cdh启用sentry的步骤

cdh版本:5.14
主要参照官方文档:https://www.cloudera.com/documentation/enterprise/5-14-x/topics/sentry.html

一.部署sentry服务
1.配置:官方建议将hive metastore的heap size至少设为10GB:
Set the HMS heap size to at least 10 GB. This is required because by default, Sentry uses 12 connections to communicate with HMS. To verify the HMS heap size, open the Hive service, click the Configuration tab, and search for the Java Heap Size of Hive Meatstore Server in Bytes property.

hive中每百万个对象(包括servers, databases, tables, partitions, columns, URIs, and views),则sentry的Heap Size相应地需要2.25GB:
Cloudera recommends that for each Sentry host, you have 2.25 GB memory per million objects in the Hive database. Hive objects include servers, databases, tables, partitions, columns, URIs, and views.

Make sure that the JVM heap size is set to a value that is appropriate for the memory requirements. You can check the heap size in Cloudera Manager. Open the Sentry service, click the Configuration tab, and search for the Java Heap Size of Sentry Server in Bytes property. Set that property to the maximum size for the Java process heap memory.

2.安装sentry
在CDH中添加sentry服务

3.开启sentry服务之前的准备工作
Using the default Hive warehouse directory - Permissions on the warehouse directory must be set as follows (see following Note for caveats):
771 on the directory itself (by default, /user/hive/warehouse)
771 on all subdirectories (for example, /user/hive/warehouse/mysubdir)
All files and subdirectories should be owned by hive:hive
For example:
$ sudo -u hdfs hdfs dfs -chmod -R 771 /user/hive/warehouse
$ sudo -u hdfs hdfs dfs -chown -R hive:hive /user/hive/warehouse

在hive服务中勾选开启senrty认证
去除hiveserver2配置项:HiveServer2 Enable Impersonation
增加yarn nodemanager选项-Allowed System Users:增加hive
在hive配置 hadoop.proxyuser.hive.groups,增加hive,hue,sentry

二.集成

1.hive配置项Sentry 服务,选择sentry
2.impala配置项Sentry 服务 选择sentry
3.hue配置项Sentry 服务 选择sentry

转载于:https://blog.51cto.com/xiaolanlan/2379009

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值