CDE(Kubernetes) 에서 Spark 로 Hive 테이블에 쓰는 Job 이 드라이버 로그에 HiveMetaStoreClient: Failed to connect to the MetaStore Server · GSS initiate failed 를 내며 실패한다. Trying to connect to metastore with URI thrift://<hms-host>:9083 까지는 진행된다.
Spark 드라이버 파드(dex-app-<id> 네임스페이스)의 /etc/krb5.conf 를 호스트와 비교하니 rdns = false 는 같았지만 default_realm · [realms] · [domain_realm] 이 파드 쪽에 없었다. KDC 를 모르니 티켓 협상이 되지 않는다.
kubectl get pods -n dex-app-<id>
kubectl exec -it <driver-pod> -n dex-app-<id> -- cat /etc/krb5.conf
CDE Service 의 Kerberos 설정(KDC · realm)을 다시 확인해 파드에 주입되는 krb5.conf 를 호스트 수준으로 맞춘다. 임시로는 ConfigMap 으로 krb5.conf 를 만들어 Job 의 driver · executor 에 마운트할 수 있다.
apiVersion: v1
kind: ConfigMap
metadata:
name: krb5-config
namespace: dex-app-<id>
data:
krb5.conf: |
[libdefaults]
default_realm = EXAMPLE.COM
rdns = false
[realms]
EXAMPLE.COM = {
kdc = kdc.example.com
admin_server = kdc.example.com
}
[domain_realm]
.example.com = EXAMPLE.COM
example.com = EXAMPLE.COM
역방향 DNS(nslookup <ip>)가 다른 호스트명을 돌려주면 rdns = false 가 필요하다.
HiveServer2CredentialProvider: Failed to get HS2 delegation token · spark.sql.hive.hiveserver2.jdbc.url 경고는 HWC(Hive Warehouse Connector)를 쓰지 않는 한 무시해도 된다. spark.sql() 은 Metastore(thrift)에서 메타데이터를 읽고 HDFS 파일을 직접 읽어 Spark 엔진으로 실행하므로 HS2 가 관여하지 않는다. HS2 가 필요한 것은 HiveWarehouseSession.session(spark).build() 로 executeQuery 를 부를 때뿐이다. Metastore 연결이 된 뒤에도 Job 이 실패하면 대상 테이블 부재 등 다른 원인을 본다.