Updated on 2026-10-09 GMT+08:00

Creating an MRS Cluster User

By default, only the admin user has full operational permissions on MRS Manager, which does not support multi-department and multi-role collaborative O&M. When different teams or applications access the cluster, administrators must create dedicated user accounts and assign appropriate permissions to enforce permission isolation and enable operation auditing. On MRS Manager, you can create users and assign user groups or roles to satisfy multi-user security management requirements. This section describes how to create a service user in an MRS cluster.

  • Human-machine user: Used for manual operations, such as logging in to MRS Manager for cluster O&M or executing commands on a component client. You must set a password during user creation and change the initial password upon first login.
  • Machine-to-machine user: Used for automated application access to the cluster, such as developing component applications or executing scheduled tasks. The system automatically generates a random password during user creation; no manual configuration is required.
  • User group: A logical categorization of users used to manage permissions in batches. When a user is added to a user group, they automatically inherit all roles and permissions assigned to that group. A user can belong to multiple user groups.
  • Primary group: The default group assigned when a user creates directories or files. A user can have only one primary group, but can belong to multiple secondary groups. The primary group provides the same permission control functionality as a secondary group.
  • Role: A collection of specific operational permissions. Assigning a role directly to a user grants fine-grained permissions. If the permissions inherited from a user group already meet operational requirements, you do not need to assign additional roles to the user.

Notes and Constraints

  • In MRS 3.x or later, MRS Manager supports up to 50,000 users, including built-in users.
  • In MRS 2.x or earlier, MRS Manager supports up to 1,000 users.

Video Tutorial

This video demonstrates how to create a service user in an MRS cluster.

The UI may vary depending on the version. This tutorial is for reference only.

Creating a User (MRS 3.x and Later)

  1. Log in to FusionInsight Manager of the MRS cluster.

    For details about how to log in to FusionInsight Manager, see Accessing MRS Manager.

  2. Choose System > Permission > User.
  3. On the User page, click Create.
  4. Set Username. The username can contain digits, letters, underscores (_), hyphens (-), and spaces. It is case-insensitive and cannot be the same as any existing username in the system or OS.

    If the username contains special characters, such as periods (.) and at signs (@), the IAM user may fail to be synchronized.

  5. Set User Type to Human-Machine or Machine-Machine.

    • Human-Machine user: used for FusionInsight Manager O&M and component client operations. If you select this option, you also need to select the password policy and set Password and Confirm Password.
    • Machine-Machine user: used for component application development. If you select this option, the password is randomly generated.

  6. In the User Group area, click Add to add one or more user groups to the list.

    • If the selected user group has been bound to a role or a permission policy has been configured in Ranger, the user can obtain the corresponding permissions.
    • After FusionInsight Manager is installed, some user groups generated by default have special permissions. Select desired user groups based on the descriptions on the UI.
    • If existing user groups cannot meet your requirements, click Create User Group to create a user group. For details, see Creating a User Group.

  7. Select a group from the Primary Group drop-down list to create directories and files.

    The drop-down list contains all groups selected in User Group.

    A user can belong to multiple groups (including one primary group and multiple secondary groups). The primary group is set to facilitate maintenance and comply with the permission mechanism of the Hadoop community. The primary group has the same permission control functionality as other groups.

  8. In the Role area, click Add to bind roles to the user.

    • When creating a user, you can assign a role to define their permissions.
    • If the permissions granted to the user from the user group cannot meet service requirements, you can bind other created roles to the user. You can also click Create Role to create a role first. For details, see Creating a Role.

      It takes up to 3 minutes for role permission assignments to take effect for the user. If the permissions inherited from the user group are sufficient, you do not need to assign a role.

    • After enabling Ranger authentication for a component, you must configure Ranger policies to assign user permissions beyond those provided by the default user group or role.
    • If a user is not added to a user group or assigned a role, the user cannot view information or perform operations after logging in to FusionInsight Manager.

