Support Questions
Find answers, ask questions, and share your expertise

Ranger group policy issue



We are facing issues in Ranger group policy enforcement, but the user level policy enforcement is working fine. We are using AZURE wasb storage as a HDFS filesystem and integrated server login with LDAP using SSSD. In additon i have enabled Hadoop Group mapping to LDAP. I'm not sure what i'm missing here.

In addition to the above, when trying to get the hdfs group information the below error is thrown. Will this be an issue with Ranger group policy enforcement? Any guidance would be helpful.

# hdfs groups hadoop Exception in thread "main" java.lang.IllegalArgumentException: Invalid URI for NameNode address (check fs.defaultFS): wasb://xyz@xyz is not of scheme 'hdfs'. at org.apache.hadoop.hdfs.server.namenode.NameNode.getAddress( at org.apache.hadoop.hdfs.NameNodeProxies.createProxy( at org.apache.hadoop.hdfs.NameNodeProxies.createProxy( at at at at at


Expert Contributor
@Cibi Chakaravarthi

Can you please verify if the group name from "hdfs groups" is the exact match with the one configured in Ranger policy? Ranger group name and/or username are case sensitive while enforcing policies.





Yes, i'm just checking for the 'hadoop' group and i'm getting the above error that "Invalid URI for NameNode address (check fs.defaultFS): wasb://xyz@xyz is not of scheme 'hdfs'."

Take a Tour of the Community
Don't have an account?
Your experience may be limited. Sign in to explore more.