Skip to main content



Access AWS S3 or HCP HS3 (Hitachi) using Hadoop or HDFS or Distcp

Create Credentials File for S3 Keys


hadoop credential create fs.s3a.access.key -value <Access_KEY> -provider localjceks://file/$HOME/aws-dev-keys.jceks

hadoop credential create fs.s3a.secret.key -value <Secret_KEY> -provider localjceks://file/$HOME/aws-dev-keys.jceks

Where - 
<Access_KEY>- S3 access key
<Secret_KEY> - S3 secret key

Note - 
  1. this will create a file local file system, in home directory with name aws-dev-keys.jceks
  2. Put this file to HDFS. For, distributed access.
To list the details execute below command- 

hadoop credential list -provider localjceks://file/$HOME/aws-dev-keys.jceks

List files in S3 Bucket with hadoop Shell

hdfs dfs -Dhadoop.security.credential.provider.path=jceks://hdfs/myfilelocation/aws-dev-keys.jceks -ls s3a://s3bucketname/

hdfs dfs -Dfs.s3a.access.key=<Access_KEY> -Dfs.s3a.secret.key=<Secret_KEY> -ls s3a://aa-daas-ookla/

Note -
  1. Similarly, other hadoop/ hdfs commands like -put, -get can be executed.

Use distcp to copy data from S3 to HDFS - 

hadoop distcp -Dhadoop.security.credential.provider.path=jceks://myfilelocation/aws-dev-keys.jceks s3a://s3bucketname/mydir/tar.gz /hdfs/mydata/

Use distcp to copy data from HDFS to S3 - 

hadoop distcp -Dhadoop.security.credential.provider.path=jceks://myfilelocation/aws-dev-keys.jceks /hdfs/mydata/tar.gz s3a://s3bucketname/mydir/


Refer - https://docs.cloudera.com/HDPDocuments/HDP2/HDP-2.6.5/bk_cloud-data-access/content/s3-credential-providers.html

Note that by default it goes to AWS S3. But, say you have HCP S3 API or any other vendor S3 that you want to access then it can be done just by specifying one more property as below - 

-D fs.s3a.endpoint=hcp.s3-compatible.tests3api.com


The default provider password is "none".

To read value of an alias from provider file. Open Spark-Shell and execute below commands - 

val jceks_path="jceks://myfilelocation/aws-dev-keys.jceks"
val alias="fs.s3a.access.key"

val conf = spark.sparkContext.hadoopConfiguration
conf.set("hadoop.security.credential.provider.path", jceks_path)

val credential_raw = conf.getPassword(alias)
credential_raw.mkString

Comments

Popular posts

Unix Server ( Edge Node ) hangs when there are many jobs running on hadoop cluster started from Unix Edge Node.

  When a unix server or an edge node is running lots of jobs (like Spark, Hadoop, or custom batch processes), crashes happen. For example. For example a process might hit a segementation fault, memory issue or ay other runtime issue. By default, if ulimit -c is not 0, the OS will create core dump. Core dump are written to disk and can be very large, sometimes hundreds of MBs or even GBs per process. What we realized was that when multiple processes crash at the same time, the system suddenly tries to write core files to disk. This was leading to DisK I/O spikes. Thus, node was becoming unresponsive. This was also leading CPU spike because OS was handling crash logging. Setting "ulimit -c 0" disables core dumps. This way we lose ability to debug crashes via core dump But, kept production edge nodes stable. On most Linux systems, by default, "core dumps" are written in current working directory of the process that crashes. Linux allows you to change core dump file nam...




VPN testing checklist

 To test: Is VPN active? Is it leaking? Does it look residential? Does it alter network fingerprints? Public IP Test (Basic Detection) - curl ipinfo.io DNS Leak Test - nslookup google.com MTU Test (Encapsulation Detection) - ping 8.8.8.8 -f -l 1472 TCP MSS Inspection - Use Wireshark and Look for SYN packets. Traceroute Path Test - tracert 8.8.8.8 WebRTC Leak Test - browserleaks.com/webrtc IPv6 Leak Test - test-ipv6.com Latency / Jitter Test - ping -n 50 8.8.8.8. VPN usually causes: More Jitters and Latency. Reverse DNS (PTR Record) - nslookup <your-public-ip> IP Reputation Check - Like most IP's from VPN Providers like Express VPN, etc. are blacklisted and all. Look for: Proxy/VPN classification, Hosting provider tagging




Spark-JDBC connection with Oracle Fails - java.sql.SQLSyntaxErrorException: ORA-00903: invalid table name

  While connecting Spark with Oracle JDBC, one may observe exception like below -  spark.read.format("jdbc"). option("url", "jdbc:oracle:thin:@//oraclehost:1521/servicename"). option("dbtable", "mytable"). option("user", "myuser").option("driver", "oracle.jdbc.driver.OracleDriver") option("password", "mypassword"). load().write.parquet("/data/out") java.sql.SQLSyntaxErrorException: ORA-00903: invalid table name at oracle.jdbc.driver.T4CTTIoer.processError(T4CTTIoer.java:447) at oracle.jdbc.driver.T4CTTIoer.processError(T4CTTIoer.java:396) at oracle.jdbc.driver.T4C8Oall.processError(T4C8Oall.java:951) at oracle.jdbc.driver.T4CTTIfun.receive(T4CTTIfun.java:513) at oracle.jdbc.driver.T4CTTIfun.doRPC(T4CTTIfun.java:227) at oracle.jdbc.driver.T4C8Oall.doOALL(T4C8Oall.java:531) at oracle.jdbc.driver.T4CPreparedStatement.doOall8(T4CPreparedStatement.java:208) ...




Spring MongoDB Rest API not returning response in 90 seconds which is leading to client timeout

  We have Spring Boot  Rest API deployed in Kubernetes cluster which integrates with MongoDB to fetch the data.  MongoDB is fed with data by a real time Spark & NiFi job.  Our clients complained that for a request what they send they don't have response within 90 seconds. Consider it like an OMS ( Order ManagEment System).  On further analysis, we found that Spark & NiFi processing is happenning within 10 seconds after consuming response data from Kafka. Thus, initally out thought was that it due to delay from upstream to produce data in to Kafka.  Thankfully, our data had create / request  timestamp, and when response was received, and when response was inserted into MongoDB. Subtracting response insert time from request time seemed to be well within 90 seconds. But, still client did timeout on not seeing a response within 90 seconds. This led to confusion on our side.  But, then we realized it was due to Read Preference . We updated this...




MongoDB Regex Query taking more time in Production but same query perform well in UAT

   We came across a situation where-in, MongoDB Query was taking more time in Production like 10 seconds and 4.2 seconds but same query performed well in UAT taking under 400 ms. The very first thought that was evident to us that it is because of amount of data which differed in UAT and Production. Then we ran following to see the execution plan -   db.collection.aggregate(<queries>).explain() This gave us Winning and Rejected Plans. Under which, we analyzed that although it was using 'IXSCAN.' But, it was incorrect index- as we had one compound index built on time field and other fields, and there was other index just on time field for TTL purposes. Winning plan picked TTL index rather than compound index. Thus, we dropped TTL index and built TTL index on a different time field.  That got our query performance time from 10 seconds to 726 ms. Also, for other query the performance came down from 8 seconds to 4.3 seconds. Then, we ran following -  ...