Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Support Questions

Find answers, ask questions, and share your expertise
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

permission failure when using beeline

avatar
Expert Contributor

we are using ambari 2.6.2.2 with hdp 2.6.5

 

the permissions are being managed by the ranger, but checking the ranger settings, it's only managing the /apps/hive/warehouse directory on the hdfs

 

the problem we are having is in the /area/data/pll directory on the hdfs, this directory has acl rwx permission for the user

 

using beeline to create an external table is returning the error:

 

Error: Error while compiling statement: FAILED: HiveAccessControlException Permission denied: user [service_user] does not have [ALL] privilege on [hdfs://service1/area/data/pll] (state=42000,code=40000)

 

but using hive cli does not return error, table is created successfully.

 

What could be causing this problem?

3 REPLIES 3

avatar
Master Collaborator

Hi @yagoaparecidoti Ranger Hive plugin only applies to Hiveserver2. Hive CLI should be protected using permissions at the HDFS folder/file level using Ranger or HDFS ACLs.

avatar
Expert Contributor

hi @Scharan 

 

so, does the ranger only work the permissions if it uses beeline or connections that access the hiveserver2 address?

avatar
Expert Contributor

hi @Scharan 

 

the same goes for sentry?