You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kerberos数据库中找不到Server报错:Hue连接Hive失败求助

问题描述

我从GitHub安装了Hue,在hue.ini中配置了以下参数来连接Hive:

[desktop]
server_user=spnego
server_group=spnego
default_user=hue
.
.
.
[[kerberos]]
hue_keytab=/etc/spnego.keytab
# Kerberos principal name for Hue hue_principal=spnego/hostname.foo.com
# Frequency in seconds with which Hue will renew its keytab
REINIT_FREQUENCY=3600
# Path to keep Kerberos credentials cached
ccache_path=/tmp/hue_krb5_ccache
# Path to kinit
kinit_path=/path/to/kinit
krb5_renewlifetime_enabled=true

[hadoop]

# Configuration for HDFS NameNode
# ------------------------------------------------------------------------
[[hdfs_clusters]]
  # HA support by using HttpFs

[[[default]]]
# Enter the filesystem uri
fs_defaultfs=hdfs://mycluster

# NameNode logical name.
## logical_name=

# Use WebHdfs/HttpFs as the communication mechanism.
# Domain should be the NameNode or HttpFs host.
# Default port is 14000 for HttpFs.
webhdfs_url=http://mynamenode:50070/webhdfs/v1
#here when i set httpfs it says error unauthorized 401 even the service is up with kerberos i dont get it
# Change this if your HDFS cluster is Kerberos-secured
security_enabled=false

[beeswax]

# Host where HiveServer2 is running.
# If Kerberos security is enabled, use fully-qualified domain name (FQDN).
hive_server_host=hiveserver
# Binary thrift port for HiveServer2.
hive_server_port=10000

# Http thrift port for HiveServer2.
hive_server_http_port=10001

使用fake_user(HDFS中的合法用户)登录Hue可正常查看HDFS文件,但尝试连接Hive时出现报错:server not found in Kerberos database,日志无详细信息。请问该报错中的“server”具体指哪个服务?如何排查解决?

问题解答

一、报错中的“server”具体指向哪个服务?

这个报错里的“server”指的是HiveServer2(HS2)。当前操作是连接Hive,Hue需要通过Kerberos认证访问HS2,而Kerberos数据库中找不到HS2对应的服务主体(Principal),才会抛出该错误。

二、排查解决步骤

1. 确认HiveServer2的Kerberos主体配置

  • 检查Hive配置文件hive-site.xml中的hive.server2.authentication.kerberos.principal参数,确认HS2的主体格式正确,通常为hive/<完全限定域名>@REALM.COM(例如hive/hiveserver.example.com@EXAMPLE.COM)。
  • 在KDC服务器上执行kadmin.local,输入listprincs命令,确认Kerberos数据库中存在该HS2主体。

2. 补全Hue的Kerberos相关配置

  • 取消hue.ini中[[kerberos]]段hue_principal的注释,填写正确的主体格式(例如spnego/hostname.foo.com@REALM.COM),同时确保/etc/spnego.keytab文件权限正确(Hue进程用户需拥有读取权限)。
  • 在[beeswax]段添加Kerberos认证配置:
    hive_server_principal=hive/hiveserver.example.com@EXAMPLE.COM  # 必须与HS2配置的主体完全一致
    security_enabled=true
    
    注意hive_server_principal要和HS2的主体完全匹配,包括完全限定域名和REALM。

3. 验证主机名解析与Kerberos域名一致性

  • 确保Hue服务器能正确解析HS2的完全限定域名,且HS2服务器的主机名与Kerberos主体中的域名完全一致(Kerberos要求使用完全限定域名,禁止短域名)。
  • 检查Hue和HS2服务器上的krb5.conf文件,确认REALM配置、KDC地址完全一致。

4. 测试Kerberos认证连通性

  • 在Hue服务器上,以Hue进程用户身份执行kinit -kt /etc/spnego.keytab spnego/hostname.foo.com@REALM.COM,验证Hue的主体能否成功获取Kerberos票据。
  • 使用beeline工具从Hue服务器连接HS2,测试基础Kerberos认证是否正常:
    beeline -u "jdbc:hive2://hiveserver.example.com:10000/default;principal=hive/hiveserver.example.com@EXAMPLE.COM"
    
    如果beeline连接失败,说明问题出在Kerberos基础认证链路,需先解决该问题再排查Hue配置。

5. 附带排查HttpFs 401未授权问题

  • 若使用HttpFs,需确保其Kerberos主体(通常为http/httpfs-host.example.com@REALM.COM)已在KDC注册,且hadoop-httpfs-site.xml中正确配置Kerberos参数。
  • Hue的webhdfs_url应指向HttpFs地址(默认端口14000),同时将security_enabled设为true(因为集群启用了Kerberos安全模式)。

内容的提问来源于stack exchange,提问作者CompEng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 11:30:37