要求

  • Start from Hadoop 3.3.2 -> need new docker image
  • Configure s3 policy for s3:DataAccessPointArn
statement {  
  effect = "Allow"  
  actions = [  
    "s3:PutObject*",  
    "s3:GetObject*"  
  ]  
  resources = [ "arn:aws:s3:::hulu-${var.yp_service_namespace}-${var.ads-environment}-${local.bucket_name}",  
    "arn:aws:s3:::hulu-${var.yp_service_namespace}-${var.ads-environment}-${local.bucket_name}/*"  
  ]  
  condition {  
    test     = "StringLike"  
    values   = ["arn:aws:s3:us-west-2:${local.account}:accesspoint/*"]  
    variable = "s3:DataAccessPointArn"  
  }  
}

参考资料