This may help clarify the use of Isilon proxy users on a kerberized Isilon. You need to create a proxy user for the service and then add users or groups that need to run jobs to that proxy user. Lets take a hive job as an example. A Kerberos user: hdpuser3 tries to run […]Read more "Isilon hdfs proxy users"
If you are kerberizing a hadoop cluster against an Isilon, you’ll need to look at adding the following to the hdfs services to enable Isilon compatibility. All Distro’s 1. Add custom property hadoop.security.token.service.use_ip=false to core-site.xml When you kerberize with AD, Isilon’s cluster SPN is used and not the SCZ SPN. (this is our odd behavior) […]Read more "Tweaks to HDFS services to make them play nice with Kerberized Isilon access"