レルム | GRID.EXAMPLE.COM |
---|
No. | ノード | Kerberosプリンシパル | オーナ | モード | keytabファイル (/grid/etc/keytabs /colo00) | 備考 |
---|
0 | ZooKeeper | zookeeper/zk0{0..2}.grid.example.com@GRID.EXAMPLE.COM | zookeeper:zookeeper | 400 | zk.keytab | SASL/Kerberos用(Client-Server相互認証のみ) |
1 | Ganglia Web | HTTP/gm9{0..1}.grid.example.com@GRID.EXAMPLE.COM | root:www-data | 440 | /etc/krb5.keytab | SPNEGO/Kerberos用 |
2 | Nagios | HTTP/nm9{0..1}.grid.example.com@GRID.EXAMPLE.COM | root:www-data | 440 | /etc/krb5.keytab | SPNEGO/Kerberos用 |
No. | ノード | Kerberosプリンシパル | オーナ | モード | keytabファイル (/grid/etc/keytabs /pleiades) | 備考 |
---|
0 | - | hdfs@GRID.EXAMPLE.COM | hdfs:hdfs | - | - | HDFS管理用ユーザプリンシパル |
1 | NameNode | hdfs/pleiades-nn.grid.example.com@GRID.EXAMPLE.COM | hdfs:hdfs | 400 | HTTP.keytab -> nn.keytab | SASL/Kerberos(Hadoop RPC)用 |
host/pleiades-nn.grid.example.com@GRID.EXAMPLE.COM | KSSL*1用(checkpoint、fsck) |
HTTP/pleiades-nn.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用(checkpoint、fsck*2、WebHDFS、Web Console) |
2 | CheckpointNode? (SecondaryNameNode) | hdfs/pleiades-cn.grid.example.com@GRID.EXAMPLE.COM | hdfs:hdfs | 400 | HTTP.keytab -> cn.keytab | SASL/Kerberos(Hadoop RPC)用 |
host/pleiades-cn.grid.example.com@GRID.EXAMPLE.COM | KSSL*3用(checkpoint) |
HTTP/pleiades-cn.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用(checkpoint*4、Web Console) |
3 | - | yarn@GRID.EXAMPLE.COM | yarn:yarn | - | - | YARN管理用ユーザプリンシパル |
4 | ResourceManager? (Hadoop 2.0) | yarn/pleiades-rm.grid.example.com@GRID.EXAMPLE.COM | yarn:yarn | 400 | HTTP.keytab -> rm.keytab | SASL/Kerberos(Hadoop RPC)用 |
HTTP/pleiades-rm.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用(Web Console) |
5 | - | mapred@GRID.EXAMPLE.COM | mapred:mapred | - | - | MapReduce?管理用ユーザプリンシパル |
6 | JobTracker | mapred/pleiades-jt.grid.example.com@GRID.EXAMPLE.COM | mapred:mapred | 400 | HTTP.keytab -> jt.keytab | SASL/Kerberos(Hadoop RPC)用 |
HTTP/pleiades-jt.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用(Web Console) |
7 | DataNode | hdfs/dn0000{0..1}.grid.example.com@GRID.EXAMPLE.COM | hdfs:hdfs | 400 | dn.keytab | SASL/Kerberos(Hadoop RPC)用 |
HTTP/dn0000{0..1}.grid.example.com@GRID.EXAMPLE.COM | hdfs:hadoop | 440 | HTTP.keytab -> dn-HTTP.keytab | SPNEGO/Kerberos用(WebHDFS、Web Console) |
8 | NodeManager? (Hadoop 2.0) | yarn/dn0000{0..1}.grid.example.com@GRID.EXAMPLE.COM | yarn:yarn | 400 | nm.keytab | SASL/Kerberos(Hadoop RPC)用 |
HTTP/dn0000{0..1}.grid.example.com@GRID.EXAMPLE.COM | hdfs:hadoop | 440 | HTTP.keytab -> dn-HTTP.keytab | SPNEGO/Kerberos用(Web Console) |
9 | TaskTracker | mapred/dn0000{0..1}.grid.example.com@GRID.EXAMPLE.COM | mapred:mapred | 400 | tt.keytab | SASL/Kerberos(Hadoop RPC)用 |
HTTP/dn0000{0..1}.grid.example.com@GRID.EXAMPLE.COM | hdfs:hadoop | 440 | HTTP.keytab -> dn-HTTP.keytab | SPNEGO/Kerberos用(Web Console) |
10 | JobHistoryServer? (Hadoop 2.0) | mapred/pleiades-jh.grid.example.com@GRID.EXAMPLE.COM | mapred:mapred | 400 | HTTP.keytab -> jh.keytab | SASL/Kerberos(Hadoop RPC)用 |
HTTP/pleiades-jh.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用(Web Console) |
11 | HBase Master | hbase/hm{0..1}.grid.example.com@GRID.EXAMPLE.COM | hbase:hbase | 400 | HTTP.keytab -> hm.keytab | SASL/Kerberos(HBase RPC)用 |
HTTP/hm{0..1}.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用(Web Console)*5 |
12 | HBase RegionServer? | hbase/dn0000{0..1}.grid.example.com@GRID.EXAMPLE.COM | hbase:hbase | 400 | hr.keytab | SASL/Kerberos(HBase RPC)用 |
13 | Oozie | oozie@GRID.EXAMPLE.COM | oozie:oozie | 400 | wf.keytab | ProxyUser用 |
HTTP/pleiades-wf.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用 |
14 | HttpFS(Hoop) | (httpfs|hoop)@GRID.EXAMPLE.COM | (httpfs|hoop) | 400 | pxy.keytab | ProxyUser用 |
HTTP/pleiades-pxy.grid.example.com@GRID.EXAMPLE.COM | SPNEGO/Kerberos用 |
15 | HCatalog | hive-metastore/pleiades-meta.grid.example.com@GRID.EXAMPLE.COM | hive:hive | 400 | meta.keytab | SASL/Kerberos(MetaStore?)、ProxyUser用 |
16 | Ganglia Web | HTTP/gm0{0..1}.grid.example.com@GRID.EXAMPLE.COM | root:www-data | 440 | /etc/krb5.keytab | SPNEGO/Kerberos用 |
17 | Nagios | HTTP/nm0{0..1}.grid.example.com@GRID.EXAMPLE.COM | root:www-data | 440 | /etc/krb5.keytab | SPNEGO/Kerberos用 |
18 | クライアント | alice@GRID.EXAMPLE.COM | alice:alice | 400 | - | テスト用ユーザ |