ALM-45192 Failed to Obtain the IAM Security Token
Alarm Description
Meta calls an ECS API to obtain the AK/SK information. If permissions are set for users, Meta also needs to call an IAM API to obtain the security token. This alarm is generated when Meta fails to call the IAM API for three consecutive times.
This alarm is cleared when Meta successfully calls the IAM API.
Alarm Attributes
Alarm ID |
Alarm Severity |
Alarm Type |
Service Type |
Auto Cleared |
---|---|---|---|---|
45192 |
Major |
Error handling |
meta |
Yes |
Alarm Parameters
Type |
Parameter |
Description |
---|---|---|
Location Information |
Source |
Specifies the cluster for which the alarm is generated. |
ServiceName |
Specifies the service for which the alarm is generated. |
|
RoleName |
Specifies the role for which the alarm is generated. |
|
HostName |
Specifies the host for which the alarm is generated. |
Impact on the System
For systems with decoupled storage and compute, the cluster cannot obtain the latest security token. Users with fine-grained permissions may fail to access OBS and cannot use component services.
Possible Causes
- The meta role of the MRS cluster is abnormal.
- The IAM service is abnormal.
Handling Procedure
Check the status of the meta role.
- On FusionInsight Manager, choose O&M > Alarm > Alarms, click in the row of this alarm, and view the host name of the instance for which the alarm is generated in Location.
- On FusionInsight Manager of the cluster, choose Cluster > Services > meta. On the page that is displayed, click the Instance tab, and check whether the meta role corresponding to the host for which the alarm is generated is normal.
- Select the abnormal role, click More, and select Restart Instance to restart the abnormal meta role.
- Check whether the alarm is cleared.
- If yes, no further action is required.
- If no, go to 5.
- Log in to the host obtained in 1 and check whether the /var/log/Bigdata/meta/mrs-meta.log file contains error information. If yes, rectify the fault based on the log information.
- Check whether the alarm is cleared.
- If yes, no further action is required.
- If no, go to 7.
Collect fault information.
- On FusionInsight Manager of the active cluster, choose O&M. In the navigation pane on the left, choose Log > Download.
- Expand the Service drop-down list, select meta for the target cluster, and click OK.
- Click in the upper right corner, and set Start Date and End Date for log collection to 10 minutes ahead of and after the alarm generation time, respectively. Then, click Download.
- Contact O&M engineers and provide the collected logs.
Alarm Clearance
This alarm is automatically cleared after the fault is rectified.
Related Information
None.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot