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Invalidate metadata with Sentry and AD

Invalidate metadata with Sentry and AD

New Contributor

Hi guys,


We are currently expressing an issue when executing invalidate metadata via impala-shell and next exception is raised:


User 'impala' does not have privileges to execute: LIST_ROLES
at org.apache.impala.util.SentryPolicyService.listAllRoles(
at org.apache.impala.util.SentryProxy$
at java.util.concurrent.Executors$
at java.util.concurrent.FutureTask.runAndReset(
at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$301(
at java.util.concurrent.ScheduledThreadPoolExecutor$
at java.util.concurrent.ThreadPoolExecutor.runWorker(
at java.util.concurrent.ThreadPoolExecutor$


impala with Sentry and authentication using AD server.


Maybe someone faced the same issue as well


Re: Invalidate metadata with Sentry and AD

Is "impala" user being registered as sentry admin user?

Go to CM > Sentry > Configuration > Admin Groups to see if "impala" is on the list.