DataHub WebUI对接Kerberos认证Hive失败,CLI正常求助
问题描述
使用DataHub WebUI执行Hive数据接入Recipe时出现连接异常,报错信息:
[2024-02-04 08:11:42,352] INFO {thrift.transport.TSocket:118} - Could not connect to ('69.167.164.199', 10000)
Recipe配置如下:
source: type: hive config: host_port: 'xxxxx.test.com:10000' database: dm_prod username: hive include_views: false stateful_ingestion: ignore_old_state: true enabled: true database_pattern: allow: - dm_prod table_pattern: allow: - 'dm_prod.*' options: connect_args: auth: KERBEROS kerberos_service_name: hive scheme: hive+https pipeline_name: ingest-scheduler-test
该Recipe在CLI环境下可正常接入Hive数据,但WebUI执行失败。
排查方向与解决办法
1. 网络连通性验证
CLI能正常运行说明本地机器可访问Hive的10000端口,但WebUI所在服务器可能存在网络隔离:
- 在WebUI部署服务器上执行
telnet 69.167.164.199 10000或nc -zv 69.167.164.199 10000测试连通性。 - 如果不通,联系运维团队开放对应端口的防火墙/安全组规则。
2. Kerberos认证上下文不一致
CLI执行时依赖当前用户的有效Kerberos Ticket,但WebUI的Ingestion Service进程可能缺少正确的认证环境:
- 检查WebUI运行用户的
krb5.conf配置是否与CLI环境一致,确保KDC地址、Realm等参数正确。 - 为WebUI运行用户配置长期Kerberos keytab并设置自动续期,避免手动获取的Ticket过期。
- 确认Ingestion Service启动时加载了
KRB5_CONFIG等Kerberos相关环境变量。
3. Hive客户端配置缺失
CLI可能依赖本地hive-site.xml中的Thrift连接参数,但WebUI的Ingestion Service未加载该配置:
- 将本地
hive-site.xml复制到WebUI的Ingestion Service配置目录(如/etc/datahub/ingestion),确保服务启动时能读取到。 - 在Recipe的
connect_args中补充必要参数,比如启用SSL时添加ssl=true,或使用HTTP传输时添加transport_mode=http。
4. DNS解析异常
WebUI服务器对xxxxx.test.com的DNS解析结果可能与CLI环境不一致:
- 在WebUI服务器上执行
nslookup xxxxx.test.com,对比CLI环境的解析结果。 - 若解析错误,修改服务器DNS配置,或直接在Recipe中使用Hive服务的正确IP替换域名。
5. 文件权限问题
WebUI运行用户可能无权限访问Kerberos keytab、krb5.conf或hive-site.xml:
- 检查上述文件的权限设置,确保WebUI运行用户拥有读权限(可使用
chmod 644调整)。
内容的提问来源于stack exchange,提问作者YoChai
相关产品推荐
相关产品推荐

