[ 
https://issues.apache.org/jira/browse/SQOOP-3018?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15566087#comment-15566087
 ] 

Abraham Fine commented on SQOOP-3018:
-------------------------------------

[~jarcec] I believe that your concerns are valid for the current codebase. 

It does not seem to me that there is a good answer here. If we run the job as 
the submitting user they will have access to the logs but may be able to access 
confidential information. If we allow the connector to choose where 
impersonation happens the correct information will be hidden but the user may 
not be able to access the job logs.

What do you think [~ybraun]?

> Hadoop MapReduce job submission be done in client user UGI?
> -----------------------------------------------------------
>
>                 Key: SQOOP-3018
>                 URL: https://issues.apache.org/jira/browse/SQOOP-3018
>             Project: Sqoop
>          Issue Type: New Feature
>          Components: connectors/hdfs
>    Affects Versions: 1.99.7
>            Reporter: Yan Braun
>
> Hdfs Connector read and write to HDFS in client user UGI when proxyUser is 
> enabled.  But MapReduce job submission is done using Sqoop user UGI, which 
> makes all jobs from different users run in Sqoop user's hadoop queue  instead 
> of client users' own queue.   
> This is a follow-up JIRA after our discussions with Abraham Fine on whether 
> this will be on sqoop2 road map in the near future.  Thanks.  



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to