forked from docs/doc-exports
MRS UMN 20230907 version
Reviewed-by: Pruthi, Vineet <vineet.pruthi@t-systems.com> Co-authored-by: Yang, Tong <yangtong2@huawei.com> Co-committed-by: Yang, Tong <yangtong2@huawei.com>
This commit is contained in:
parent
4e67ec282b
commit
a6600ded84
@ -2473,7 +2473,7 @@
|
||||
"uri":"mrs_01_0416.html",
|
||||
"product_code":"mrs",
|
||||
"code":"248",
|
||||
"des":"Add a bootstrap action.This operation applies to MRS 3.x or earlier clusters.",
|
||||
"des":"Add a bootstrap action.This operation applies to clusters earlier than MRS 3.x.",
|
||||
"doc_type":"usermanual",
|
||||
"kw":"Adding a Bootstrap Action,Bootstrap Actions,User Guide",
|
||||
"title":"Adding a Bootstrap Action",
|
||||
|
@ -66,7 +66,10 @@
|
||||
</p></li><li id="ALM-24010__li32414295111"><span>Run the <strong id="ALM-24010__b06039552262">ls -l</strong> command to check whether the <strong id="ALM-24010__b55521541273">flume_sChat.crt</strong> file exists.</span><p><ul id="ALM-24010__ul1524072195110"><li id="ALM-24010__li02401027516">If yes, go to <a href="#ALM-24010__li224142155111">5</a>.</li><li id="ALM-24010__li13240192185114">If no, go to <a href="#ALM-24010__li1317765214610">6</a>.</li></ul>
|
||||
</p></li><li id="ALM-24010__li224142155111"><a name="ALM-24010__li224142155111"></a><a name="li224142155111"></a><span>Run the <strong id="ALM-24010__b818113518271">openssl x509 -in flume_sChat.crt -text -noout</strong> command to check whether certificate details are displayed properly.</span><p><ul id="ALM-24010__ul424162205119"><li id="ALM-24010__li62412215519">If yes, go to <a href="#ALM-24010__li593632253716">9</a>.</li><li id="ALM-24010__li3241142135114">If no, go to <a href="#ALM-24010__li1317765214610">6</a>.</li></ul>
|
||||
</p></li><li id="ALM-24010__li1317765214610"><a name="ALM-24010__li1317765214610"></a><a name="li1317765214610"></a><span>Run the following command to go to the Flume script directory:</span><p><p id="ALM-24010__p423665824613"><strong id="ALM-24010__b559162394714">cd </strong><strong id="ALM-24010__b98711913411">${BIGDATA_HOME}</strong><strong id="ALM-24010__b459220231472">/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin</strong></p>
|
||||
</p></li><li id="ALM-24010__li17341718297"><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24010__p159962057135218"><strong id="ALM-24010__b1638395313206">sh geneJKS.sh -f </strong><em id="ALM-24010__i781719538204">sNetty12@</em><strong id="ALM-24010__b65507599201"> -g </strong><em id="ALM-24010__i599765913202">cNetty12@</em><ul id="ALM-24010__ul76631154175216"><li id="ALM-24010__li16663145425211">If yes, go to <a href="#ALM-24010__li57811511185514">8</a>.</li><li id="ALM-24010__li196639543523">If no, go to <a href="#ALM-24010__li593632253716">9</a>.</li></ul>
|
||||
</p></li><li id="ALM-24010__li17341718297"><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24010__p159962057135218"><strong id="ALM-24010__b57614165395">sh geneJKS.sh -f </strong><em id="ALM-24010__i16486142733915">Custom certificate password of the Flume role on the server</em> <strong id="ALM-24010__b123841740143914">-g </strong><em id="ALM-24010__i57281049113911">Custom certificate password of the Flume role on the client</em><ul id="ALM-24010__ul76631154175216"><li id="ALM-24010__li16663145425211">If yes, go to <a href="#ALM-24010__li57811511185514">8</a>.</li><li id="ALM-24010__li196639543523">If no, go to <a href="#ALM-24010__li593632253716">9</a>.<div class="note" id="ALM-24010__note17847172210279"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><div class="p" id="ALM-24010__p136902296299">The custom certificate passwords must meet the following complexity requirements:<ul id="ALM-24010__ul663011436283"><li id="ALM-24010__li17630154392816">Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.</li><li id="ALM-24010__li10630104362812">Contain 8 to 64 characters.</li><li id="ALM-24010__li063084316285">Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.</li></ul>
|
||||
</div>
|
||||
</div></div>
|
||||
</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24010__li57811511185514"><a name="ALM-24010__li57811511185514"></a><a name="li57811511185514"></a><span>Check whether this alarm is generated again during periodic system check.</span><p><ul id="ALM-24010__ul57908115553"><li id="ALM-24010__li879015118554">If yes, go to <a href="#ALM-24010__li593632253716">9</a>.</li><li id="ALM-24010__li57901911155516">If no, no further action is required.</li></ul>
|
||||
</p></li></ol>
|
||||
|
@ -65,7 +65,10 @@
|
||||
<ol start="2" id="ALM-24011__ol093713227375"><li id="ALM-24011__li39371222113715"><span>Log in to the node for which the alarm is generated as user <strong id="ALM-24011__b139218238313">root</strong> and run the <strong id="ALM-24011__b69251123133110">su - omm</strong> command to switch to user <strong id="ALM-24011__b9927623113116">omm</strong>.</span></li><li id="ALM-24011__li83681101307"><span>Run the following command to go to the Flume service certificate directory:</span><p><p id="ALM-24011__p207871518014"><strong id="ALM-24011__b11649760539">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/conf</strong></p>
