启用Ranger Hive插件后Web UI无显示,Spark权限管控遇阻
Ranger Hive插件状态不显示排查请求
环境与目标
部署两台虚拟机:
- 一台运行Apache Ranger与LDAP服务
- 另一台运行Apache Spark
期望通过Ranger Policies管控Beeline中的用户查询操作
操作流程
- 执行
$SPARK_HOME/sbin/start-thriftserver启动ThriftServer - 在Ranger Web界面通过Hadoop SQL选项创建基于资源的策略,已确认能连接Hiveserver2
- 执行
enable-hive-plugin.sh,控制台返回提示:Ranger Plugin for hive has been enabled. Please restart hive to ensure that changes are effective. - 进入Ranger Web UI的Audit>Plugin Status页面,无法看到该Hive插件
配置文件内容
$SPARK_HOME/conf/hive-site.xml
<configuration> <!-- Thriftserver --> <property> <name>hive.server2.transport.mode</name> <value>http</value> </property> <property> <name>hive.server2.thrift.http.port</name> <value>10001</value> </property> <property> <name>hive.server2.thrift.bind.host</name> <value>localhost</value> </property> <property> <name>hive.server2.webui.port</name> <value>10002</value> </property> <property> <name>hive.server2.thrift.http.path</name> <value>cliservice</value> </property> <!-- LDAP --> <property> <name>hive.server2.authentication</name> <value>LDAP</value> </property> <property> <name>hive.server2.authentication.ldap.url</name> <value>ldap://10.142.15.210:10389</value> </property> <property> <name>hive.server2.authentication.ldap.baseDN</name> <value>ou=usuarios,dc=example,dc=com</value> </property> <property> <name>hive.server2.authentication.ldap.Domain</name> <value></value> </property> <!-- Ranger --> <property> <name>hive.security.authorization.enabled</name> <value>true</value> </property> <property> <name>hive.security.authorization.manager</name> <value>org.apache.ranger.authorization.hive.authorizer.RangerHiveAuthorizerFactory</value> </property> </configuration>
${HIVE_PLUGIN_PATH}/install.properties
POLICY_MGR_URL=10.142.15.210:6080 # IP FROM RANGER REPOSITORY_NAME=hivedev COMPONENT_INSTALL_DIR_NAME=/opt/spark
已尝试操作
参考过Stack Overflow相关方案但未解决问题,求排查思路。
内容的提问来源于stack exchange,提问作者Eduardo Carlos
相关产品推荐
相关产品推荐

