When authorization is enabled for the Hadoop Distributed File System (HDFS), you must have the required permissions to perform operations such as reading data or creating directories. This topic describes how to enable HDFS authorization.
Background
Hadoop provides the following two modes to determine user identity:
-
simple mode: The operating system of the client connected to HDFS determines the user's identity. On Unix-like systems, this is equivalent to the
whoamicommand. -
Kerberos mode: The client's Kerberos credentials determine its identity.
You can enable Kerberos mode when you create an EMR cluster. For more information, see Kerberos.
Prerequisites
You must have an EMR cluster. For more information, see Create a cluster.
Procedure
-
For a Kerberos-enabled cluster, HDFS authorization is configured by default (umask is 027). No additional configuration or service restart is required.
-
For a cluster in simple mode, you must follow these steps to add the configuration and restart the service.
-
Go to the cluster service page.
-
In the top navigation bar, select a region and a resource group as needed.
-
In the Actions column of the target cluster, click Services.
-
On the Services page, in the HDFS service section, click Configure.
-
In the Service Configuration area, modify the parameters.
Parameter
Description
dfs.permissions.enabled
Enables permission checks. Set the value to true.
The default value is false.
dfs.datanode.data.dir.perm
Permissions for the DataNode's local directory paths.
fs.permissions.umask-mode
The permission mask that defines the default permissions for new files and directories.
dfs.namenode.acls.enabled
The default value is false. Set this parameter to true to enable Access Control List (ACL) support. This allows you to manage permissions for specific users and groups.
Commands related to ACLs include
hadoop fs -getfacl [-R] <path>andhadoop fs -setfacl [-R] [-b |-k -m |-x <acl_spec> <path>] |[--set <acl_spec> <path>].dfs.permissions.superusergroup
The name of the superuser group. The default value is hadoop. Users in this group have superuser privileges.
-
Save the changes.
-
Click Save at the bottom of the page.
-
In the dialog box that appears, enter an execution reason and click Save.
-
-
Restart the service.
-
In the upper-right corner of the HDFS service page, choose .
-
In the dialog box that appears, enter an Execution Reason and click OK.
-
In the Confirm dialog box, click OK.
Click Operation History at the top of the page to monitor the task progress. Wait for the restart to complete.
-
Example
-
Connect to the cluster by using SSH. For more information, see Connect to a cluster.
-
Run the following command to switch to the emrtest user.
-
Run the following command to create a directory as the emrtest user.
-
Run the following command to view the permissions of the created directory.
hadoop fs -ls /tmpThe command returns output similar to the following:
drwxr-x--x - emrtest hadoop 0 2022-10-21 14:08 /tmp/emrtest drwxr-x--x - hadoop hadoop 0 2022-10-21 10:06 /tmp/hadoop-yarn drwx-wx-wx - hive hadoop 0 2022-10-21 10:13 /tmp/hive drwxr-x--x - hadoop hadoop 0 2022-10-21 10:23 /tmp/kyuubi-staging drwxrwxrwt - hadoop hadoop 0 2022-10-21 10:23 /tmp/logs -
Run the following command to set an ACL for the directory and grant the foo user rwx permissions.
-
Run the following command to view the directory permissions.
hadoop fs -ls /tmp/The command returns output similar to the following:
drwxrwx--x+ - emrtest hadoop 0 2022-10-21 14:08 /tmp/emrtest drwxr-x--x - hadoop hadoop 0 2022-10-21 10:06 /tmp/hadoop-yarn drwx-wx-wx - hive hadoop 0 2022-10-21 10:13 /tmp/hive drwxr-x--x - hadoop hadoop 0 2022-10-21 10:23 /tmp/kyuubi-staging drwxrwxrwt - hadoop hadoop 0 2022-10-21 10:23 /tmp/logsNoteA plus sign (+) at the end of the permission string, such as drwxrwx--x+, indicates that an ACL is configured.
-
Run the following command to view the ACL details.
hadoop fs -getfacl /tmp/emrtestThe command returns output similar to the following:
# file: /tmp/emrtest # owner: emrtest # group: hadoop user::rwx user:foo:rwx group::r-x mask::rwx other::--x
su emrtest
hadoop fs -mkdir /tmp/emrtest
hadoop fs -setfacl -m user:foo:rwx /tmp/emrtest