Skip to main content

LDAP sync failing: no clerk node?

  • May 8, 2018
  • 5 replies
  • 4 views

Bryan_H
Forum|alt.badge.img+2

We set up LDAP link onsite and tried to run it, and it failed though the suggested openldap search commands seem to work. This is what we get from the run:

So I am still getting this when I run select * from v_monitor.ldap_link_events;

2018-05-04 14:59:41.142908-04 | v_healthfaqs_node0002 | _healthfaqs_node0002-16230:0x6f421 | 45035996273704962 | vertdba | 49539595901148425 | SYNC_STARTED | ---------- | 0 | 0
2018-05-04 14:59:41.144566-04 | v_healthfaqs_node0002 | _healthfaqs_node0002-16230:0x6f421 | 45035996273704962 | vertdba | 49539595901148425 | SYNC_FAILED |
| 0 | 0

In the vertica.log (there is no ldap.log)

2018-05-04 15:01:58.971 Init Session:7f82777fe700 [Session] [Query] TX:0(_healthfaqs_node0004-2009:0x2c52d) select ldap_link_sync_start();
2018-05-04 15:01:58.973 Init Session:7f82777fe700 [Util] Task 'LDAPLinkService' enabled
2018-05-04 15:01:58.973 LDAPLinkService:7f825effd700 [Basics] LDAPLink Service: this is not a clerk. Will not run on this node - v_healthfaqs_node0004.
2018-05-04 15:01:58.973 LDAPLinkService:7f825effd700 [Util] Task 'LDAPLinkService' enabled
2018-05-04 15:01:58.983 DistCall Dispatch:7f825effd700-b0000000011d1d [Txn] Rollback Txn: b0000000011d1d 'LDAP Link service'

So what did we miss? I find no mention of "clerk nodes" anywhere, and we checked node0002 as the ldap_link_events table suggested and found nothing useful in vertica.log there.

5 replies

Bryan_H
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • May 10, 2018

So I found the isRecoveryClerk flag in Catalog/config.cat on a node but is there a way to find this in database?


Jim_Knicely
Forum|alt.badge.img+2
  • Participating Frequently
  • May 11, 2018

See previous post :)

SELECT name, isrecoveryclerk FROM vs_nodes ORDER BY name;


Ben_Vandiver
Forum|alt.badge.img
  • Participating Frequently
  • May 11, 2018

Sadly Vertica has several clerks - I can think of at least 3: spread clerk, lock clerk, and recovery clerk. You're looking up the recovery clerk, but I believe the LDAP Link service runs on the spread clerk. There's always a spread clerk - it's the node in the cluster with the "lowest" spread name.

I think you could be getting distracted by the clerk stuff - there's evidence that LDAPLink is running above (on v_healthfaqs_node0002) but it's failing. I would drill down there.


Jim_Knicely
Forum|alt.badge.img+2
  • Participating Frequently
  • May 11, 2018

@Ben_Vandiver - Thanks for the info! It makes a lot more sense to me now that LDAP Link would run on a Spread clerk vs. a Recovery clerk.

Is there a way to get the Spread clerk from a SQL statement?


RonaldRong
Forum|alt.badge.img+1
  • Participating Frequently
  • May 12, 2018

Thanks!