|
||||
</p></li><li id="ALM-24011__li1015285019"><span>Run the following command to check the effective time and expiration time of the Flume user certificate:</span><p><p id="ALM-24011__p1105152912014"><strong id="ALM-24011__b61241229175719">openssl x509 -noout -text -in flume_sChat.crt</strong></p>
|
||||
</p></li><li id="ALM-24011__li15688521425"><span>Perform <a href="#ALM-24011__li1778591515212">6</a> to <a href="#ALM-24011__li1599711402218">7</a> during off-peak hours to update the certificate file as needed.</span></li><li id="ALM-24011__li1778591515212"><a name="ALM-24011__li1778591515212"></a><a name="li1778591515212"></a><span>Run the following command to go to the Flume script directory:</span><p><p id="ALM-24011__p1924311275213"><strong id="ALM-24011__b10153103102710">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin</strong></p>
|
||||
</p></li><li id="ALM-24011__li1599711402218"><a name="ALM-24011__li1599711402218"></a><a name="li1599711402218"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24011__p4663164119217"><strong id="ALM-24011__b14517820122419">sh geneJKS.sh -f </strong><em id="ALM-24011__i9453621162413">sNetty12@</em><strong id="ALM-24011__b12658830112411"> -g </strong><em id="ALM-24011__i1965933042416">cNetty12@</em><ul id="ALM-24011__ul770182010388"><li id="ALM-24011__li127011820153816">If yes, go to <a href="#ALM-24011__li127861713811">9</a>.</li><li id="ALM-24011__li1260435810588">If no, go to <a href="#ALM-24011__li6673192244411">8</a>.</li></ul>
|
||||
</p></li><li id="ALM-24011__li1599711402218"><a name="ALM-24011__li1599711402218"></a><a name="li1599711402218"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24011__p4663164119217"><strong id="ALM-24011__b57614165395">sh geneJKS.sh -f </strong><em id="ALM-24011__i16486142733915">Custom certificate password of the Flume role on the server</em> <strong id="ALM-24011__b123841740143914">-g </strong><em id="ALM-24011__i57281049113911">Custom certificate password of the Flume role on the client</em><ul id="ALM-24011__ul770182010388"><li id="ALM-24011__li127011820153816">If yes, go to <a href="#ALM-24011__li127861713811">9</a>.</li><li id="ALM-24011__li1260435810588">If no, go to <a href="#ALM-24011__li6673192244411">8</a>.<div class="note" id="ALM-24011__note17847172210279"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><div class="p" id="ALM-24011__p136902296299">The custom certificate passwords must meet the following complexity requirements:<ul id="ALM-24011__ul663011436283"><li id="ALM-24011__li17630154392816">Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.</li><li id="ALM-24011__li10630104362812">Contain 8 to 64 characters.</li><li id="ALM-24011__li063084316285">Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.</li></ul>
|
||||
</div>
|
||||
</div></div>
|
||||
</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24011__li6673192244411"><a name="ALM-24011__li6673192244411"></a><a name="li6673192244411"></a><span>Log in to the Flume node for which the alarm is generated as user <strong id="ALM-24011__b6465424113516">omm</strong> and repeat <a href="#ALM-24011__li1778591515212">6</a> to <a href="#ALM-24011__li1599711402218">7</a>. Then, check whether the alarm is automatically cleared one hour later.</span><p><ul id="ALM-24011__ul15162135612215"><li id="ALM-24011__li18162056621">If yes, go to <a href="#ALM-24011__li127861713811">9</a>.</li><li id="ALM-24011__li101622056322">If no, go to <a href="#ALM-24011__li593632253716">10</a>.</li></ul>
|
||||
</p></li><li id="ALM-24011__li127861713811"><a name="ALM-24011__li127861713811"></a><a name="li127861713811"></a><span>Check whether this alarm is generated again during periodic system check.</span><p><ul id="ALM-24011__ul478613131112"><li id="ALM-24011__li14786121315111">If yes, go to <a href="#ALM-24011__li593632253716">10</a>.</li><li id="ALM-24011__li16786201316114">If no, no further action is required.</li></ul>
|
||||
|
@ -66,7 +66,10 @@
|
||||
</p></li><li id="ALM-24012__li8235154418819"><span>Run the following command to check the effective time and expiration time of the HA user certificate to determine whether the certificate file is still in the validity period:</span><p><div class="p" id="ALM-24012__p19184174518813"><strong id="ALM-24012__b1512574317516">openssl x509 -noout -text -in flume_sChat.crt</strong><ul id="ALM-24012__ul6937722163711"><li id="ALM-24012__li10937142203720">If yes, go to <a href="#ALM-24012__li593632253716">9</a>.</li><li id="ALM-24012__li8937222183720">If no, go to <a href="#ALM-24012__li161213411093">5</a>.</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24012__li161213411093"><a name="ALM-24012__li161213411093"></a><a name="li161213411093"></a><span>Run the following command to go to the Flume script directory:</span><p><p id="ALM-24012__p1369012421997"><strong id="ALM-24012__b10153103102710">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin</strong></p>
