HDFS
This guide shows you how to configure HDFS for use with Pinot, including data import and deep storage.
Enable the Hadoop distributed file system (HDFS) using the pinot-hdfs plugin. In the controller or server, add the config:
-Dplugins.dir=/opt/pinot/plugins -Dplugins.include=pinot-hdfsHDFS implementation provides the following options:
hadoop.conf.path: Absolute path of the directory containing Hadoop XML configuration files, such as hdfs-site.xml, core-site.xml .hadoop.write.checksum: Create checksum while pushing an object. Default isfalsehadoop.kerberos.principlehadoop.kerberos.keytabhadoop.allow.insecure: Set totrueto access an HDFS cluster without Kerberos by installing the configured remote user as the JVM-wide Hadoop login user. Default isfalse.hadoop.user.name: Hadoop username to use whenhadoop.allow.insecureistrue.
Each of these properties should be prefixed by pinot.[node].storage.factory.class.hdfs. where node is either controller or server depending on the config
The kerberos configs should be used only if your Hadoop installation is secured with Kerberos. Refer to the Hadoop in secure mode documentation for information on how to secure Hadoop using Kerberos.
For an HDFS cluster without Kerberos, configure both insecure-access properties on the storage factory. This mode changes the global Hadoop login user for the Pinot JVM, so use it only when that process should act as one HDFS identity.
pinot.controller.storage.factory.hdfs.hadoop.allow.insecure=true
pinot.controller.storage.factory.hdfs.hadoop.user.name=pinotYou must provide proper Hadoop dependencies jars from your Hadoop installation to your Pinot startup scripts.
export HADOOP_HOME=/local/hadoop/
export HADOOP_VERSION=2.7.1
export HADOOP_GUAVA_VERSION=11.0.2
export HADOOP_GSON_VERSION=2.2.4
export CLASSPATH_PREFIX="${HADOOP_HOME}/share/hadoop/hdfs/hadoop-hdfs-${HADOOP_VERSION}.jar:${HADOOP_HOME}/share/hadoop/common/lib/hadoop-annotations-${HADOOP_VERSION}.jar:${HADOOP_HOME}/share/hadoop/common/lib/hadoop-auth-${HADOOP_VERSION}.jar:${HADOOP_HOME}/share/hadoop/common/hadoop-common-${HADOOP_VERSION}.jar:${HADOOP_HOME}/share/hadoop/common/lib/guava-${HADOOP_GUAVA_VERSION}.jar:${HADOOP_HOME}/share/hadoop/common/lib/gson-${HADOOP_GSON_VERSION}.jar"Push HDFS segment to Pinot Controller
To push HDFS segment files to Pinot controller, send the HDFS path of your newly created segment files to the Pinot Controller. The controller will download the files.
This curl example requests tells the controller to download segment files to the proper table:
Examples
Job spec
Standalone Job:
Hadoop Job:
Controller config
Server config
Minion config
HDFS as deep storage
To use HDFS as deep storage, configure each Pinot component with the HDFS plugin and the appropriate storage factory and segment fetcher properties. The sections below provide complete configuration and startup examples for each component.
Server setup
Configuration
Executable
Controller setup
Configuration
Executable
Broker setup
Configuration
Executable
Kerberos authentication
When using HDFS with Kerberos security enabled, Pinot provides two ways to authenticate:
1. Automatic authentication (recommended)
By configuring the storage.factory Kerberos properties shown above, Pinot will automatically handle Kerberos authentication using the specified keytab and principal. This eliminates the need for manual kinit commands and ensures continuous authentication even after ticket expiration.
Why these properties are required
The storage.factory Kerberos properties serve a critical purpose in Pinot's HDFS integration:
For Controller:
The controller uses
controller.data.dirto store segment metadata and other data in HDFSWhen
controller.data.dirpoints to an HDFS path (e.g.,hdfs://namenode:8020/pinot/data), the HadoopPinotFS plugin needs Kerberos credentials to access itWithout
storage.factoryKerberos properties, the controller would fail to read/write to HDFS, causing segment upload and metadata operations to failThese properties enable the HadoopPinotFS plugin to programmatically authenticate using the keytab file
For Server:
The server uses HadoopPinotFS for various HDFS operations including segment downloads and deep storage access
When servers need to access segments stored in HDFS deep storage, they require valid Kerberos credentials
The
storage.factoryproperties provide persistent authentication that survives across server restarts and ticket expirations
Understanding the two sets of Kerberos properties
You may notice two sets of Kerberos properties in the configuration:
storage.factoryproperties (recommended):pinot.controller.storage.factory.hdfs.hadoop.kerberos.principalpinot.controller.storage.factory.hdfs.hadoop.kerberos.keytabpinot.server.storage.factory.hdfs.hadoop.kerberos.principalpinot.server.storage.factory.hdfs.hadoop.kerberos.keytab
Purpose: These properties configure Kerberos authentication for the HadoopPinotFS storage factory, which handles controller and server deep storage operations and general HDFS filesystem operations through the storage factory.
