Member since
03-06-2020
114
Posts
3
Kudos Received
0
Solutions
06-03-2020
10:44 PM
Hi @paras do you think this is now somehow sufficient? only the know users are indicated on the Admin ACL, can dr.who no longer ran a job in my yarn? :
... View more
06-03-2020
03:02 AM
Dr.who is running on my CDH 6.3, I've seen its crontab also using YARN user: I've already remove the files of this and I want to implement some restrictions using firewalld, how can I block this virus on running on my YARN 8088? do I need to block the 8088 port in all nodes? and what IP addresses do I need to insert for whitelisting? below is my current rules in firewalld: public target: default icmp-block-inversion: no interfaces: sources: services: dhcpv6-client ssh ports: 8042/tcp 7191/tcp 2181/tcp 3181/tcp 4181/tcp 9010/tcp 8044/tcp 8041/tcp 8040/tcp 8091/tcp 9091/tcp 9995/tcp 9994/tcp 7184/tcp 7185/tcp 8084/tcp 8087/tcp 9087/tcp 9999/tcp 9998/tcp 9867/tcp 9866/tcp 9864/tcp 9865/tcp protocols: masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: rule family="ipv4" source address="195.3.146.118" reject Appreciate your help on this! thanks!
... View more
Labels:
- Labels:
-
Apache YARN
06-02-2020
08:00 PM
Hi I've tried to implement firewall using the firewalld of my rhel7 server which is also our datanode, what rules and ports do I need to implement here so that the cloudera services is still functioning and will not block there connection? firewall-cmd --list-all public target: default icmp-block-inversion: no interfaces: sources: services: dhcpv6-client ssh ports: protocols: masquerade: no forward-ports: source-ports: icmp-blocks: rich rules:
... View more
Labels:
- Labels:
-
Cloudera Manager
05-28-2020
10:56 PM
Hi @paras i've tried including my group where my admin user reside and the user itself on sentry.service.admin.group. but still no luck. what do I need to input on sentry.service.admin.group? the user or the group where it belongs? I'm still getting the error of Unable to obtain groups to cloudera(which is my user)
... View more
05-27-2020
07:35 PM
Hi @paras do I need to add the user itself on the group of sentry admins? or the one that I must add is the group where the user is associated? My CDH version is 6.3.2 I think I didn't do yet the modifying of ACLs of the HDFS directories, can you teach me how please? but I have enabled this already : dfs.namenode.acls.enabled
... View more
05-27-2020
04:47 AM
I'm getting this error also when i'm trying to create ACL on file browser
... View more
05-27-2020
04:10 AM
I want to create roles for my hive database management in Hue, but when I try to create roles using Sentry in Hue, I keep on getting this message : Unable to obtain groups in user : I've already input my admin user to Sentry admin user
... View more
Labels:
- Labels:
-
Apache Sentry
-
Cloudera Data Explorer
05-26-2020
09:39 PM
Okay @paras this is noted. thanks for help!
... View more
05-26-2020
07:13 PM
1 Kudo
Hi right now there is no free virtual image on the site of cloudera. But you can still download free cloudera express installer here in this link. you will just manually install the cloudera packages from here, just choose what is your OS : https://archive.cloudera.com/cm6/6.3.1/redhat7/yum/cloudera-manager.repo
... View more
05-26-2020
07:05 PM
hi @paras thanks for this. big help! also just want to have a follow up question, can I disable the download button for specific user or groups only?
... View more