|
||||
</p></li><li id="ALM-24012__li084616591915"><a name="ALM-24012__li084616591915"></a><a name="li084616591915"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24012__p2628170131016"><strong id="ALM-24012__b131291419284">sh geneJKS.sh -f </strong><em id="ALM-24012__i1558454132813">sNetty12@</em><strong id="ALM-24012__b5981654112819"> -g </strong><em id="ALM-24012__i1853618545284">cNetty12@</em><ul id="ALM-24012__ul770182010388"><li id="ALM-24012__li127011820153816">If yes, go to <a href="#ALM-24012__li1788491915716">8</a>.</li><li id="ALM-24012__li1465218563614">If no, go to <a href="#ALM-24012__li172496117507">7</a>.</li></ul>
|
||||
</p></li><li id="ALM-24012__li084616591915"><a name="ALM-24012__li084616591915"></a><a name="li084616591915"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24012__p2628170131016"><strong id="ALM-24012__b57614165395">sh geneJKS.sh -f </strong><em id="ALM-24012__i16486142733915">Custom certificate password of the Flume role on the server</em> <strong id="ALM-24012__b123841740143914">-g </strong><em id="ALM-24012__i57281049113911">Custom certificate password of the Flume role on the client</em><ul id="ALM-24012__ul770182010388"><li id="ALM-24012__li127011820153816">If yes, go to <a href="#ALM-24012__li1788491915716">8</a>.</li><li id="ALM-24012__li1465218563614">If no, go to <a href="#ALM-24012__li172496117507">7</a>.<div class="note" id="ALM-24012__note17847172210279"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><div class="p" id="ALM-24012__p136902296299">The custom certificate passwords must meet the following complexity requirements:<ul id="ALM-24012__ul663011436283"><li id="ALM-24012__li17630154392816">Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.</li><li id="ALM-24012__li10630104362812">Contain 8 to 64 characters.</li><li id="ALM-24012__li063084316285">Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.</li></ul>
|
||||
</div>
|
||||
</div></div>
|
||||
</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24012__li172496117507"><a name="ALM-24012__li172496117507"></a><a name="li172496117507"></a><span>Log in to the Flume node for which the alarm is generated as user <strong id="ALM-24012__b20345547174710">omm</strong> and repeat <a href="#ALM-24012__li161213411093">5</a> to <a href="#ALM-24012__li084616591915">6</a>. Then, check whether the alarm is automatically cleared one hour later.</span><p><ul id="ALM-24012__ul567911341584"><li id="ALM-24012__li467933412817">If yes, go to <a href="#ALM-24012__li1788491915716">8</a>.</li><li id="ALM-24012__li96791534282">If no, go to <a href="#ALM-24012__li593632253716">9</a>.</li></ul>
|
||||
</p></li><li id="ALM-24012__li1788491915716"><a name="ALM-24012__li1788491915716"></a><a name="li1788491915716"></a><span>Check whether this alarm is generated again during periodic system check.</span><p><ul id="ALM-24012__ul13890131919711"><li id="ALM-24012__li188909195714">If yes, go to <a href="#ALM-24012__li593632253716">9</a>.</li><li id="ALM-24012__li18904191779">If no, no further action is required.</li></ul>
|
||||
|
@ -66,7 +66,10 @@
|
||||
</p></li><li id="ALM-24013__li32414295111"><span>Run the <strong id="ALM-24013__b0574319155919">ls -l</strong> command to check whether the <strong id="ALM-24013__b144731229175917">ms_sChat.crt</strong> file exists:</span><p><ul id="ALM-24013__ul1524072195110"><li id="ALM-24013__li02401027516">If yes, go to <a href="#ALM-24013__li224142155111">5</a>.</li><li id="ALM-24013__li13240192185114">If no, go to <a href="#ALM-24013__li20454978185">6</a>.</li></ul>
|
||||
</p></li><li id="ALM-24013__li224142155111"><a name="ALM-24013__li224142155111"></a><a name="li224142155111"></a><span>Run the <strong id="ALM-24013__b91511928019">openssl x509 -in ms_sChat.crt -text -noout</strong> command to check whether certificate details are displayed.</span><p><ul id="ALM-24013__ul424162205119"><li id="ALM-24013__li62412215519">If yes, go to <a href="#ALM-24013__li593632253716">9</a>.</li><li id="ALM-24013__li3241142135114">If no, go to <a href="#ALM-24013__li20454978185">6</a>.</li></ul>
|
||||
</p></li><li id="ALM-24013__li20454978185"><a name="ALM-24013__li20454978185"></a><a name="li20454978185"></a><span>Run the following command to go to the Flume script directory:</span><p><p id="ALM-24013__p12408971815"><strong id="ALM-24013__b10153103102710">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin</strong></p>
|
||||
</p></li><li id="ALM-24013__li07622024171810"><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24013__p2335225111811"><strong id="ALM-24013__b1564115519299">sh geneJKS.sh -m </strong><em id="ALM-24013__i68324559295">sKitty12@</em><strong id="ALM-24013__b59651590298"> -n </strong><em id="ALM-24013__i1747213083017">cKitty12@</em><ul id="ALM-24013__ul2241152165114"><li id="ALM-24013__li3241429519">If yes, go to <a href="#ALM-24013__li57811511185514">8</a>.</li><li id="ALM-24013__li4815135625414">If no, go to <a href="#ALM-24013__li593632253716">9</a>.</li></ul>
