Table of Contents

Search

  1. About the Intelligent Data Lake Administrator Guide
  2. Introduction to Intelligent Data Lake Administration
  3. Administration Process
  4. User Account Setup
  5. Data Preparation Service
  6. Intelligent Data Lake Service
  7. Application Configuration
  8. Roles, Privileges, and Profiles
  9. Data Asset Access and Publication Management
  10. Monitoring Intelligent Data Lake
  11. Backing Up and Restoring Intelligent Data Lake
  12. Data Type Reference

Intelligent Data Lake Administrator Guide

Intelligent Data Lake Administrator Guide

Step 5. Set Up User Impersonation

Step 5. Set Up User Impersonation

When a user performs tasks in Intelligent Data Lake, the Data Integration Service connects to Hadoop services to access the data lake and perform the operation on behalf of the user. The Data Integration Service uses impersonation to pass the user account to Hadoop.
Configure user impersonation for Intelligent Data Lake based on the user access requirements of your organization.
You can configure user impersonation in the following ways:
Using the Intelligent Data Lake user account to connect to Hadoop services
You can configure the Data Integration Service to impersonate the user account logged in to the Intelligent Data Lake application. The user account logged in to Intelligent Data Lake must have user or group authorization to connect to the Hadoop services. To use this option, you must configure the Data Integration Service to use operating system profiles. You must assign the Intelligent Data Lake user account a default operating system profile with the
Use the logged in user as Hadoop Impersonation User
option selected.
Using an authorized user account to connect to Hadoop services
If the Intelligent Data Lake user accounts do not have logged authorization to connect Hadoop, you can configure the Data Integration Service to impersonate a specific authorized user. The impersonated user account must have authorization to connect to the data lake and the Hadoop services. To use this option, you must configure the Data Integration Service to use operating system profiles. The operating system profile must have the
Use the specified user as Hadoop Impersonation User
option selected and must specify the authorized user account to impersonate.
Using the Hive connection user account to connect to Hadoop services
If user access to the data lake does not require authorization or if all users have the same authorization, you do not need to set up operating system profiles to connect to the Hadoop services. The Data Integration Service connects to Hadoop services using the user account specified in the Hive connection object for Intelligent Data Lake.
To configure user impersonation for Intelligent Data Lake, perform the following steps:
  • Configure user impersonation in the Hadoop cluster.
  • Configure the user account in the Hive connection.