Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Kerberized HDFS and NFS Failover with Cloudera

Introduction​

You can fail over Kerberized HDFS and Kerberized NFS workloads on PowerScale with Cyberstorage for Dell Disaster Recovery by using Access Zone failover. Eyeglass manages the standard SmartConnect and HOST SPN failover for the Access Zone. The Kerberos service principal names (SPNs) that HDFS and Kerberized NFS require are not managed by Eyeglass, so you create them on the production cluster before failover and move them to the DR cluster after failover.

This guide covers two typical configurations:

  • Cloudera CDH clients accessing Kerberized HDFS and WebHDFS on PowerScale.
  • Linux NFS clients accessing Kerberized NFS exports on PowerScale.

Prerequisites​

  • Access Zone failover is configured and working for the Access Zone that serves the HDFS or NFS data. See Access Zone Failover Configuration.
  • The PowerScale clusters are joined to Active Directory, and Kerberos authentication is working for the HDFS or NFS clients.
  • You have administrative access to both PowerScale clusters to run the isi auth ads spn commands.

Kerberized HDFS​

Required SPNs for Cloudera CDH​

Create the following SPNs for each Access Zone that serves HDFS data.

SPNNamePurpose
hdfs/clustername.fqdnName of the cluster that is joined to ADHDFS authentication to AD
hdfs/namenode.smartconnectname.fqdnNameNode FQDN that clients useHDFS authentication to AD for each SmartConnect zone
HTTP/namenode.smartconnectname.fqdnNameNode FQDN that clients useWebHDFS authentication to AD for each SmartConnect zone

Before Failover​

Follow the standard Access Zone failover configuration. Then create the required SPNs on the production cluster. In this example, ad1.test is the Active Directory provider, rnsm04-c07-z01.ad1.test is the SmartConnect zone name that the NameNode uses, and rnsm04-c07.ad1.test is the cluster name:

isi auth ads spn create ad1.test HTTP/rnsm04-c07-z01.ad1.test
isi auth ads spn create ad1.test hdfs/rnsm04-c07-z01.ad1.test
isi auth ads spn create ad1.test hdfs/rnsm04-c07.ad1.test

After Failover​

  1. Delete the SPNs from the production cluster:

    isi auth ads spn delete ad1.test HTTP/rnsm04-c07-z01.ad1.test
    isi auth ads spn delete ad1.test hdfs/rnsm04-c07-z01.ad1.test
    isi auth ads spn delete ad1.test hdfs/rnsm04-c07.ad1.test
  2. Create the same SPNs on the DR cluster:

    isi auth ads spn create ad1.test HTTP/rnsm04-c07-z01.ad1.test
    isi auth ads spn create ad1.test hdfs/rnsm04-c07-z01.ad1.test
    isi auth ads spn create ad1.test hdfs/rnsm04-c07.ad1.test
  3. Verify that the HDFS clients can access the data. You do not need to reboot the Cloudera CDH machines after failover.

Kerberized NFS​

Required SPN​

SPNName
nfs/smartconnectzonename.fqdnSmartConnect zone name of the IP pool that serves the Kerberized NFS exports

Before Failover​

Follow the standard Access Zone failover configuration. Then create the required SPN on the production cluster:

isi auth ads spn create ad1.test nfs/rnsm04-c07-z01.ad1.test

After Failover​

  1. Delete the SPN from the production cluster:

    isi auth ads spn delete ad1.test nfs/rnsm04-c07-z01.ad1.test
  2. Create the SPN on the DR cluster:

    isi auth ads spn create ad1.test nfs/rnsm04-c07-z01.ad1.test
  3. Reboot the NFS client machines before you access the data from the DR cluster. The clients cache Kerberos tickets, so they cannot access the data on the DR cluster until the cached tickets are cleared.

See Also​