When Using the MRS Multi-user Access to OBS Function, a User Does Not Have the Permission to Access the /tmp Directory
Issue
When the MRS multi-user access to OBS function is used to execute jobs such as Spark, Hive, and Presto jobs, an error message is displayed, indicating that the user does not have the permission to access the /tmp directory.
Symptom
When the MRS multi-user access to OBS function is used to execute jobs such as Spark, Hive, and Presto jobs, an error message is displayed, indicating that the user does not have the permission to access the /tmp directory.
Cause Analysis
A temporary directory exists during job execution. The user who submits the job does not have permission on the temporary directory.
Procedure
- On the Dashboard tab page of the cluster, query and record the name of the agency bound to the cluster.
- Log in to the IAM console.
- Choose Permissions. On the displayed page, click Create Custom Policy.
- Policy Name: Enter a policy name.
- Scope: Select Global services.
- Policy View: Select Visual editor.
- Policy Content:
- Allow: Select Allow.
- Select service: Select Object Storage Service (OBS).
- Select action: Select WriteOnly, ReadOnly, and ListOnly.
- Specific resources:
- Set object to Specify resource path, click Add resource path, and enter obs_bucket_name/tmp/ and obs_bucket_name/tmp/* in Path. The /tmp directory is used as an example. If you need to add permissions for other directories, perform the following steps to add the directories and resource paths of all objects in the directories.
- Set bucket to Specify resource path, click Add resource path, and enter obs_bucket_name in Path.
Replace obs_bucket-name with the actual OBS bucket name. If the bucket type is Parallel File System, you need to add the obs_bucket_name/tmp/ path. If the bucket type is Object Storage, you do not need to add the path.
- (Optional) Request condition, which does not need to be added currently.
Figure 1 Custom policy
- Click OK.
- Select Agency and click Assign Permissions in the Operation column of the agency queried in 1.
- Query and select the created policy in 3.
- Click OK.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.