Azure Government中HDInsight添加存储账户失败的解决咨询
Alright, let's figure out how to get your Azure Government storage account added to your HDInsight cluster. The issue here is that the default "Add an Azure Storage account" script in the portal is built for public Azure, not Government cloud environments. Here's exactly what you need to do:
Yes, you'll need to download the original script, tweak it to support Azure Government endpoints, then run it as a custom script action on your cluster. Here's the step-by-step breakdown:
1. Grab the Original Script
First, download the script from the public URL referenced in your error:
https://hdiconfigactions.blob.core.windows.net/linuxaddstorageaccountv01/add-storage-account-v01.sh
2. Modify the Script for Azure Government
The core fix is updating the storage endpoint suffix from public Azure's core.windows.net to Azure Government's core.usgovcloudapi.net. Here are the key edits:
- Scan the script for any lines that construct storage account URLs or validate credentials using the public endpoint. Replace every instance of
.blob.core.windows.netwith.blob.core.usgovcloudapi.net. - If the script includes any references to Azure Resource Manager or AD endpoints (like
management.azure.com), swap those out for Government equivalents (e.g.,management.usgovcloudapi.net).
Here's an example of a modified credential validation snippet:
# Original public Azure line STORAGE_URL="https://${STORAGE_ACCOUNT}.blob.core.windows.net/" # Modified for Azure Government STORAGE_URL="https://${STORAGE_ACCOUNT}.blob.core.usgovcloudapi.net/"
Once modified, upload this script to your own Azure Government storage account (avoid hosting it in public Azure to prevent cross-environment issues). Generate a SAS token if needed to make the script accessible via a URL.
3. Run the Modified Script as a Custom Action
- Navigate to your HDInsight cluster in the Azure Government portal.
- Go to Script Actions > + Submit New.
- Choose Custom as the script type.
- Paste the URL of your modified (Azure Gov-hosted) script into the Script URI field.
- Enter your Azure Government storage account name and key as parameters (same as you tried before).
- Select all cluster node types (head, worker, zookeeper)—the storage account needs to be accessible across all nodes.
- Submit the action and monitor its execution. This should successfully add your storage account to the cluster.
Alternative: Manual Configuration (No Script Changes Needed)
If you'd rather skip modifying the script, you can manually add the storage account to every cluster node:
- SSH into each node of your HDInsight cluster.
- Edit the
core-site.xmlfile located at/etc/hadoop/conf/core-site.xml. - Add the following XML properties, replacing placeholders with your storage account details:
<property> <name>fs.azure.account.key.YOUR_STORAGE_ACCOUNT_NAME.blob.core.usgovcloudapi.net</name> <value>YOUR_STORAGE_ACCOUNT_KEY</value> </property> - Restart all Hadoop services via Ambari (either through the portal or command line) to apply the changes.
内容的提问来源于stack exchange,提问作者mdewan

