Hi forum,
a Vertica VSQLOH prospect is running a POC. They are facing authentication issues related to WebHDFS. This is the email I received. Can you please help with the two issues the prospects raises.
Thank you
Dieter
Hello Dieter,
we have installed a Vertica on Hadoop cluster and run the first tests.
Our HDFS has the following structure:
- /vertica : Data storage location for Vertica, Read/Write access for Vertica user.
- /tenants/tenant-XXXX : source data which will be used for Vertica external tables, access for Kerberos user tenant-XXXX
(multiple tenants access the same AWS cluster, each tenant can see their own source data only)
We have applied an HDFS Encryption Zone to /tenants/tenant-XXXX. Its key can only be used by the corresponding tenant-XXXX user.
Authentication is done through Kerberos.
We have these questions / encountered these problems on the topic:
1) When we try to use an external table from the directory with Encryption Zone we get an error. It indicates that WebHDFS was used instead of the native HDFS connector. This is described in this blog entry on Vertica 7.2.3
https://my.vertica.com/blog/what-s-new-in-7-2-3-new-apache-hadoop-integration-featuresba-p236946/)
For example, if it finds that the Hadoop cluster it is trying to read data from uses Kerberos authentication, it switches back to webHDFS.
The problem with WebHDFS seems to be that it uses always the same HDFS user. This would disable tenant ecryption as each tenant would see all data on the system (loss of data protection).
Is there a chance to use the native Hadoop connector when accessing /tenants/tenant-XXXX?
2) similar issue to 1)
Is there a chance to place a HDFS Encryption Zone on Vertica data storage?
Also in this case we need the native HDFS connector - and we need to use Kerberos for authentication.
Thanks
your prospect