apache/iceberg · warning
Failed to get Hadoop user
Error message
Failed to get Hadoop user
What it means
HiveHadoopUtil.currentUser resolves the Hadoop user via UserGroupInformation.getCurrentUser(). If Hadoop's UGI initialization fails (IOException), the library logs this warning and falls through to alternate resolution (user.name system property). It is a degradation, not a thrown error.
Solutions
- Ensure Hadoop configuration (core-site.xml / hdfs-site.xml) is on the classpath so UGI initializes
- Set the 'user.name' system property so the fallback returns a sensible identity
- Call UserGroupInformation.setConfiguration(conf) and/or ugi.loginUserFromKeytab before catalog operations
- If Kerberos, verify keytab/principal settings and that the login succeeds
Example fix
// before String user = HiveHadoopUtil.currentUser(); // null-ish / warns // after UserGroupInformation.setConfiguration(new Configuration()); UserGroupInformation.loginUserFromKeytab(principal, keytabPath); String user = HiveHadoopUtil.currentUser();
Defensive patterns
Strategy: fallback
Validate before calling
try { UserGroupInformation.getCurrentUser(); } catch (IOException e) { /* UGI not usable — initialize before catalog use */ } Try / catch
try { UserGroupInformation.getCurrentUser().getShortUserName(); } catch (IOException e) { UserGroupInformation.setConfiguration(new Configuration()); /* retry */ } Prevention
- Initialize UserGroupInformation with Hadoop conf before catalog operations
- Login via keytab for Kerberos environments
- Set user.name system property as a safety net
When it happens
Trigger: Calling code that relies on HiveHadoopUtil.currentUser() (e.g. HiveTableOperations for ownership/lock metadata) when UserGroupInformation cannot determine the current user — UGI not initialized, no Kerberos/login context, or Hadoop config missing.
Common situations: Running outside a Hadoop-configured environment (no core-site.xml on classpath); using the hive-metastore catalog from a non-Hadoop runtime; missing hadoop-auth setup in containers.
Related errors
- Hadoop user is null, defaulting to user.name
- Cannot remove properties " + namespace + " …
- Cannot serialize a Hadoop input file: " + location()
- Cannot serialize an eager input file
- Cannot set namespace properties " + namespace + " …
AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12).
Data as JSON: /api/errors/7c1e484404af65c6.
Report an issue: GitHub.
Appendix: source
Thrown at hive-metastore/src/main/java/org/apache/iceberg/hive/HiveHadoopUtil.java:37
package org.apache.iceberg.hive;
import java.io.IOException;
import org.apache.hadoop.security.UserGroupInformation;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class HiveHadoopUtil {
private static final Logger LOG = LoggerFactory.getLogger(HiveHadoopUtil.class);
private HiveHadoopUtil() {}
public static String currentUser() {
String username = null;
try {
username = UserGroupInformation.getCurrentUser().getShortUserName();
} catch (IOException e) {
LOG.warn("Failed to get Hadoop user", e);
}
if (username != null) {
return username;
} else {
LOG.warn("Hadoop user is null, defaulting to user.name");
return System.getProperty("user.name");
}
}
}
View on GitHub (pinned to 86d9c8fc54)