使用WebHDFS创建目录时遇权限错误,求技术协助
Hey there, let's work through why you're hitting that permission denied error when trying to create a directory via WebHDFS.
First, let's break down the error message you received to understand what's going on:
"RemoteException":{"exception":"AccessControlException","javaClassName":"org.apache.hadoop.security.AccessControlException","message":"Permission denied: user=dr.who, access=WRITE, inode="/tempdir":root:supergroup:drwxr-xr-x"}
This tells us three critical details:
- You're accessing WebHDFS as the default anonymous user
dr.who(since no authentication was specified in your curl call) - You're attempting a WRITE operation on the
/tempdirdirectory - The
/tempdirdirectory is owned byroot(groupsupergroup) with permissionsdrwxr-xr-x— meaning only the owner has write access; other users likedr.whocan only read and execute, not modify or add content.
Here are targeted fixes based on your actual goal:
1. You meant to create a subdirectory inside /tempdir
If your intent is to make a folder under /tempdir (not create /tempdir itself), adjust your curl command to target the subdirectory path:
curl -i -X PUT "http://myhost:50070/webhdfs/v1/tempdir/mysubdir?op=MKDIRS"
Note: You'll still need write access to /tempdir for this to work — jump to option 2 if you don't have that permission.
2. You need write access to the existing /tempdir
To let dr.who write to /tempdir, you'll need a user with admin/superuser privileges to run one of these commands:
- Quick (less secure) fix: Add write permissions for all other users (good for testing):
hdfs dfs -chmod o+w /tempdir - Secure fix: Transfer ownership to
dr.who(ideal if this directory is meant for their use):hdfs dfs -chown dr.who:dr.who /tempdir - Group-based fix: Add write permissions for the supergroup (if
dr.whois part ofsupergroup):hdfs dfs -chmod g+w /tempdir
3. You want to create /tempdir from scratch (it doesn't exist yet)
If /tempdir doesn't exist, the problem is likely that the root directory (/) blocks anonymous users from creating new folders. Here's how to fix this:
- Ask your Hadoop admin to create
/tempdirfor you and set permissions that allowdr.whoto use it, or - Authenticate as a user with root directory write access. For example, if using Kerberos, use this curl command to leverage your valid Kerberos ticket:
curl -i -X PUT --negotiate -u : "http://myhost:50070/webhdfs/v1/tempdir?op=MKDIRS"
内容的提问来源于stack exchange,提问作者user5431918

