描述
1、2024-11-27号从Doris2.1.5升级到2.1.7后,发现Ranger权限下载不到Doris FE的cache目录了,Doris2.1.5版本还没有这个问题,这是BUG吗
2、但是新增策略权限后,hive beeline权限是没有问题的
现象如下
2024-12-05号新增了Ranger权限策略,上一次更新Ranger权限是2024-11-25号(是在升级之前)
显示Download下载日志
Doris FE的策略cache目录
最终导致查询没权限
Hive Catalog创建语句如下
CREATE CATALOG hive PROPERTIES (
"yarn.resourcemanager.principal" = "rm/_HOST@HUAN.TV",
"uri" = "thrift://ali-odp-master-01.huan.tv:9083,thrift://ali-odp-master-02.huan.tv:9083",
"type" = "hms",
"oss.secret_key" = "",
"oss.endpoint" = "",
"oss.access_key" = "",
"metadata_refresh_interval_sec" = "3600",
"hive.version" = "3.1.3",
"hive.metastore.uris" = "thrift://ali-odp-master-01.huan.tv:9083,thrift://ali-odp-master-02.huan.tv:9083",
"hive.metastore.sasl.enabled" = "true",
"hive.metastore.kerberos.principal" = "hive/_HOST@HUAN.TV",
"hadoop.security.authentication" = "kerberos",
"hadoop.kerberos.principal" = "hive@HUAN.TV",
"hadoop.kerberos.keytab" = "/root/hive.keytab",
"dfs.nameservices" = "ha-nn",
"dfs.namenode.rpc-address.ha-nn.nn2" = "ali-odp-master-02.huan.tv:8020",
"dfs.namenode.rpc-address.ha-nn.nn1" = "ali-odp-master-01.huan.tv:8020",
"dfs.ha.namenodes.ha-nn" = "nn1,nn2",
"dfs.client.failover.proxy.provider.ha-nn" = "org.apache.hadoop.hdfs.server.namenode.ha.ConfiguredFailoverProxyProvider",
"access_controller.properties.ranger.service.name" = "hive",
"access_controller.class" = "org.apache.doris.catalog.authorizer.ranger.hive.RangerHiveAccessControllerFactory"
);