GBase 8a
安装配置
文章

GBase UP与星环TDH的连接(kerberos认证)

发表于2024-02-20 14:09:10141次浏览3个评论

1配置星环
1.1修改星环参数,需重启
将hadoop_security.authentication.oauth2.enable,改为false,星环自己的安全认证,暂时没有适配,需要关掉
 

1.2创建数据交换目录,并分配配额
hdfs dfs -mkdir /tmp/gbase8up  #目录必须是/tmp/gbase8up,UP程序中是写死的
hdfs dfs -chmod 777 /tmp/gbase8up
hdfs dfsadmin -setSpaceQuota 10G /tmp/gbase8up #必须设置,就算默认随意使用也要设置,涉及到数据交换时,up要导出数据到HDFS时,会先查看配额,如果未获取到值,会认为没有分配配额
 

1.3提供认证用户、keytab文件
提供连接时所需的用户、keytab文件,并赋予建库(否则后续gccli建库时会报无权限在hive建库),建表,增删改查的权限
 

2配置操作系统
2.1安装星环客户端
GBase UP集群的所有管理节点都要安装星环客户端,注意:开kerboers和不开kerberos的客户端不一样,需要在星环HD管理页面上下载
 ①安装配置java环境,客户端需要java环境
 ②配置yum源,客户端一键安装脚本会调用yum
 ③赋予gbase用户sudo权限,修改/etc/sudoers
 ④解压tdh客户端安装包,使用root用户执行一键安装脚本
source init.sh
 ⑤查看principal,并认证keytab,然后把keytab文件拷到每个管理节点上的相同目录下
 klist -kt /opt/gbase/keytab文件    #查看Principal

 kinit -kt /opt/gbase/keytab文件 Principal   #认证
⑥把 source ..../init.sh添加到gbase用户的环境变量中去,把kinit -kt /opt/gbase/keytab文件 Principal同样也添加到gbase用户的环境变量中去,这登录gbase用户就默认可连接THD了
vi /home/gbase/.bash_profile
添加:
source ..../init.sh   #最好写绝对路径
kinit -kt /opt/gbase/keytab文件 Principal
 ⑦使用gbase用户,验证beeline客户端,是否可以连接通星环HD,验证建库、建表的权限
 su - gbase
 beeline
 !connect jdbc:hive2://tdh01:10000/default;principal=principal串
 tdh01:hive插件所在的服务器IP和主机名
 default: 连接库
 principal串:第五步查出的principal串
⑧验证hdfs 命令的读和写
 hdfs dfs -ls /tmp
 hdfs dfs -put 1.txt /tmp/gbase8up/
 

2.2配置kerberos信息
①创建目录
mkdir -p /home/gbase/tmp
②在星环客户端中找到krb5.conf,并拷到/etc/目录下
③添加环境变量
vi /home/gbase/.bash_profile中添加
export KRB5CCNAME=/home/gbase/tmp/krb5cache
export KRB5CONF=/etc/krb5.conf
 

3配置GBase UP
3.1修改配置文件gbase_8a_gbase.cnf
[gbased]
........
gbase_hdfs_auth_mode=kerberos
gbase_hdfs_protocol=RPC
gbase_hdfs_keytab=/opt/ndty01.keytab
#gbase_hdfs_namenodes=tdh02:8020,tdh03:8020
_gbase_hdfs_rpcconfig='dfs.block.access.token.enable=true'
gbase_hdfs_port=8020
gbase_hdfs_principal=ndty01@TDH
 

3.2修改配置文件gbase_8a_gcluster.cnf,需重启集群
[gbased]
........
gbase_hdfs_auth_mode=kerberos
gbase_hdfs_protocol=RPC
gbase_hdfs_keytab=/opt/ndty01.keytab
#gbase_hdfs_namenodes=tdh02:8020,tdh03:8020
_gbase_hdfs_rpcconfig='dfs.block.access.token.enable=true'
gbase_hdfs_port=8020
gbase_hdfs_principal=ndty01@TDH
.......
[hive]
# According to the realistic environment to modify those configuration as follows.
hive_hdfs_user_name=ndty01   ###认证用户
# HA zookeeper connect
hive_zookeeper_host=tdh01:2181,tdh02:2181,tdh03:2181   ##zookeeper
# HA namenode
hive_hdfs_cluster_name=nameservice1       ##集群名称

# The NameNode's IP.
hive_hdfs_server_name=tdh03        ##namenodeIP,如果多个,逗号分隔(如果报错,就只写一个)
# The port of HDFS server.
hive_hdfs_server_port=8020                ##HDFS端口

# Tha HBase Master's IP
hive_hbase_server_name=n35            

# Which table to store Blob data.
hive_hbase_table_name=HbaseStream

# The local directory to store BlobCache.
hive_blob_cache_path=/opt/gcluster/userdata/blob_cache

# Which directory to store Blob data.
hive_hdfs_blob_path=/blobstorage

# When data exchange,the minmum hdfs space must be >1G.Default is 10G,units values is in bytes.
hive_hdfs_tmpspace_limit=10G

# When the data exchange,the minmum hive space must be 1G-100G.Default is 10G,units values is in bytes.
hive_space_limit=10G

# When the data exchange,the minmum of gnode space must be >1G.Default is 10G,units values is in bytes.
hive_gcluster_space_limit=10G

# The maximum of connections range 1-64,default 5.
hive_max_connections=5

# The number of  connection in pool error,range 0-64,default 3.
hive_max_connections_in_pool=2

# The number of retry when get connection error,range 1-10,default 5.
hive_max_try_connect_times=5

# The Column Family name of table which to store Blob data.
hive_hbase_col_family_name=file

# The port of HBase server.
hive_hbase_server_port=9090

# The maximum of connections to HBase is range 1-64,default 5.
hive_hbase_max_connections=5

# The maximum length of single blob data,range 2M-16M,default 16M,units values is in bytes.
# If the length of blob data exceed 16M,it will be stored to HDFS.
hive_blob_max_size_in_hbase=16M

# The maximum length of single blob data stored to HDFS,range 1G-1T,default 16G,units values is in bytes.
hive_blob_max_size_in_hdfs=16G

# The maximum space of BlobCache cached in the local disk,range 1G-16G,default 8G,units values is in bytes.
hive_blob_cache_space_limit=8G

# range: 0 or 1
# 0: Will send the blob data stored by HDFS to client.
# 1: First,get the uri from 8a mpp.Then,get the blob data by uri.Finally,send the blob data to client.
hive_blob_send_from_uri=1

3.3添加实例
install plugin hive soname 'ha_hive.so';

select create_engine_instance('hive','inst1','param://hive?hostlist=tdh01?port=10000?thriftversion=6?thrifttimeout=60?authmode=1?authtype=KERBEROS?mechanism=GSSAPI?principal=ndty01@TDH?keytabfile=/opt/ndty01.keytab?serverid=tdh01?protocol=hive?renewtime=7');
 

评论

登录后才可以发表评论
用户头像
GBase用户28017发表于 6个月前
学习。
崔哥发表于 3个月前
红满苔阶绿满枝,杜宇声声,杜宇声悲!交欢未久又分离,彩凤孤飞,彩凤孤栖。别后相思是几时,后会难知,后会难期。此情何以表相思,一首情词,一首情诗。雨打梨花深闭门,忘了青春,误了青春。赏心乐事共谁论,花下销魂,月下销魂。愁聚眉峰尽日颦,千点啼痕,万点啼痕。晓看天色暮看云,行也思君,坐也思君。
用户头像
levvel发表于 2个月前
学习一下