All Products
Search
Document Center

E-MapReduce:Enable authorization

Last Updated:Sep 16, 2026

When authorization is enabled for the Hadoop Distributed File System (HDFS), you must have the required permissions to perform operations such as reading data or creating directories. This topic describes how to enable HDFS authorization.

Background

Hadoop provides the following two modes to determine user identity:

  • simple mode: The operating system of the client connected to HDFS determines the user's identity. On Unix-like systems, this is equivalent to thewhoami command.

  • Kerberos mode: The client's Kerberos credentials determine its identity.

    You can enable Kerberos mode when you create an EMR cluster. For more information, see Kerberos.

Prerequisites

You must have an EMR cluster. For more information, see Create a cluster.

Procedure

Note
  • For a Kerberos-enabled cluster, HDFS authorization is configured by default (umask is 027). No additional configuration or service restart is required.

  • For a cluster in simple mode, you must follow these steps to add the configuration and restart the service.

  1. Go to the cluster service page.

    1. Log on to the EMR on ECS console.

    2. In the top navigation bar, select a region and a resource group as needed.

    3. In the Actions column of the target cluster, click Services.

  2. On the Services page, in the HDFS service section, click Configure.

  3. In the Service Configuration area, modify the parameters.

    Parameter

    Description

    dfs.permissions.enabled

    Enables permission checks. Set the value to true.

    The default value is false.

    dfs.datanode.data.dir.perm

    Permissions for the DataNode's local directory paths.

    fs.permissions.umask-mode

    The permission mask that defines the default permissions for new files and directories.

    dfs.namenode.acls.enabled

    The default value is false. Set this parameter to true to enable Access Control List (ACL) support. This allows you to manage permissions for specific users and groups.

    Commands related to ACLs includehadoop fs -getfacl [-R] <path> andhadoop fs -setfacl [-R] [-b |-k -m |-x <acl_spec> <path>] |[--set <acl_spec> <path>].

    dfs.permissions.superusergroup

    The name of the superuser group. The default value is hadoop. Users in this group have superuser privileges.

  4. Save the changes.

    1. Click Save at the bottom of the page.

    2. In the dialog box that appears, enter an execution reason and click Save.

  5. Restart the service.

    1. In the upper-right corner of the HDFS service page, choose More > Restart.

    2. In the dialog box that appears, enter an Execution Reason and click OK.

    3. In the Confirm dialog box, click OK.

      Click Operation History at the top of the page to monitor the task progress. Wait for the restart to complete.

Example

  1. Connect to the cluster by using SSH. For more information, see Connect to a cluster.

  2. Run the following command to switch to the emrtest user.

  3. su emrtest
  4. Run the following command to create a directory as the emrtest user.

  5. hadoop fs -mkdir /tmp/emrtest
  6. Run the following command to view the permissions of the created directory.

    hadoop fs -ls /tmp

    The command returns output similar to the following:

    drwxr-x--x   - emrtest hadoop          0 2022-10-21 14:08 /tmp/emrtest
    drwxr-x--x   - hadoop  hadoop          0 2022-10-21 10:06 /tmp/hadoop-yarn
    drwx-wx-wx   - hive    hadoop          0 2022-10-21 10:13 /tmp/hive
    drwxr-x--x   - hadoop  hadoop          0 2022-10-21 10:23 /tmp/kyuubi-staging
    drwxrwxrwt   - hadoop  hadoop          0 2022-10-21 10:23 /tmp/logs                                 
  7. Run the following command to set an ACL for the directory and grant the foo user rwx permissions.

  8. hadoop fs -setfacl -m user:foo:rwx /tmp/emrtest
  9. Run the following command to view the directory permissions.

    hadoop fs -ls /tmp/

    The command returns output similar to the following:

    drwxrwx--x+  - emrtest hadoop          0 2022-10-21 14:08 /tmp/emrtest
    drwxr-x--x   - hadoop  hadoop          0 2022-10-21 10:06 /tmp/hadoop-yarn
    drwx-wx-wx   - hive    hadoop          0 2022-10-21 10:13 /tmp/hive
    drwxr-x--x   - hadoop  hadoop          0 2022-10-21 10:23 /tmp/kyuubi-staging
    drwxrwxrwt   - hadoop  hadoop          0 2022-10-21 10:23 /tmp/logs
    Note

    A plus sign (+) at the end of the permission string, such as drwxrwx--x+, indicates that an ACL is configured.

  10. Run the following command to view the ACL details.

    hadoop fs -getfacl /tmp/emrtest

    The command returns output similar to the following:

    # file: /tmp/emrtest
    # owner: emrtest
    # group: hadoop
    user::rwx
    user:foo:rwx
    group::r-x
    mask::rwx
    other::--x