Cloudera Manager 웹 UI(7180 · 7183) 와 CDP Private Cloud 의 Management Console 은 인증 컴포넌트가 완전히 다르다. 로그의 클래스명으로 구분한다. com.cloudera.server.web.cmf.* 가 보이면 /var/log/cloudera-scm-server/cloudera-scm-server.log 즉 Cloudera Manager 쪽이고, Management Console 은 ECS 위의 Thunderhead IAM 파드가 처리한다.
Cloudera Manager 로그에 AuthenticationFailureEventListener: Authentication failure for user: 'cdpadmin' 만 있고 LDAP error code · bind failed · PKIX 같은 흔적이 전혀 없다면, CM 이 LDAP 에 질의조차 안 하고 로컬 DB 로만 인증하고 있다는 뜻이다. External Authentication 이 실제로 켜져 있는지부터 본다. 로컬 admin 계정까지 같이 실패한다면 단순 암호 오류일 가능성이 가장 높다.
cdp 네임스페이스에서 로그인 흐름에 관여하는 순서다.
| 우선순위 | 파드 | 역할 |
|---|---|---|
| 1 | ...thunderhead-iam-api-* |
LDAP 바인드 · 사용자 검색을 실제로 수행. LDAP 에러가 여기 찍힌다 |
| 2 | ...thunderhead-cdp-private-authentication-console* |
로그인 화면과 인증 처리 |
| 3 | ...thunderhead-consoleauthenticationcdp-* |
콘솔 인증 게이트웨이 |
| 4 | ...thunderhead-usermanagement-private-* |
사용자 · 그룹 관리 |
| 5 | ...thunderhead-iam-console-* |
IAM 콘솔 UI |
kubectl logs -n cdp -l app.kubernetes.io/name=thunderhead-iam-api --tail=100
kubectl logs -n cdp <iam-api-pod> | grep -iE "ldap|bind|authentic|fail|denied|tls|cert" | tail -50
iam-api 파드는 컨테이너가 두 개라 애플리케이션 컨테이너를 지정해야 할 수 있다.
kubectl get pod -n cdp <iam-api-pod> -o jsonpath='{.spec.containers[*].name}{"\n"}'
kubectl logs -n cdp <iam-api-pod> -c <컨테이너명>
파드 이름 끝의 해시는 재배포마다 바뀌므로 라벨 셀렉터를 쓰는 편이 낫다. 라벨을 모르면 kubectl get pod -n cdp <pod> --show-labels 로 확인한다.
IAM API 로그를 -f 로 띄워 둔 채 실제로 한 번 로그인해서 그 순간 찍히는 메시지를 본다. 파드가 Running 이어도 인증만 실패하는 경우가 대부분이라 상태보다 로그가 핵심이지만, 비정상 여부도 같이 본다.
kubectl get pod -n cdp | grep -E "iam|authentication|usermanagement"
kubectl get events -n cdp --sort-by='.lastTimestamp' | tail -30