Installing the Knox IDBroker

Add the IDBroker role to the Knox service so that Cloudera Iceberg REST Catalog can vend temporary Ozone S3 credentials to external clients.

In Cloudera on cloud environments, the Knox IDBroker is provisioned automatically. In on premises environments, you must add the IDBroker role to the Knox service manually before you can configure it for Ozone S3 credential vending.

  1. Login to Cloudera Manager as Administrator.
  2. Go Clusters > KNOX-1, then select the Instances tab.
  3. Add the IDBroker role to the Knox service.

    Click Add Role Instances, and assign the IDBroker role to the host running Knox. Continue through the wizard.

    Figure 1. Assigning the IDBroker role to the Knox host
  4. On the Review Changes page, set the IDBroker master secret.
    1. Provide a value for IDBroker Master Secret (idbroker_master_secret)
      Figure 2. IDBroker master secret on the Review Changes page
    2. Click Finish.
  5. Restart all affected services from Cloudera Manager.
    Figure 3. Restarting affected services after adding IDBroker

Continue with Configuring Ozone STS for on premises Data Sharing.