This message was deleted.
# troubleshooting
s
This message was deleted.
s
Works on my machine 😄 :
How is your cluster deployed, do the MMs have access to the internet?
f
yep, they should have. Is there something on the user management that I should do? I see that the 403 is being returned by the Imply API
by the
/druid/v2/sql/task
endpoint
s
Next stop would be the overlord log and the MM log to see where that error is showing up.
f
I don’t really see an error, the 403 seems to be coming from the endpoint, like I don’t have permission to use EXTERN
I just checked and the roles accept a
EXTERNAL
clause that one can set, and I added it to all roles. Still, the same 403
there’s seems to be a cache on that, so maybe it is a cache issue now
s
could be. Restart? How are you issuing the request?
f
I’m sending the request through the console, on the query tab. Checking the network tab using the developer tools I see that the request that is issued to the
/druid/v2/sql/task
endpoint is returning the 403. It’s been a while since I added the
EXTERNAL
clause to all roless and it is still not working (the default cache life is 1 minute, so it looks like it isn’t a cache issue after all)
s
hmmm... so you've configured authentication right? I haven't done this myself, so I'm not familiar with how it is setup for the UI... I'll look into it.
g
Does it work OK without
EXTERN
? (You can try using a different already-existing datasource as input)
If so then it is likely permission related & I'd double-check the roles and perms
l
Can you share the role of the user that is trying to run the query as well as the permissions associated with it? The role should have READ permission on the EXTERNAL data source.
f
it works fine without
EXTERN
, yep. It looks like it is definitely permission related, but I don’t really know what to check and what to change. Regarding roles and users, I added
READ
on
EXTERNAL
to all roles, and it still doesn’t work. I’m using the druid console to launch the query and I’m not really sure how to check the user executing the request, I don’t see an authorization header, just a cookie being used (I just know it is supposed to be an ADMIN, and the role has the permission).
g
hmm; if you enable request logging, the
identity
will be logged, that'll give you some info on which user is running the query
f
I was able to curl it successfully, using a created user. The problem is only present on the imply console
l
Were you able to make the request and submit the job successfully using cURL and unable to do the same using the console? If so, can you share the network request that gets made by using the browser console?
f
yep, that’s exactly the case. I’m not able to understand which user is performing the request on the console. What of the request do you want for me to share?
g
Ah — we should provide an API for users to get their own usernames!
I feel that looking at the
identity
on the Broker logs is your best bet for getting to the bottom of this. It seems likely that the console user is different from the curl user, and the console user doesn't have the relevant permissions. You mentioned Imply, also: if you're an Imply customer you can file a support case and we can help you figure out what is going on in your specific environment