java.lang.RuntimeException: Failed to connect to timeline server.
Connection retries limit exceeded. The posted timeline event may be missing
at org.apache.hadoop.yarn.client.api.impl.TimelineConnector$TimelineClientConnectionRetry.retryOn
또는 TLS 단계에서 끊긴다.
com.sun.jersey.api.client.ClientHandlerException: javax.net.ssl.SSLHandshakeException:
DestHost:destPort timelinehost:8190 ... Received fatal alert: handshake_failure
애플리케이션의 실행 이력과 메타데이터를 모아 두는 서비스다. 여기에 이벤트를 올리지 못해도 잡 자체는 대체로 계속 돌아간다. 이력 조회가 안 되고 로그에 재시도 메시지가 쌓인다. 다만 이벤트 전송 재시도로 클라이언트가 느려지는 경우가 있으므로 방치하지 않는다.
서비스가 살아 있는지, 포트가 열려 있는지부터 본다.
ps -ef | grep -i timeline
ss -lntp | grep -E '8188|8190'
curl -s http://timelinehost:8188/ws/v1/timeline/ | head
curl -sk https://timelinehost:8190/ws/v1/timeline/ | head
기동은 다음과 같다. 서비스로 관리되는 환경에서는 관리 도구를 쓴다.
sudo -u yarn yarn --daemon start timelineserver
yarn-site.xml 에서 정책과 주소, 키스토어를 지정한다.
| 키 | 뜻 |
|---|---|
yarn.timeline-service.http-policy |
HTTP_ONLY · HTTPS_ONLY |
yarn.timeline-service.webapp.address |
HTTP 주소. 기본 포트 8188 |
yarn.timeline-service.webapp.https.address |
HTTPS 주소. 기본 포트 8190 |
키스토어와 트러스트스토어는 대개 ssl-server.xml 과 ssl-client.xml 에서 관리한다. Hadoop 은 이 두 파일의 ssl.server.keystore.location, ssl.client.truststore.location 등을 공통으로 사용한다.
handshake_failure 는 대부분 다음 중 하나다. 클라이언트가 서버 인증서의 발급자를 신뢰하지 않거나, 양쪽이 공통으로 쓸 수 있는 프로토콜 버전 또는 암호 스위트가 없거나, 인증서가 만료됐거나 호스트명이 맞지 않는 경우다.
openssl s_client -connect timelinehost:8190 -servername timelinehost </dev/null 2>/dev/null \
| openssl x509 -noout -subject -issuer -dates
keytool -list -v -keystore /etc/security/truststore.jks -storepass ${TRUSTSTORE_PASSWORD} \
| grep -E 'Alias|Owner|Valid'
클라이언트의 트러스트스토어에 서버 인증서의 CA 가 들어 있는지 확인하고, 없으면 추가한다. 자체 서명 인증서를 쓰는 환경에서는 CA 인증서를 모든 노드의 트러스트스토어에 배포해야 한다.
이력 수집이 급하지 않다면 클라이언트에서 Timeline 사용을 끄고 잡을 먼저 돌린다.
yarn jar ... -Dyarn.timeline-service.enabled=false
Hive on Tez 환경에서 쿼리 지연의 원인이 Timeline Server 일 때도 같은 방법으로 먼저 분리해 확인한다.