apache/iceberg · warning

Failed to get Hadoop user

Error message

Failed to get Hadoop user

What it means

HiveHadoopUtil.currentUser resolves the Hadoop user via UserGroupInformation.getCurrentUser(). If Hadoop's UGI initialization fails (IOException), the library logs this warning and falls through to alternate resolution (user.name system property). It is a degradation, not a thrown error.

Solutions

  1. Ensure Hadoop configuration (core-site.xml / hdfs-site.xml) is on the classpath so UGI initializes
  2. Set the 'user.name' system property so the fallback returns a sensible identity
  3. Call UserGroupInformation.setConfiguration(conf) and/or ugi.loginUserFromKeytab before catalog operations
  4. If Kerberos, verify keytab/principal settings and that the login succeeds

Example fix

// before
String user = HiveHadoopUtil.currentUser(); // null-ish / warns
// after
UserGroupInformation.setConfiguration(new Configuration());
UserGroupInformation.loginUserFromKeytab(principal, keytabPath);
String user = HiveHadoopUtil.currentUser();
Defensive patterns

Strategy: fallback

Validate before calling

try { UserGroupInformation.getCurrentUser(); } catch (IOException e) { /* UGI not usable — initialize before catalog use */ }

Try / catch

try { UserGroupInformation.getCurrentUser().getShortUserName(); } catch (IOException e) { UserGroupInformation.setConfiguration(new Configuration()); /* retry */ }

Prevention

When it happens

Trigger: Calling code that relies on HiveHadoopUtil.currentUser() (e.g. HiveTableOperations for ownership/lock metadata) when UserGroupInformation cannot determine the current user — UGI not initialized, no Kerberos/login context, or Hadoop config missing.

Common situations: Running outside a Hadoop-configured environment (no core-site.xml on classpath); using the hive-metastore catalog from a non-Hadoop runtime; missing hadoop-auth setup in containers.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/7c1e484404af65c6. Report an issue: GitHub.

Appendix: source

Thrown at hive-metastore/src/main/java/org/apache/iceberg/hive/HiveHadoopUtil.java:37

package org.apache.iceberg.hive;

import java.io.IOException;
import org.apache.hadoop.security.UserGroupInformation;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

public class HiveHadoopUtil {

  private static final Logger LOG = LoggerFactory.getLogger(HiveHadoopUtil.class);

  private HiveHadoopUtil() {}

  public static String currentUser() {
    String username = null;
    try {
      username = UserGroupInformation.getCurrentUser().getShortUserName();
    } catch (IOException e) {
      LOG.warn("Failed to get Hadoop user", e);
    }

    if (username != null) {
      return username;
    } else {
      LOG.warn("Hadoop user is null, defaulting to user.name");
      return System.getProperty("user.name");
    }
  }
}

View on GitHub (pinned to 86d9c8fc54)