edit-icon download-icon

Execution plan authentication

Last Updated: Mar 23, 2018
1. Master account access

After logging on to E-MapReduce console with the master account, you can run the corresponding execution plan on the Execution plan page. Submit the jobs to the security cluster for execution and access the related open source component services involved in the jobs using the hadoop username.

2. Subaccount access

After logging on to E-MapReduce console with the RAM subaccount, you can run the corresponding execution plan on the Execution plan page. Submit the jobs to the security cluster for execution and access the related open source component services involved in the jobs using the corresponding username of the RAM subaccount.

3. Examples
  • The master account administrator can create multiple subaccounts (such as A, B, and C) as needed and grant the Aliyun EMR Full Access permissions to these subaccounts from the RAM console. Then, the subaccounts can log on to the E-MapReduce console and use the related functions.
  • The master account administrator may provide the subaccounts to developers.
  • After job creation and plan execution, the developers may start executing the execution plans to submit the jobs to the cluster, and then access the relevant component services in the cluster using usernames (such as A, B, and C) corresponding to their subaccounts.

    Note: Currently, the periodic execution plans are uniformly executed using the hadoop account.

  • Relevant permission control for component services, such as whether or not Account A has the permission to access a file in hdfs, is performed by using the username of a subaccount.
Thank you! We've received your feedback.