Yang, Tong 3f5759eed2 MRS comp-lts 2.0.38.SP20 version
Reviewed-by: Hasko, Vladimir <vladimir.hasko@t-systems.com>
Co-authored-by: Yang, Tong <yangtong2@huawei.com>
Co-committed-by: Yang, Tong <yangtong2@huawei.com>
2023-01-19 17:08:45 +00:00

18 lines
4.0 KiB
HTML

<a name="mrs_01_0972"></a><a name="mrs_01_0972"></a>
<h1 class="topictitle1">Authorizing Over 32 Roles in Hive</h1>
<div id="body8662426"><div class="section" id="mrs_01_0972__en-us_topic_0000001219149029_section1971814572430"><h4 class="sectiontitle">Scenario</h4><p id="mrs_01_0972__en-us_topic_0000001219149029_p47611257174319">This function applies to Hive.</p>
<p id="mrs_01_0972__en-us_topic_0000001219149029_p67618575439">The number of OS user groups is limited, and the number of roles that can be created in Hive cannot exceed 32. After this function is enabled, more than 32 roles can be created in Hive.</p>
<div class="note" id="mrs_01_0972__en-us_topic_0000001219149029_note2391914161812"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><ul id="mrs_01_0972__en-us_topic_0000001219149029_ul114102404529"><li id="mrs_01_0972__en-us_topic_0000001219149029_li124101340105218">After this function is enabled and the table or database is authorized, roles that have the same permission on the table or database will be combined using vertical bars (|). When the ACL permission is queried, the combined result is displayed, which is different from that before the function is enabled. This operation is irreversible. Determine whether to make adjustment based on the actual application scenario.</li><li id="mrs_01_0972__en-us_topic_0000001219149029_li124801243125210">If the current component uses Ranger for permission control, you need to configure related policies based on Ranger for permission management. For details, see <a href="mrs_01_1858.html">Adding a Ranger Access Permission Policy for Hive</a>.</li><li id="mrs_01_0972__en-us_topic_0000001219149029_li16718534122419">After this function is enabled, a maximum of 512 roles (including <strong id="mrs_01_0972__en-us_topic_0000001219149029_b187758233317">owner</strong>) are supported by default. The number is controlled by the user-defined parameter <strong id="mrs_01_0972__en-us_topic_0000001219149029_b161518581633">hive.supports.roles.max</strong> of MetaStore. You can change the value based on the actual application scenario.</li></ul>
</div></div>
</div>
<div class="section" id="mrs_01_0972__en-us_topic_0000001219149029_section3720957144315"><h4 class="sectiontitle">Procedure</h4><ol id="mrs_01_0972__en-us_topic_0000001219149029_ol181811550174911"><li id="mrs_01_0972__en-us_topic_0000001219149029_li874802051810"><span>Log in to FusionInsight Manager. For details, see <a href="mrs_01_2124.html">Accessing FusionInsight Manager</a>. Choose <strong id="mrs_01_0972__en-us_topic_0000001219149029_b13850122313567">Cluster</strong> &gt; <strong id="mrs_01_0972__en-us_topic_0000001219149029_b0140646394">Services</strong> &gt; <strong id="mrs_01_0972__en-us_topic_0000001219149029_b161404461198">Hive</strong> &gt; <strong id="mrs_01_0972__en-us_topic_0000001219149029_b514018464915">Configurations</strong> &gt; <strong id="mrs_01_0972__en-us_topic_0000001219149029_b16141174611918">All Configurations</strong>.</span></li><li id="mrs_01_0972__en-us_topic_0000001219149029_li540112614154"><span>Choose <strong id="mrs_01_0972__en-us_topic_0000001219149029_b1588110531090">MetaStore(Role)</strong> &gt; <strong id="mrs_01_0972__en-us_topic_0000001219149029_b8881653999">Customization</strong>, add a customized parameter to the <strong id="mrs_01_0972__en-us_topic_0000001219149029_b14881653495">hivemetastore-site.xml</strong> parameter file, set <strong id="mrs_01_0972__en-us_topic_0000001219149029_b15882145310910">Name</strong> to <strong id="mrs_01_0972__en-us_topic_0000001219149029_b18882185317912">hive.supports.over.32.roles</strong>, and set <strong id="mrs_01_0972__en-us_topic_0000001219149029_b10882105310917">Value</strong> to <strong id="mrs_01_0972__en-us_topic_0000001219149029_b158831153797">true</strong>. Restart all Hive instances after the modification.</span></li></ol>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="mrs_01_0581.html">Using Hive</a></div>
</div>
</div>