zhengchenyu opened a new issue, #991:
URL: https://github.com/apache/incubator-uniffle/issues/991

   ### Code of Conduct
   
   - [X] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   
   
   ### Search before asking
   
   - [X] I have searched in the 
[issues](https://github.com/apache/incubator-uniffle/issues?q=is%3Aissue) and 
found no similar issues.
   
   
   ### What would you like to be improved?
   
   For now, client-tez can not support secure cluster, will throw exception:
   
   ```
   2023-07-04 12:03:22,206 INFO examples.WordCount: DAG diagnostics: [Vertex 
failed, vertexName=Tokenizer, vertexId=vertex_1683514063269_21170_1_00, 
diagnostics=[Task failed, taskId=task_1683514063269_21170_1_00_000003, 
diagnostics=[TaskAttempt 0 failed, info=[Error: Error while running task ( 
failure ) : attempt_1683514063269_21170_1_00_000003_0:java.io.IOException: 
DestHost:destPort hadoop-tz-001017.prod.ljnode.com:39153 , LocalHost:localPort 
hadoop-tz-001017.prod.ljnode.com/10.201.1.17:0. Failed on local exception: 
java.io.IOException: org.apache.hadoop.security.AccessControlException: Client 
cannot authenticate via:[KERBEROS]
        at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
        at 
sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62)
        at 
sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
        at java.lang.reflect.Constructor.newInstance(Constructor.java:423)
        at org.apache.hadoop.net.NetUtils.wrapWithMessage(NetUtils.java:833)
        at org.apache.hadoop.net.NetUtils.wrapException(NetUtils.java:808)
        at org.apache.hadoop.ipc.Client.getRpcResponse(Client.java:1558)
        at org.apache.hadoop.ipc.Client.call(Client.java:1492)
        at org.apache.hadoop.ipc.Client.call(Client.java:1389)
        at 
org.apache.hadoop.ipc.WritableRpcEngine$Invoker.invoke(WritableRpcEngine.java:251)
        at com.sun.proxy.$Proxy11.getShuffleAssignments(Unknown Source)
        at 
org.apache.tez.runtime.library.output.RssOrderedPartitionedKVOutput.initialize(RssOrderedPartitionedKVOutput.java:155)
        at 
org.apache.tez.runtime.LogicalIOProcessorRuntimeTask$InitializeOutputCallable._callInternal(LogicalIOProcessorRuntimeTask.java:550)
        at 
org.apache.tez.runtime.LogicalIOProcessorRuntimeTask$InitializeOutputCallable.callInternal(LogicalIOProcessorRuntimeTask.java:533)
        at 
org.apache.tez.runtime.LogicalIOProcessorRuntimeTask$InitializeOutputCallable.callInternal(LogicalIOProcessorRuntimeTask.java:518)
        at org.apache.tez.common.CallableWithNdc.call(CallableWithNdc.java:36)
        at java.util.concurrent.FutureTask.run(FutureTask.java:266)
        at 
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:511)
        at java.util.concurrent.FutureTask.run(FutureTask.java:266)
        at 
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
        at 
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
        at java.lang.Thread.run(Thread.java:748)
   Caused by: java.io.IOException: 
org.apache.hadoop.security.AccessControlException: Client cannot authenticate 
via:[KERBEROS]
        at org.apache.hadoop.ipc.Client$Connection$1.run(Client.java:771)
        at java.security.AccessController.doPrivileged(Native Method)
        at javax.security.auth.Subject.doAs(Subject.java:422)
        at 
org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1730)
        at 
org.apache.hadoop.ipc.Client$Connection.handleSaslConnectionFailure(Client.java:734)
        at 
org.apache.hadoop.ipc.Client$Connection.setupIOstreams(Client.java:828)
        at org.apache.hadoop.ipc.Client$Connection.access$3900(Client.java:422)
        at org.apache.hadoop.ipc.Client.getConnection(Client.java:1615)
        at org.apache.hadoop.ipc.Client.call(Client.java:1436)
        ... 14 more
   Caused by: org.apache.hadoop.security.AccessControlException: Client cannot 
authenticate via:[KERBEROS]
        at 
org.apache.hadoop.security.SaslRpcClient.selectSaslClient(SaslRpcClient.java:173)
        at 
org.apache.hadoop.security.SaslRpcClient.saslConnect(SaslRpcClient.java:390)
        at 
org.apache.hadoop.ipc.Client$Connection.setupSaslConnection(Client.java:628)
        at org.apache.hadoop.ipc.Client$Connection.access$2300(Client.java:422)
        at org.apache.hadoop.ipc.Client$Connection$2.run(Client.java:815)
        at org.apache.hadoop.ipc.Client$Connection$2.run(Client.java:811)
        at java.security.AccessController.doPrivileged(Native Method)
        at javax.security.auth.Subject.doAs(Subject.java:422)
        at 
org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1730)
        at 
org.apache.hadoop.ipc.Client$Connection.setupIOstreams(Client.java:811)
        ... 17 more
   ```
   
   ### How should we improve?
   
   support secure cluster.
   
   ### Are you willing to submit PR?
   
   - [X] Yes I am willing to submit a PR!


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to