You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python写入Kerberos认证HDFS时遇连接重试超限问题求助

问题:Python通过hdfscli连接Kerberos认证的HDFS时连接被拒绝

背景与代码

我尝试使用Python的hdfscli库写入启用Kerberos认证的HDFS,相关代码如下:

认证代码

def init_kinit():
    kinit_args = ['/usr/bin/kinit', '-kt', '/tmp/xx.keytab',
                  'kerberos_principle']
    subp = Popen(kinit_args, stdin=PIPE, stdout=PIPE, stderr=PIPE)
    subp.wait()

客户端上传代码

from hdfs.ext.kerberos import KerberosClient
client = KerberosClient(url='http://xx.com:port', session=session,
                            mutual_auth="REQUIRED")
client.upload(
        f'/hdfspath/file.parquet',
        f'/localpath/file.parquet')

错误信息

运行代码后出现如下连接错误:

requests.exceptions.ConnectionError: HTTPConnectionPool(host='xxx', port=xxx): 
Max retries exceeded with url: /webhdfs/v1/user/xxx/xxx.parquet?op=LISTSTATUS (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f499c104d30>: Failed to establish a new connection: [Errno 111] Connection refused'))

已做排查

已确认dfs.webhdfs.enabled参数已启用,且参考过相关排查方案,但问题仍未解决。


解决办法

  • 验证网络连通性:用telnet xx.com port或curl http://xx.com:port/webhdfs/v1/?op=GETHOMEDIRECTORY测试目标主机和端口是否可达,排查防火墙、网络ACL等是否阻断了连接。
  • 确认WebHDFS端口与地址正确性:
    • HDFS Namenode默认HTTP端口为50070,HTTPS为50470,需确认集群实际配置的端口;
    • 若集群开启HA,必须连接Active Namenode的地址,Standby节点不会响应WebHDFS请求。
  • 检查Kerberos认证有效性:
    • 执行kinit后,用klist命令查看是否获取到有效票据;
    • 可在认证函数中添加日志输出,排查kinit是否执行成功:
      def init_kinit():
          kinit_args = ['/usr/bin/kinit', '-kt', '/tmp/xx.keytab', 'kerberos_principle']
          subp = Popen(kinit_args, stdin=PIPE, stdout=PIPE, stderr=PIPE)
          stdout, stderr = subp.communicate()
          print("kinit输出:", stdout.decode())
          print("kinit错误:", stderr.decode())
          if subp.returncode != 0:
              raise Exception(f"kinit执行失败,返回码: {subp.returncode}")
      
  • 调整KerberosClient配置:
    • 若集群使用HTTPS协议,需将url改为https://xx.com:port;
    • 尝试将mutual_auth参数改为OPTIONAL,部分集群无需双向Kerberos认证。
  • 核对HDFS配置:检查hdfs-site.xml中的dfs.namenode.http-address(或dfs.namenode.https-address)是否与连接地址一致,且dfs.webhdfs.enabled已设置为true,并确认Namenode服务已重启生效。
  • 修复依赖问题:确保requests-kerberos库已正确安装,版本兼容,可执行pip install --upgrade requests-kerberos hdfs重新安装依赖。

内容的提问来源于stack exchange,提问作者Atheer Abdullatif

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 17:36:15