Uploaded image for project: 'Hadoop HDFS'
  1. Hadoop HDFS
  2. HDFS-9956

LDAP PERFORMANCE ISSUE AND FAIL OVER

Add voteVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • None
    • None

    Description

      The typical LDAP group name resolution works well under typical scenarios. However, we have seen cases where a user is mapped to many groups (in an extreme case, a user is mapped to more than 100 groups). The way it's being implemented now makes this case super slow resolving groups from ActiveDirectory and making the namenode to failover.
      Instead of failover, we can use the parameter(ha.zookeeper.session-timeout.ms) in the getgroups method to time-out and send the failed response back to the user so that we can prevent name node failover.

      Attachments

        Issue Links

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            sanjayvamanna sanjay kenganahalli vamanna

            Dates

              Created:
              Updated:

              Issue deployment