|
||||
</p></li><li id="ALM-24013__li07622024171810"><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24013__p2335225111811"><strong id="ALM-24013__b1275311512572">sh geneJKS.sh -m </strong><em id="ALM-24013__i17757113518575">Custom password of the MonitorServer certificate on the server</em><strong id="ALM-24013__b1355174005718"> -n </strong><em id="ALM-24013__i741365610577">Custom password of the MonitorServer certificate on the client</em><ul id="ALM-24013__ul2241152165114"><li id="ALM-24013__li3241429519">If yes, go to <a href="#ALM-24013__li57811511185514">8</a>.</li><li id="ALM-24013__li4815135625414">If no, go to <a href="#ALM-24013__li593632253716">9</a>.<div class="note" id="ALM-24013__note3368101522913"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><div class="p" id="ALM-24013__en-us_topic_0000001395012346_p136902296299">The custom certificate passwords must meet the following complexity requirements:<ul id="ALM-24013__en-us_topic_0000001395012346_ul663011436283"><li id="ALM-24013__en-us_topic_0000001395012346_li17630154392816">Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.</li><li id="ALM-24013__en-us_topic_0000001395012346_li10630104362812">Contain 8 to 64 characters.</li><li id="ALM-24013__en-us_topic_0000001395012346_li063084316285">Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.</li></ul>
|
||||
</div>
|
||||
</div></div>
|
||||
</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24013__li57811511185514"><a name="ALM-24013__li57811511185514"></a><a name="li57811511185514"></a><span>Check whether this alarm is generated again during periodic system check.</span><p><ul id="ALM-24013__ul57908115553"><li id="ALM-24013__li879015118554">If yes, go to <a href="#ALM-24013__li593632253716">9</a>.</li><li id="ALM-24013__li57901911155516">If no, no further action is required.</li></ul>
|
||||
</p></li></ol>
|
||||
|
@ -65,7 +65,10 @@
|
||||
<ol start="2" id="ALM-24014__ol093713227375"><li id="ALM-24014__li39371222113715"><span>Log in to the node for which the alarm is generated as user <strong id="ALM-24014__b26841635153211">root</strong> and run the <strong id="ALM-24014__b16947359327">su - omm</strong> command to switch to user <strong id="ALM-24014__b1869512353327">omm</strong>.</span></li><li id="ALM-24014__li1630973716207"><span>Run the following command to go to the MonitorServer certificate file directory:</span><p><p id="ALM-24014__p072163711203"><strong id="ALM-24014__b11649760539">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/conf</strong></p>
|
||||
</p></li><li id="ALM-24014__li1344549132017"><span>Run the following command to check the effective time and expiration time of the MonitorServer user certificate:</span><p><p id="ALM-24014__p14455184919202"><strong id="ALM-24014__b61241229175719">openssl x509 -noout -text -in ms_sChat.crt</strong></p>
|
||||
</p></li><li id="ALM-24014__li15688521425"><span>Perform <a href="#ALM-24014__li368813032118">6</a> to <a href="#ALM-24014__li153512414216">7</a> during off-peak hours to update the certificate file as needed.</span></li><li id="ALM-24014__li368813032118"><a name="ALM-24014__li368813032118"></a><a name="li368813032118"></a><span>Run the following command to go to the Flume script directory:</span><p><p id="ALM-24014__p105243113215"><strong id="ALM-24014__b10153103102710">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin</strong></p>
|
||||
</p></li><li id="ALM-24014__li153512414216"><a name="ALM-24014__li153512414216"></a><a name="li153512414216"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24014__p1889034182113"><strong id="ALM-24014__b06961922123010">sh geneJKS.sh -m </strong><em id="ALM-24014__i1997192343019">sKitty12@</em><strong id="ALM-24014__b106971922103011"> -n </strong><em id="ALM-24014__i532111843017">cKitty12@</em><ul id="ALM-24014__ul770182010388"><li id="ALM-24014__li127011820153816">If yes, go to <a href="#ALM-24014__li127861713811">9</a>.</li><li id="ALM-24014__li1260435810588">If no, go to <a href="#ALM-24014__li6673192244411">8</a>.</li></ul>
|
||||
</p></li><li id="ALM-24014__li153512414216"><a name="ALM-24014__li153512414216"></a><a name="li153512414216"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24014__p1889034182113"><strong id="ALM-24014__b1275311512572">sh geneJKS.sh -m </strong><em id="ALM-24014__i17757113518575">Custom password of the MonitorServer certificate on the server</em><strong id="ALM-24014__b1355174005718"> -n </strong><em id="ALM-24014__i741365610577">Custom password of the MonitorServer certificate on the client</em><ul id="ALM-24014__ul770182010388"><li id="ALM-24014__li127011820153816">If yes, go to <a href="#ALM-24014__li127861713811">9</a>.</li><li id="ALM-24014__li1260435810588">If no, go to <a href="#ALM-24014__li6673192244411">8</a>.<div class="note" id="ALM-24014__note3368101522913"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><div class="p" id="ALM-24014__en-us_topic_0000001395012346_p136902296299">The custom certificate passwords must meet the following complexity requirements:<ul id="ALM-24014__en-us_topic_0000001395012346_ul663011436283"><li id="ALM-24014__en-us_topic_0000001395012346_li17630154392816">Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.</li><li id="ALM-24014__en-us_topic_0000001395012346_li10630104362812">Contain 8 to 64 characters.</li><li id="ALM-24014__en-us_topic_0000001395012346_li063084316285">Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.</li></ul>
