Installing the Metering V2 Service

Learn how to install and configure the Metering V2 service to monetize API calls to Hive Metastore made by your clients.

  1. Open Cloudera Manager and open your cluster.
  2. Click Action > Add Service.
  3. Select Metering V2 in the resulting screen.
  4. In the Assign Templates step (the Select Dependencies step will already be done), click the Gateway text box and select the nodes where Hive Metastore is located. Once the hosts have been selected, click the Continue button.
    Figure 1. Role assignment for Light Duty Data Lakes
    Figure 2. Role assignment for Enterprise Duty Data Lakes
  5. In Review Changes, click Continue.
  6. The Command Details step will automatically switch to Summary if no problems are detected with the first commands.
  7. In Summary, click the Finish.
  8. Click Save Changes.
  9. Click Clusters > Metering V2 > Actions > Restart.
  10. If TLS is enabled for Metering V2 and you share data from Cloudera Object Store (powered by Apache Ozone) storage, import the Metering V2 certificate authority into the Hive Metastore JVM truststore.

    Import the Metering V2 Cloudera Manager Local Certificate Authority alias (metering-scm-ca) into the cacerts truststore used by the Hive Metastore and REST Catalog JVM on every Hive Metastore node, and restart Hive Metastore. Without this import, REST Catalog API calls fail because Hive Metastore cannot establish a trusted TLS connection to the metering endpoint.

    For example, retrieve the Metering V2 certificate, import it under the metering-scm-ca alias, and verify the import. Replace [***METERING-HOST***] with the host running the Metering V2 service, and adjust the JDK path if your cluster uses a different JVM. Inspect the certificate chain first and select the correct certificate: use c==2 for an intermediate CA or c==1 for a self-signed certificate.

    export METERING_HOST=[***METERING-HOST***]
    export JHOME=/usr/lib/jvm/jdk1.17.0.11.0-openjdk-cloudera
    
    # Inspect the chain, then pick the right cert (example: intermediate = c==2, self-signed = c==1)
    echo | openssl s_client -connect "${METERING_HOST}:50052" -showcerts 2>/dev/null \
      | awk '/BEGIN CERT/{c++} c==2,/END CERT/' > /tmp/metering.pem
    
    # Sanity check the extracted certificate
    openssl x509 -in /tmp/metering.pem -noout -subject -issuer
    
    sudo "$JHOME/bin/keytool" -importcert -noprompt \
      -alias metering-scm-ca \
      -file /tmp/metering.pem \
      -keystore "$JHOME/lib/security/cacerts" \
      -storepass changeit
    
    "$JHOME/bin/keytool" -list \
      -alias metering-scm-ca \
      -keystore "$JHOME/lib/security/cacerts" \
      -storepass changeit