Hadoop 2.8.3 Web UI只读模式关闭及简易认证配置求助
Hey there! Let's break down your two questions about Hadoop 2.8.3's Web UI clearly:
1. Disabling/Modifying READ ONLY MODE on the NameNode Web UI (port 50070)
First off, it's important to note that the NameNode Web UI (http://localhost:50070) is designed exclusively for monitoring and viewing HDFS status in Hadoop 2.8.3. There's no official configuration to "turn off" its read-only mode because it doesn't support write operations (like uploading files or modifying cluster settings) through the UI itself—this is intentional to keep the cluster stable.
If you need to perform HDFS operations via a web interface, you should enable WebHDFS instead:
- Edit your
hdfs-site.xmland add this configuration:<property> <name>dfs.webhdfs.enabled</name> <value>true</value> </property> - Restart your HDFS services. You can then use the WebHDFS API endpoint (
http://localhost:50070/webhdfs/v1) to run read/write operations. For example, to create a directory via curl:curl -X PUT "http://localhost:50070/webhdfs/v1/mydir?op=MKDIRS&user.name=hadoop"
2. Setting Up Simple Username/Password Authentication for Web UIs
The official docs can be a bit dense, so here's a simplified, step-by-step guide to enable HTTP Basic authentication for all Hadoop Web UIs:
Step 1: Create a password file
Use the htpasswd tool (install apache-utils if you don't have it) to create a file storing encrypted user credentials:
# Create the file and add your first user (e.g., admin) htpasswd -c /opt/hadoop/conf/hadoop-jetty-users.properties admin # Add additional users (omit the -c flag) htpasswd /opt/hadoop/conf/hadoop-jetty-users.properties user1
Step 2: Update core-site.xml
Add these properties to enable authentication and point to your password file:
<property> <name>hadoop.http.authentication.type</name> <value>simple</value> <!-- Enables Basic authentication --> </property> <property> <name>hadoop.http.authentication.simple.anonymous.allowed</name> <value>false</value> <!-- Block anonymous access --> </property> <property> <name>hadoop.http.authentication.signature.secret.file</name> <value>/opt/hadoop/conf/hadoop-jetty-secret</value> <!-- Create an empty file here, set permissions to 600 --> </property> <property> <name>hadoop.http.authentication.simple.user.passwd.file</name> <value>/opt/hadoop/conf/hadoop-jetty-users.properties</value> <!-- Path to your password file --> </property>
Step 3: Configure hadoop-env.sh
Modify the HADOOP_OPTS line to include the Jetty login configuration:
export HADOOP_OPTS="$HADOOP_OPTS -Djava.security.auth.login.config=/opt/hadoop/conf/hadoop-jetty-login.conf"
Step 4: Create the Jetty login config file
Make a file named hadoop-jetty-login.conf with this content:
Jetty { org.eclipse.jetty.jaas.spi.PropertyFileLoginModule required debug="false" file="/opt/hadoop/conf/hadoop-jetty-users.properties"; };
Ensure the file path matches your password file location.
Step 5: Restart all Hadoop services
After restarting the NameNode, DataNode, ResourceManager, and other services, accessing any Hadoop Web UI (like 50070 or 8088) will prompt you for a username and password.
内容的提问来源于stack exchange,提问作者sacha.p