|
||||
</div>
|
||||
</div></div>
|
||||
</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24014__li6673192244411"><a name="ALM-24014__li6673192244411"></a><a name="li6673192244411"></a><span>Log in to the Flume node for which the alarm is generated as user <strong id="ALM-24014__b18561413183413">omm</strong> and repeat <a href="#ALM-24014__li368813032118">6</a> to <a href="#ALM-24014__li153512414216">7</a>. Then, check whether the alarm is automatically cleared one hour later.</span><p><ul id="ALM-24014__ul15162135612215"><li id="ALM-24014__li18162056621">If yes, go to <a href="#ALM-24014__li127861713811">9</a>.</li><li id="ALM-24014__li101622056322">If no, go to <a href="#ALM-24014__li593632253716">10</a>.</li></ul>
|
||||
</p></li><li id="ALM-24014__li127861713811"><a name="ALM-24014__li127861713811"></a><a name="li127861713811"></a><span>Check whether this alarm is generated again during periodic system check.</span><p><ul id="ALM-24014__ul478613131112"><li id="ALM-24014__li14786121315111">If yes, go to <a href="#ALM-24014__li593632253716">10</a>.</li><li id="ALM-24014__li16786201316114">If no, no further action is required.</li></ul>
|
||||
|
@ -66,7 +66,10 @@
|
||||
</p></li><li id="ALM-24015__li592012461273"><span>Run the following command to check the effective time and expiration time of the user certificate to determine whether the certificate file is still in the validity period:</span><p><div class="p" id="ALM-24015__p14775147122712"><strong id="ALM-24015__b1512574317516">openssl x509 -noout -text -in ms_sChat.crt</strong><ul id="ALM-24015__ul6937722163711"><li id="ALM-24015__li10937142203720">If yes, go to <a href="#ALM-24015__li593632253716">9</a>.</li><li id="ALM-24015__li8937222183720">If no, go to <a href="#ALM-24015__li160343112815">5</a>.</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24015__li160343112815"><a name="ALM-24015__li160343112815"></a><a name="li160343112815"></a><span>Run the following command to go to the Flume script directory:</span><p><p id="ALM-24015__p20957163172814"><strong id="ALM-24015__b10153103102710">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin</strong></p>
|
||||
</p></li><li id="ALM-24015__li68486146283"><a name="ALM-24015__li68486146283"></a><a name="li68486146283"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24015__p928811154287"><strong id="ALM-24015__b22371028163112">sh geneJKS.sh -m </strong><em id="ALM-24015__i3583122820318">sKitty12@</em><strong id="ALM-24015__b6330932153114"> -n </strong><em id="ALM-24015__i786017322314">cKitty12@</em><ul id="ALM-24015__ul770182010388"><li id="ALM-24015__li127011820153816">If yes, go to <a href="#ALM-24015__li1788491915716">8</a>.</li><li id="ALM-24015__li1465218563614">If no, go to <a href="#ALM-24015__li172496117507">7</a>.</li></ul>
|
||||
</p></li><li id="ALM-24015__li68486146283"><a name="ALM-24015__li68486146283"></a><a name="li68486146283"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24015__p928811154287"><strong id="ALM-24015__b1275311512572">sh geneJKS.sh -m </strong><em id="ALM-24015__i17757113518575">Custom password of the MonitorServer certificate on the server</em><strong id="ALM-24015__b1355174005718"> -n </strong><em id="ALM-24015__i741365610577">Custom password of the MonitorServer certificate on the client</em><ul id="ALM-24015__ul770182010388"><li id="ALM-24015__li127011820153816">If yes, go to <a href="#ALM-24015__li1788491915716">8</a>.</li><li id="ALM-24015__li1465218563614">If no, go to <a href="#ALM-24015__li172496117507">7</a>.<div class="note" id="ALM-24015__note3368101522913"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><div class="p" id="ALM-24015__en-us_topic_0000001395012346_p136902296299">The custom certificate passwords must meet the following complexity requirements:<ul id="ALM-24015__en-us_topic_0000001395012346_ul663011436283"><li id="ALM-24015__en-us_topic_0000001395012346_li17630154392816">Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.</li><li id="ALM-24015__en-us_topic_0000001395012346_li10630104362812">Contain 8 to 64 characters.</li><li id="ALM-24015__en-us_topic_0000001395012346_li063084316285">Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.</li></ul>
|
||||
</div>
|
||||
</div></div>
|
||||
</li></ul>
|
||||
</div>
|
||||
