Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Limit # of connections per user

Highlighted

Limit # of connections per user

Contributor

Is there a way to limit the # of connections per user? We are having to respond to security guidelines for databases and they have the desire the max # of connections for each user (we're using Kerberos and AD) to avoid DDOS attacks.

4 REPLIES 4
Highlighted

Re: Limit # of connections per user

Contributor

FYI, if there is a place to hook some Java code into HBase as a coprocessor or some other mechanism, we're willing to take it on. Our customer stops short of us monkeying with the actual HBase/Phoenix code base (we are using Phoenix on top of HBase).

Highlighted

Re: Limit # of connections per user

Mentor

@Jeff Watson

For a kerberized environment when an authorized user/application grabs a ticket the default lifetime is configurable in /etc/krb5.conf usually ticket_lifetime = 24h, but note should be taken that this ticket is renewed automatically as long as there is a job running previously. Kerberos won't expire the ticket which would lead to the job to fail.

I don't know id AD has a mechanism to timeout idle connections but most databases have a configurable session timeout.
Can you be more specific on the databases.

Highlighted

Re: Limit # of connections per user

Contributor

It's less a matter of ticket timeout and more restricting the same user for creating lots of sessions. I'm looking into custom ranger plugins which looks promising.

Re: Limit # of connections per user

Contributor

Starting Hive 3 we have following properties to limit the number of connections

  • hive.server2.limit.connections.per.ipaddress
  • hive.server2.limit.connections.per.user
  • hive.server2.limit.connections.per.user.ipaddress

https://issues.apache.org/jira/browse/HIVE-16917

Don't have an account?
Coming from Hortonworks? Activate your account here