  9. Enter information in Description.
  10. Click OK.

    After a human-machine user is created, you need to change the initial password as prompted after logging in to FusionInsight Manager.

Verification:

In the user list, verify that the new user is displayed with a normal state. This confirms that the user was created successfully. For a human-machine user, log in to MRS Manager as the new user to verify that you are prompted to reset the initial password.

Creating a User (MRS 2.x and Earlier)

  1. Log in to FusionInsight Manager of the MRS cluster.

    For details about how to log in to FusionInsight Manager, see Accessing MRS Manager.

  2. Click System.
  3. In the Permission area, click Manage User.
  4. On the User page, click Create.
  5. Configure parameters as prompted and enter a username in Username.

    • A username that differs only in alphabetic case from an existing username is not allowed. For example, if User1 has been created, you cannot create user1.
    • When you use the user you created, enter the exactly correct username, which is case-sensitive.
    • Username is mandatory and contains 3 to 20 characters. Only digits, letters, and underscores (_) are allowed.
    • If the username contains special characters, such as periods (.) and at signs (@), the IAM user may fail to be synchronized.
    • root, omm, and ommdba are reserved system users. Select another username.

  6. Set User Type to Human-Machine or Machine-Machine.

    • Human-machine user: used for MRS Manager O&M scenarios and component client operation scenarios. If you select this user type, you need to enter a password and confirm the password in Password and Confirm Password accordingly.
    • Machine-machine users: used for MRS application development scenarios. If you select this user type, you do not need to enter a password, because the password is randomly generated.

  7. In User Group, click Select and Join User Group to select user groups and add users to them.

    • If roles have been assigned to user groups, users automatically inherit the permissions of those roles.
    • If you want to grant new users with Hive permissions, add the users to the Hive group.
    • If a user needs to manage tenant resources, the user group must be assigned the Manager_tenant role and the role corresponding to the tenant.

  8. In Primary Group, select a group as the primary group for users to create directories and files. The drop-down list contains all groups selected in User Group.
  9. In Assign Rights by Role, click Select and Add Role to add roles for users based on onsite service requirements.

    • If the permissions granted to the user from the user group cannot meet service requirements, you can bind other created roles to the user. It takes 3 minutes to make role permissions granted to the new user take effect.
    • When creating a user, you can assign a role to define their permissions.
    • A new user can access web UIs of HDFS, HBase, YARN, Spark, and Hue even when roles are not assigned to the user.

  10. In Description, provide description based on onsite service requirements.

    Description is optional.

  11. Click OK.

    If a new user is used in the MRS cluster for the first time, for example, used for logging in to MRS Manager or using the cluster client, the password must be changed.

Verification:

In the user list, verify that the new user is displayed with a normal state. This confirms that the user was created successfully. For a human-machine user, log in to MRS Manager as the new user to verify that you are prompted to reset the initial password.

FAQs

  • What should I do if a newly created user cannot log in or lacks required permissions?

    Possible causes: The user is not added to any user group or assigned any role (resulting in a lack of permissions), the username contains unsupported special characters (causing IAM synchronization to fail), or a human-machine user has not changed their initial password upon first login.

    Ensure that the user is added to at least one user group or assigned a role. Verify that the username contains only letters, digits, underscores (_), hyphens (-), or spaces. For a human-machine user, log in to MRS Manager and reset the initial password as prompted upon first login.

  • What should I do if assigned role permissions do not take effect immediately?

    After you assign a role to a user, permissions may take up to several minutes to take effect. If Ranger authorization is enabled for the component, you must also assign permissions to the user using Ranger policies.

    Wait for 3 minutes and try again. If Ranger authorization is enabled for the component, configure an access policy for the user in Ranger.

  • What should I do if user synchronization fails due to special characters in the username?

    If a username contains unsupported special characters, IAM synchronization fails, preventing the user from performing operations.

    Delete the affected user, then recreate the user and ensure the new username contains only letters, digits, underscores (_), hyphens (-), or spaces.

Helpful Links