</p></li><li id="ALM-24015__li172496117507"><a name="ALM-24015__li172496117507"></a><a name="li172496117507"></a><span>Log in to the Flume node for which the alarm is generated as user <strong id="ALM-24015__b3795122633813">omm</strong> and repeat <a href="#ALM-24015__li160343112815">5</a> to <a href="#ALM-24015__li68486146283">6</a>. Then, check whether the alarm is automatically cleared one hour later.</span><p><ul id="ALM-24015__ul567911341584"><li id="ALM-24015__li467933412817">If yes, go to <a href="#ALM-24015__li1788491915716">8</a>.</li><li id="ALM-24015__li96791534282">If no, go to <a href="#ALM-24015__li593632253716">9</a>.</li></ul>
|
||||
</p></li><li id="ALM-24015__li1788491915716"><a name="ALM-24015__li1788491915716"></a><a name="li1788491915716"></a><span>Check whether this alarm is generated again during periodic system check.</span><p><ul id="ALM-24015__ul13890131919711"><li id="ALM-24015__li188909195714">If yes, go to <a href="#ALM-24015__li593632253716">9</a>.</li><li id="ALM-24015__li18904191779">If no, no further action is required.</li></ul>
|
||||
|
@ -2223,7 +2223,7 @@
|
||||
"code":"247"
|
||||
},
|
||||
{
|
||||
"desc":"Add a bootstrap action.This operation applies to MRS 3.x or earlier clusters.",
|
||||
"desc":"Add a bootstrap action.This operation applies to clusters earlier than MRS 3.x.",
|
||||
"product_code":"mrs",
|
||||
"title":"Adding a Bootstrap Action",
|
||||
"uri":"mrs_01_0416.html",
|
||||
|
@ -75,6 +75,7 @@
|
||||
<td class="cellrowborder" valign="top" headers="mcps1.3.2.3.1.6.1.2 "><p id="admin_guide_000239__en-us_topic_0046736684_p23115188">Bigdata123@</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" headers="mcps1.3.2.3.1.6.1.3 "><p id="admin_guide_000239__en-us_topic_0046736684_p60390938">Internal running user of the system. This user is an OS user generated on all nodes and does not require a unified password.</p>
|
||||
<p id="admin_guide_000239__p162211545152917">In MRS 3.2.0-LTS.2 or later, the password of user <strong id="admin_guide_000239__b14982185482917">omm</strong> is randomly generated.</p>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
|
@ -1,8 +1,7 @@
|
||||
<a name="mrs_01_0413"></a><a name="mrs_01_0413"></a>
|
||||
|
||||
<h1 class="topictitle1">Installing Third-Party Software Using Bootstrap Actions</h1>
|
||||
<div id="body1527134095709"><p id="mrs_01_0413__p714415401742">This operation applies to MRS 3.<em id="mrs_01_0413__i11145161815226">x</em> or earlier clusters.</p>
|
||||
<p id="mrs_01_0413__p214454011413">In MRS 3.<em id="mrs_01_0413__i1209766407112129">x</em>, bootstrap actions cannot be added during cluster creation.</p>
|
||||
<div id="body1527134095709"><p id="mrs_01_0413__p714415401742">This operation applies to clusters earlier than MRS 3.x.</p>
|
||||
<div class="section" id="mrs_01_0413__section1597735362819"><h4 class="sectiontitle">Prerequisites</h4><p id="mrs_01_0413__p8554151452919">The bootstrap action script has been prepared by referring to <a href="mrs_01_0417.html">Preparing the Bootstrap Action Script</a>.</p>
|
||||
</div>
|
||||
<div class="section" id="mrs_01_0413__section15552454152615"><h4 class="sectiontitle">Adding a Bootstrap Action When Creating a Cluster</h4><ol id="mrs_01_0413__ol2075093010406"><li id="mrs_01_0413__li3745133010409"><span>Log in to the MRS management console.</span></li><li id="mrs_01_0413__li8745230114016"><span>Click <span class="parmvalue" id="mrs_01_0413__parmvalue485530574112129"><b>Create Cluster</b></span>. The page for creating a cluster is displayed.</span></li><li id="mrs_01_0413__li18785535122717"><span>Click the <strong id="mrs_01_0413__b1297263501112129">Custom Config</strong> tab.</span></li><li id="mrs_01_0413__li15299182012355"><span>Configure the cluster software and hardware by referring to <a href="mrs_01_0513.html">Creating a Custom Cluster</a>.</span></li><li id="mrs_01_0413__li3745193012404"><span>On the <span class="wintitle" id="mrs_01_0413__wintitle1542558719112129"><b>Set Advanced Options</b></span> tab page, click <span class="wintitle" id="mrs_01_0413__wintitle737204160112129"><b>Add</b></span> in the <strong id="mrs_01_0413__b376187139112129">Bootstrap Action</strong> area.</span><p>
|
||||
|
@ -2,7 +2,7 @@
|
||||
|
||||
<h1 class="topictitle1">Adding a Bootstrap Action</h1>
|
||||
<div id="body1527303335451"><p id="mrs_01_0416__p192521961220">Add a bootstrap action.</p>
|
||||
<p id="mrs_01_0416__p714415401742">This operation applies to MRS 3.<em id="mrs_01_0416__i989172714499">x</em> or earlier clusters.</p>
|
||||
<p id="mrs_01_0416__p714415401742"><span id="mrs_01_0416__ph16672358195815">This operation applies to clusters earlier than MRS 3.<em id="mrs_01_0416__i92531956595">x</em></span>.</p>
|
||||