Why needed: The storage factory is initialized at startup and used throughout the component's lifecycle for HDFS access. Without these properties, any HDFS operation through the storage factory would fail with authentication errors.
segment.fetcherproperties (legacy, for backward compatibility):pinot.controller.segment.fetcher.hdfs.hadoop.kerberos.principle(note: typo "principle" instead of "principal" maintained for compatibility)pinot.controller.segment.fetcher.hdfs.hadoop.kerberos.keytabpinot.server.segment.fetcher.hdfs.hadoop.kerberos.principlepinot.server.segment.fetcher.hdfs.hadoop.kerberos.keytab
Purpose: These configure Kerberos for the segment fetcher component specifically.
Why both are needed: While there is some functional overlap, having both ensures complete coverage of all HDFS access patterns, backward compatibility with existing deployments, and independent operation of the segment fetcher.
Benefits of automatic authentication
Eliminates the need to run
kinitcommands manually, reducing operational overhead and human errorKerberos tickets typically expire after 24 hours (configurable); with keytab-based authentication, Pinot automatically renews tickets internally, preventing service disruptions
Keytab files provide secure, long-term credentials without storing passwords in scripts or configuration
2. Manual authentication (legacy)
Alternatively, you can manually authenticate using kinit before starting Pinot components:
Limitations of manual authentication:
Ticket expiration: Kerberos tickets typically expire after 24 hours, requiring re-authentication
Service interruption: If tickets expire while Pinot is running, HDFS operations will fail until re-authentication
Operational burden: Requires monitoring and manual intervention, especially problematic for 24/7 production systems
Automation challenges: Difficult to integrate into automated deployment pipelines
Manual authentication is not recommended for production environments. Always use the storage.factory Kerberos properties for production deployments.
Troubleshooting
HDFS FileSystem issues
If you receive an error that says No FileSystem for scheme"hdfs", the problem is likely to be a class loading issue.
To fix, try adding the following property to core-site.xml:
fs.hdfs.impl org.apache.hadoop.hdfs.DistributedFileSystem
And then export /opt/pinot/lib/hadoop-common-<release-version>.jar in the classpath.
Kerberos authentication issues
Error: "Failed to authenticate with Kerberos"
Possible causes:
Incorrect keytab path: Ensure the keytab file path is absolute and accessible by the Pinot process
Wrong principal name: Verify the principal name matches the one in the keytab file
Keytab file permissions: The keytab file must be readable by the user running Pinot (typically
chmod 400orchmod 600)
Solution:
Error: "GSSException: No valid credentials provided"
Cause: This typically occurs when the storage.factory Kerberos properties are not set, the keytab file path is incorrect or the file doesn't exist, or the Kerberos configuration (krb5.conf) is not properly configured.
Solution:
Verify all
storage.factoryKerberos properties are correctly set in the configurationEnsure the keytab file exists and has correct permissions
Check that
/etc/krb5.conf(or$JAVA_HOME/jre/lib/security/krb5.conf) is properly configured with your Kerberos realm settings
Error: "Unable to obtain Kerberos password" or "Clock skew too great"
Cause: Time synchronization issue between Pinot server and Kerberos KDC.
Solution:
Kerberos requires clock synchronization within 5 minutes (default) between client and KDC.
Error: "HDFS operation fails after running for several hours"
Cause: This typically indicates that manual kinit was used instead of storage.factory properties, and Kerberos tickets have expired (default 24 hours).
Solution:
Configure
storage.factoryKerberos properties to enable automatic ticket renewalRemove any manual
kinitfrom startup scriptsRestart Pinot components to apply the configuration
Verifying Kerberos configuration
To verify your Kerberos setup is working correctly:
Best practices
Use absolute paths for keytab files in configuration
Secure keytab files with appropriate permissions (400 or 600)
Use service principals (e.g.,
pinot/hostname@REALM) rather than user principals for productionMonitor Kerberos ticket expiration in logs to ensure automatic renewal is working
Keep keytab files backed up in secure locations
Test configuration in a non-production environment first
Last updated
Was this helpful?

