Hive:hive is not allowed to impersonate anonymous

本文介绍了一个在使用Kettle通过JDBC连接HiveServer2时遇到的异常问题,异常信息显示Hive不允许匿名用户访问。文章提供了详细的异常堆栈跟踪,并给出了解决方案:在HDFS的core-site.xml文件中添加两个属性并重启相关服务。

1、用kettle通过jdbc连接hiveserver2的时候抛出异常

Exception in thread "main" org.apache.hive.service.cli.HiveSQLException: Failed to open new session: java.lang.RuntimeException: org.apache.hadoop.ipc.RemoteException(org.apache.hadoop.security.authorize.AuthorizationException): User: hadoop is not allowed to impersonate anonymous
    at org.apache.hive.jdbc.Utils.verifySuccess(Utils.java:258)
    at org.apache.hive.jdbc.Utils.verifySuccess(Utils.java:249)
    at org.apache.hive.jdbc.HiveConnection.openSession(HiveConnection.java:579)
    at org.apache.hive.jdbc.HiveConnection.<init>(HiveConnection.java:167)
    at org.apache.hive.jdbc.HiveDriver.connect(HiveDriver.java:107)
    at java.sql.DriverManager.getConnection(DriverManager.java:571)
    at java.sql.DriverManager.getConnection(DriverManager.java:215)
    at client.main(client.java:21)
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
    at java.lang.reflect.Method.invoke(Method.java:606)
    at com.intellij.rt.execution.application.AppMain.main(AppMain.java:140)
Caused by: org.apache.hive.service.cli.HiveSQLException: Failed to open new session: java.lang.RuntimeException: org.apache.hadoop.ipc.RemoteException(org.apache.hadoop.security.authorize.AuthorizationException): User: hadoop is not allowed to impersonate anonymous
    at org.apache.hive.service.cli.session.SessionManager.openSession(SessionManager.java:324)
    at org.apache.hive.service.cli.CLIService.openSessionWithImpersonation(CLIService.java:187)
    at org.apache.hive.service.cli.thrift.ThriftCLIService.getSessionHandle(ThriftCLIService.java:424)
    at org.apache.hive.service.cli.thrift.ThriftCLIService.OpenSession(ThriftCLIService.java:318)
    at org.apache.hive.service.cli.thrift.TCLIService$Processor$OpenSession.getResult(TCLIService.java:1257)
    at org.apache.hive.service.cli.thrift.TCLIService$Processor$OpenSession.getResult(TCLIService.java:1242)
    at org.apache.thrift.ProcessFunction.process(ProcessFunction.java:39)
    at org.apache.thrift.TBaseProcessor.process(TBaseProcessor.java:39)
    at org.apache.hive.service.auth.TSetIpAddressProcessor.process(TSetIpAddressProcessor.java:56)
    at org.apache.thrift.server.TThreadPoolServer$WorkerProcess.run(TThreadPoolServer.java:286)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1142)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:617)
    at java.lang.Thread.run(Thread.java:745)
Caused by: java.lang.RuntimeException: java.lang.RuntimeException: org.apache.hadoop.ipc.RemoteException(org.apache.hadoop.security.authorize.AuthorizationException): User: hadoop is not allowed to impersonate anonymous
    at org.apache.hive.service.cli.session.HiveSessionProxy.invoke(HiveSessionProxy.java:89)
    at org.apache.hive.service.cli.session.HiveSessionProxy.access$000(HiveSessionProxy.java:36)
    at org.apache.hive.service.cli.session.HiveSessionProxy$1.run(HiveSessionProxy.java:63)
    at java.security.AccessController.doPrivileged(Native Method)
    at javax.security.auth.Subject.doAs(Subject.java:422)
    at org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1657)
    at org.apache.hive.service.cli.session.HiveSessionProxy.invoke(HiveSessionProxy.java:59)
    at com.sun.proxy.$Proxy35.open(Unknown Source)
    at org.apache.hive.service.cli.session.SessionManager.openSession(SessionManager.java:315)
    ... 12 more
Caused by: java.lang.RuntimeException: org.apache.hadoop.ipc.RemoteException(org.apache.hadoop.security.authorize.AuthorizationException): User: hadoop is not allowed to impersonate anonymous
    at org.apache.hadoop.hive.ql.session.SessionState.start(SessionState.java:554)
    at org.apache.hadoop.hive.ql.session.SessionState.start(SessionState.java:489)
    at org.apache.hive.service.cli.session.HiveSessionImpl.open(HiveSessionImpl.java:156)
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)

2、原因:hive不允许匿名用户访问

3、解决办法:

在hdfs的core-site.xml文件添加两个属性

hadoop.proxyuser.hive.groups=*
hadoop.proxyuser.hive.hosts=*

重启hdfs、hive、yarn,MR

当出现 `[08S01] Could not open client transport with JDBC Uri: jdbc:hive2://192.168.1.191:10000: Failed to open new session: java.lang.RuntimeException: org.apache.hadoop.ipc.RemoteException(org.apache.hadoop.security.authorize.AuthorizationException): User: root is not allowed to impersonate root` 错误,通常是由于 Hadoop 的代理用户配置问题导致的。以下是一些可能的解决方法: ### 配置 Hadoop 的代理用户 需要在 `core-site.xml` 文件中配置允许代理的用户和主机。在 NameNode 所在节点的 `core-site.xml` 中添加以下配置: ```xml <property> <name>hadoop.proxyuser.root.hosts</name> <value>*</value> </property> <property> <name>hadoop.proxyuser.root.groups</name> <value>*</value> </property> ``` 上述配置中,`hadoop.proxyuser.root.hosts` 设置为 `*` 表示允许从任何主机进行代理,`hadoop.proxyuser.root.groups` 设置为 `*` 表示允许代理任何用户组。如果需要更严格的安全控制,可以将 `*` 替换为具体的主机名或用户组名。 ### 重启 Hadoop 服务 在修改 `core-site.xml` 文件后,需要重启 Hadoop 相关服务,使配置生效。可以使用以下命令重启 HDFS 和 YARN: ```bash $ stop-dfs.sh $ start-dfs.sh $ stop-yarn.sh $ start-yarn.sh ``` ### 检查 HiveServer2 配置 确保 HiveServer2 配置正确,并且使用的用户具有足够的权限。可以检查 HiveServer2 的启动用户和配置文件。 ### 检查网络连接 确保 JDBC 连接的主机和端口正确,并且网络连接正常。可以使用 `ping` 和 `telnet` 命令来测试网络连接: ```bash $ ping 192.168.1.191 $ telnet 192.168.1.191 10000 ``` ### 检查防火墙设置 确保防火墙没有阻止 JDBC 连接的端口(通常是 10000)。可以临时关闭防火墙进行测试: ```bash $ systemctl stop firewalld ``` 如果关闭防火墙后可以正常连接,需要配置防火墙规则允许该端口的流量通过。
评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值