<div class="section" id="mrs_01_0416__section2931547113012"><h4 class="sectiontitle">Procedure</h4><ol id="mrs_01_0416__ol44029245191947"><li id="mrs_01_0416__li251701501815"><span>Log in to the MRS management console.</span></li><li id="mrs_01_0416__li139710345186"><span>Choose <strong id="mrs_01_0416__b1515218537102">Clusters</strong> > <strong id="mrs_01_0416__b9153653141016">Active Clusters</strong> and click the name of your desired cluster.</span></li><li id="mrs_01_0416__li12181103393614"><span>On the page that is displayed, click the <strong id="mrs_01_0416__b907329279">Bootstrap Actions</strong> tab.</span></li><li id="mrs_01_0416__li07561452102414"><span>Click <span class="uicontrol" id="mrs_01_0416__uicontrol1722111175335"><b>Add</b></span> and set parameters as prompted.</span><p>
|
||||
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="mrs_01_0416__table1187355124512" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameters</caption><thead align="left"><tr id="mrs_01_0416__row10187205514517"><th align="left" class="cellrowborder" valign="top" width="27%" id="mcps1.3.3.2.4.2.1.2.3.1.1"><p id="mrs_01_0416__p818725511459">Parameter</p>
|
||||
</th>
|
||||
|
@ -34,7 +34,7 @@
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row178019237579"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.4.2.2.3.1.1 "><p id="mrs_01_0513__p2065916742212">Cluster Version</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.4.2.2.3.1.2 "><p id="mrs_01_0513__p11302191119226">Currently, MRS 1.6.3, 1.7.2, 1.9.2, 2.1.0, 3.1.0-LTS.1, 3.1.2-LTS.3 , and 3.2.0-LTS.1 are supported. The latest version of MRS is used by default.</p>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.4.2.2.3.1.2 "><p id="mrs_01_0513__p11302191119226">Currently, MRS 3.1.2-LTS.x , and 3.2.0-LTS.x are supported. The default value displayed on the UI varies depending on the version.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row3780823165720"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.4.2.2.3.1.1 "><p id="mrs_01_0513__p197518710224">Cluster Type</p>
|
||||
@ -210,6 +210,43 @@
|
||||
<p id="mrs_01_0513__p5919131831716">The <strong id="mrs_01_0513__b1312915113234">MRS_ECS_DEFAULT_AGENCY</strong> agency has the OBSOperateAccess permission of OBS and the CESFullAccess (for users who have enabled fine-grained policies), CES Administrator, and KMS Administrator permissions in the region where the cluster is located.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row20617125916269"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.6.2.2.3.1.1 "><p id="mrs_01_0513__p551495471016">System Disk Encryption</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.6.2.2.3.1.2 "><p id="mrs_01_0513__p95874015171">Whether to encrypt data in the system disk mounted to the cluster. This function is disabled by default. To use this function, you must have the Security Administrator and KMS Administrator permissions.</p>
|
||||
<p id="mrs_01_0513__p1441105061214">The keys used to encrypt system disks are provided by Key Management Service (KMS). You do not need to build and maintain the key management infrastructure.</p>
|
||||
<p id="mrs_01_0513__p14255019124">You can choose whether to enable system disk encryption by configuring this parameter.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row989675552615"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.6.2.2.3.1.1 "><p id="mrs_01_0513__p4180347191011">System Disk Key ID</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.6.2.2.3.1.2 "><p id="mrs_01_0513__p1348291401417">This parameter is available only when <span class="parmname" id="mrs_01_0513__parmname170015239501"><b>System Disk Encryption</b></span> is enabled. The parameter indicates the key ID corresponding to the selected key name.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row145332507262"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.6.2.2.3.1.1 "><p id="mrs_01_0513__p1240517405101">System Disk Key Name</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.6.2.2.3.1.2 "><p id="mrs_01_0513__p66071326121410">This parameter is mandatory when <span class="parmname" id="mrs_01_0513__parmname779576201416"><b>System Disk Encryption</b></span> is enabled. Select the name of the key used to encrypt the system disk. By default, the default master key named <strong id="mrs_01_0513__b204761825141412">evs/default</strong> is selected. You can select another master key from the drop-down list. If disks are encrypted using a CMK, which is then disabled or scheduled for deletion, the disks can no longer be read from or written to, and data on these disks may never be restored. Exercise caution when performing this operation.</p>
|
||||
<p id="mrs_01_0513__p36074269146">Click <span class="parmname" id="mrs_01_0513__parmname799115016146"><b>View Key List</b></span> to enter a page where you can create and manage keys.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row3236230111812"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.6.2.2.3.1.1 "><p id="mrs_01_0513__p44111926115510">Data Disk Encryption</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.6.2.2.3.1.2 "><p id="mrs_01_0513__p64115263552">Whether to encrypt data in the data disk mounted to the cluster. This function is disabled by default. To use this function, you must have the Security Administrator and KMS Administrator permissions.</p>
