๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ’ปTech/๐Ÿ˜hadoop

[Hadoop] ์‚ฌ์šฉ์ž HDFS ์ ‘๊ทผ ๊ถŒํ•œ ์„ค์ • ๋ฐฉ๋ฒ•

by _viper_ 2020. 5. 12.
๋ฐ˜์‘ํ˜•

(Ranger๊ฐ€ ์„ค์น˜๋˜์–ด ์žˆ์œผ๋ฉด Ranger์—์„œ ๊ด€๋ฆฌํ•˜๋Š”๊ฒŒ ์ข‹์Šต๋‹ˆ๋‹ค)

https://heum-story.tistory.com/146

 

Apache Ranger ์‚ฌ์šฉ๋ฒ•

Ranger ๊ฐ ๊ธฐ๋Šฅ๋“ค ์–ด๋–ป๊ฒŒ ์‚ฌ์šฉํ•˜๋Š”์ง€ ํ™•์ธํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. Ranger๋ž€? ํ•˜๋‘ก ์ „์ฒด ์„œ๋น„์Šค์— ๋Œ€ํ•œ ๋ณด์•ˆ ์ •์ฑ…์„ ์ ์šฉํ•  ์ˆ˜ ์žˆ๊ณ  ๊ด€๋ฆฌ ๋ฐ ์šด์˜ํ•  ์ˆ˜ ์žˆ๋Š” ํ”„๋ ˆ์ž„์›Œํฌ์ž…๋‹ˆ๋‹ค. ํ•˜๋‘ก์˜ ๋ณด์•ˆ๊ด€๋ จ ์กฐ

heum-story.tistory.com

 

๋ฆฌ๋ˆ…์Šค ์‚ฌ์šฉ์ž๋ฅผ hdfs์— ์ ‘๊ทผ ๊ถŒํ•œ ์„ค์ •ํ•˜๋Š” ๋‘๊ฐ€์ง€ ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค.

1.  ACL ๋ช…๋ น์–ด ์‚ฌ์šฉ

  • hdfs-site.xml ์•„๋ž˜ ์„ค์ • ๋ณ€๊ฒฝํ•ด์•ผ ACL ์‚ฌ์šฉ๊ฐ€๋Šฅ
  • dfs.namenode.acls.enabled= true 
## root user๋ฅผ hdfs /user ๊ฒฝ๋กœ์— ์ฝ๊ธฐ,์“ฐ๊ธฐ,์‹คํ–‰ ๊ถŒํ•œ์„ ์คŒ
hadoop fs -setfacl -m user:root:rwx /user

## acl ํ™•์ธ
hadoop fs -getfacl /user

 

2.  user๋ฅผ supergroup์— ์ถ”๊ฐ€

  • NameNode ์„œ๋ฒ„์—์„œ ์ง„ํ–‰
## ๋„ค์ž„๋…ธ๋“œ ์„œ๋ฒ„์—์„œ supergroup ๊ทธ๋ฃน ์ƒ์„ฑ
groupadd supergroup

## supergroup์— root ์‚ฌ์šฉ์ž ์ถ”๊ฐ€
usermod -aG supergroup root

## root ์‚ฌ์šฉ์ž ๊ทธ๋ฃน ํ™•์ธ
groups root

## ์‚ฌ์šฉ์ž ๊ทธ๋ฃน ๋งคํ•‘ ๋ฆฌํ”„๋ ˆ์‹œ
hdfs dfsadmin -refreshUserToGroupsMappings

 

๐Ÿ”Ž ์ฐธ๊ณ 

โ—พ user๋ฅผ supergroup์—์„œ ์ œ๊ฑฐ

## supergroup์—์„œ root ์‚ฌ์šฉ์ž ์ œ๊ฑฐ
gpasswd -d root supergroup

## ์‚ฌ์šฉ์ž ๊ทธ๋ฃน ๋งคํ•‘ ๋ฆฌํ”„๋ ˆ์‹œ
hdfs dfsadmin -refreshUserToGroupsMappings

โ—พ user ์ƒ์„ฑํ•˜๋ฉด์„œ ๊ทธ๋ฃน ์ง€์ •

## hadoop ์‚ฌ์šฉ์ž๋ฅผ ์ƒ์„ฑํ•˜๋ฉด์„œ supergroup์— ์ง€์ •
useradd hadoop -g supergroup