|
||||
<p id="mrs_01_0513__p1341115260555">The keys used to encrypt data disks are provided by Key Management Service (KMS). You do not need to build and maintain the key management infrastructure.</p>
|
||||
<p id="mrs_01_0513__p17411026165510">Click <span class="parmname" id="mrs_01_0513__parmname141152611550"><b>Data Disk Encryption</b></span> to enable or disable the data disk encryption function.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row85391633112311"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.6.2.2.3.1.1 "><p id="mrs_01_0513__p1841152618550">Data Disk Key ID</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.6.2.2.3.1.2 "><p id="mrs_01_0513__p194111626105510">This parameter is displayed only when the <span class="parmname" id="mrs_01_0513__parmname341119269553"><b>Data Disk Encryption</b></span> function is enabled. This parameter indicates the key ID corresponding to the selected key name.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row1522613275189"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.6.2.2.3.1.1 "><p id="mrs_01_0513__p5411726155513">Data Disk Key Name</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.6.2.2.3.1.2 "><p id="mrs_01_0513__p841242613552">This parameter is mandatory when the <span class="parmname" id="mrs_01_0513__parmname19412426125510"><b>Data Disk Encryption</b></span> function is enabled. Select the name of the key used to encrypt the data disk. By default, the default master key named <strong id="mrs_01_0513__b54121126125514">evs/default</strong> is selected. You can select another master key from the drop-down list.</p>
|
||||
<p id="mrs_01_0513__p1341222695516">If disks are encrypted using a CMK, which is then disabled or scheduled for deletion, the disks can no longer be read from or written to, and data on these disks may never be restored. Exercise caution when performing this operation.</p>
|
||||
<p id="mrs_01_0513__p04121726105517">Click <span class="parmname" id="mrs_01_0513__parmname14412182616557"><b>View Key List</b></span> to enter a page where you can create and manage keys.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_0513__row846175116240"><td class="cellrowborder" valign="top" width="30%" headers="mcps1.3.6.2.2.3.1.1 "><p id="mrs_01_0513__p84665118243">Alarm</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="70%" headers="mcps1.3.6.2.2.3.1.2 "><p id="mrs_01_0513__p10460514249">If the alarm function is enabled, the cluster maintenance personnel can be notified in a timely manner to locate faults when the cluster runs abnormally or the system is faulty.</p>
|
||||
|
@ -8,7 +8,13 @@
|
||||
</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody><tr id="mrs_01_9003__row26461628288"><td class="cellrowborder" valign="top" width="25.19%" headers="mcps1.3.1.1.3.1.1 "><p id="mrs_01_9003__p86471420286">2023-07-27</p>
|
||||
<tbody><tr id="mrs_01_9003__row1774216312421"><td class="cellrowborder" valign="top" width="25.19%" headers="mcps1.3.1.1.3.1.1 "><p id="mrs_01_9003__p956315107422">2023-09-08</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="74.81%" headers="mcps1.3.1.1.3.1.2 "><p id="mrs_01_9003__p516410261423">Modified the following content:</p>
|
||||
<ul id="mrs_01_9003__ul034619507426"><li id="mrs_01_9003__li488119449441">Updated available cluster versions. For details, see <a href="mrs_01_0513.html">Creating a Custom Cluster</a>.</li><li id="mrs_01_9003__li126011555115919">Added the description about system disk encryption parameters. For details, see <a href="mrs_01_0513.html">Creating a Custom Cluster</a>.</li><li id="mrs_01_9003__li191142048874">Modified the constraints of adding a bootstrap action. For details, see <a href="mrs_01_0416.html">Adding a Bootstrap Action</a>.</li><li id="mrs_01_9003__li74825493215">Add the description that the password of user <strong id="mrs_01_9003__b1268893015434">omm</strong> is radomly generated. For details, see <a href="admin_guide_000239.html">User Account List</a>.</li><li id="mrs_01_9003__li4447125317423">Optimized Flume alarm description. For details, see <a href="ALM-24010.html">ALM-24010 Flume Certificate File Is Invalid or Damaged</a> to <a href="ALM-24015.html">ALM-24015 Flume MonitorServer Certificate File Has Expired</a>.</li></ul>
|
||||
</td>
|
||||
</tr>
|
||||
<tr id="mrs_01_9003__row26461628288"><td class="cellrowborder" valign="top" width="25.19%" headers="mcps1.3.1.1.3.1.1 "><p id="mrs_01_9003__p86471420286">2023-07-27</p>
|
||||
</td>
|
||||
<td class="cellrowborder" valign="top" width="74.81%" headers="mcps1.3.1.1.3.1.2 "><p id="mrs_01_9003__p101581630142917">Modified the following content:</p>
|
||||
<p id="mrs_01_9003__p133715296340">Modified the ALM-45431 alarm title. For details, see <a href="ALM-45431.html">ALM-45431 Improper ClickHouse Instance Distribution for Topology Allocation</a>.</p>
|
||||
|
Loading…
x
Reference in New Issue
Block a user