Amazon S3
Amazon S3
Amazon S3에 저장된 파일에서 데이터를 가져오는 방법을 보여 주는 가이드예요.
출처: Amazon S3
본문
pinot-s3 플러그인을 포함해 Amazon S3 파일시스템 백엔드를 활성화하세요. 컨트롤러나 서버 구성에 다음을 추가해요:
-Dplugins.dir=/opt/pinot/plugins -Dplugins.include=pinot-s3
S3A URI 스킴 지원
Pinot 1.3.0부터 pinot-s3 플러그인은 s3://와 s3a:// 두 URI 스킴을 모두 지원해요. 두 스킴 모두 동일한 AWS SDK v2 클라이언트와 동일한 구성을 사용하며, 차이는 URI 접두사뿐이에요. 이를 통해 Pinot이 s3a:// 스킴을 표준으로 쓰는 Hadoop 기반 에코시스템과 통합될 수 있어요.
s3a:// 스킴을 사용하려면 딥 스토어 경로와 파일시스템 구성에 지정하세요:
controller.data.dir=s3a://path/to/data/directory/
pinot.controller.storage.factory.class.s3a=org.apache.pinot.plugin.filesystem.S3PinotFS
pinot.controller.storage.factory.s3a.region=us-east-1
pinot.controller.segment.fetcher.protocols=file,http,s3a
pinot.controller.segment.fetcher.s3a.class=org.apache.pinot.common.utils.fetcher.PinotFSSegmentFetcher
아래 문서화된 모든 구성 속성은 s3와 s3a 두 스킴 모두에 동일하게 동작해요.
참고 기본적으로 Pinot은 모든 플러그인을 로드하므로 플러그인을 그냥 놓기만 하면 돼요. 또한
-Dplugins.include를 지정하면 사용할 모든 플러그인을 넣어야 해요. 예:pinot-json,pinot-avro,pinot-kafka-3.0...
S3 파일시스템은 다음 옵션으로 구성할 수 있어요:
| Configuration | Description |
|---|---|
| region | 버킷이 있는 AWS 데이터 센터 리전 |
| accessKey | (선택) 인증에 필요한 AWS 액세스 키. 이 키는 secret에 저장하지 않으므로 테스트 목적으로만 사용해야 해요. |
| secretKey | (선택) 인증에 필요한 AWS 시크릿 키. 테스트 목적으로만 사용하세요. |
| endpoint | (선택) s3 클라이언트의 엔드포인트 재정의. |
| disableAcl | false로 설정하면 버킷 소유자에게 pinot이 생성한 객체에 대한 전체 액세스 권한이 부여돼요. 기본값은 true. |
| serverSideEncryption | (선택) Amazon S3에 객체를 저장할 때 사용하는 서버측 암호화 알고리즘(현재 aws:kms 지원). SSE를 비활성화하려면 null로 설정. |
| ssekmsKeyId | (선택, 단 serverSideEncryption=aws:kms일 때 필수) 객체 암호화에 사용할 AWS KMS 키 ID를 지정. AWS KMS로 보호된 객체에 대한 모든 GET·PUT 요청은 SSL 또는 SigV4로 수행되지 않으면 실패. |
| ssekmsEncryptionContext | (선택) 객체 암호화에 사용할 AWS KMS 암호화 컨텍스트 지정. 이 헤더 값은 암호화 컨텍스트 키-값 쌍을 담은 JSON을 보관하는 base64 인코딩 UTF-8 문자열. |
| requestChecksumCalculation | (선택) S3 요청에 대한 AWS SDK 체크섬 모드 제어. 기본값: WHEN_REQUIRED. 옵션: WHEN_SUPPORTED, WHEN_REQUIRED. |
| responseChecksumValidation | (선택) S3 응답에 대한 AWS SDK 체크섬 모드 제어. 기본값: WHEN_REQUIRED. 옵션: WHEN_SUPPORTED, WHEN_REQUIRED. |
| useLegacyMd5Plugin | (선택) true로 설정하면 LegacyMd5Plugin을 사용해 2.30.0 이전의 MD5 체크섬 동작을 복원. 기본값: false. |
| enableCrossRegionAccess | (선택) 서로 다른 리전에 있는 두 버킷 간 객체를 복사하려면 사용. 미설정 시 기본값은 true. |
이 속성들은 각각 구성에 따라 pinot.[node].storage.factory.s3. 접두사가 붙어야 하는데, node는 controller 또는 server예요.
예:
pinot.controller.storage.factory.s3.region=ap-southeast-1
S3 파일시스템은 DefaultCredentialsProviderChain을 이용한 인증을 지원해요. 자격증명 제공자는 다음 순서로 자격증명을 찾아요:
- 환경 변수 -
AWS_ACCESS_KEY_ID와AWS_SECRET_ACCESS_KEY(.NET을 제외한 모든 AWS SDK와 CLI가 인식하므로 권장), 또는AWS_ACCESS_KEY와AWS_SECRET_KEY(Java SDK만 인식) - Java 시스템 속성 -
aws.accessKeyId와aws.secretKey - 환경 또는 컨테이너의 Web Identity Token 자격증명
- 모든 AWS SDK와 AWS CLI가 공유하는 기본 위치
(~/.aws/credentials)의 자격증명 프로필 파일 AWS_CONTAINER_CREDENTIALS_RELATIVE_URI환경 변수가 설정되고 보안 관리자가 변수 접근을 허용하면 Amazon EC2 컨테이너 서비스로 전달되는 자격증명- Amazon EC2 메타데이터 서비스로 전달되는 인스턴스 프로필 자격증명
accessKey와 secretKey를 속성으로 지정할 수도 있어요. 하지만 이 방식은 안전하지 않으므로 POC 구성에서만 사용해야 해요.
체크섬 검증
참고 체크섬 구성은 Pinot 1.4부터 사용할 수 있어요.
AWS SDK 2.30.0부터 S3 클라이언트는 요청·응답 체크섬 검증을 기본으로 활성화해요. Pinot은 이 동작을 제어하는 구성 속성을 노출해요.
요청 및 응답 체크섬
기본적으로 Pinot은 requestChecksumCalculation과 responseChecksumValidation을 모두 WHEN_REQUIRED로 설정해요. 이는 S3 API가 체크섬 계산·검증을 명시적으로 요구하지 않는 한, Pinot이 AWS SDK의 필수 전용 체크섬 경로를 유지하게 해요.
API가 지원할 때마다 S3 클라이언트가 체크섬을 계산·검증하게 하려면 두 속성을 모두 WHEN_SUPPORTED로 설정하세요:
pinot.controller.storage.factory.s3.requestChecksumCalculation=WHEN_SUPPORTED
pinot.controller.storage.factory.s3.responseChecksumValidation=WHEN_SUPPORTED
| Value | Behavior |
|---|---|
| WHEN_REQUIRED | S3 API가 요구할 때만 체크섬 계산·검증 사용 (기본값) |
| WHEN_SUPPORTED | S3 API가 지원할 때마다 체크섬 계산·검증 사용 |
S3 호환 스토어용 LegacyMd5Plugin
일부 S3 호환 객체 스토어(예: MinIO, Ceph, 또는 구형 AWS 구성)는 요청에 레거시 Content-MD5 헤더를 요구해요. AWS SDK 2.30.0 업그레이드 후 이런 스토어는 다음 같은 오류를 반환할 수 있어요:
Missing required content hash for this request: Content-MD5 or x-amz-content-sha256
2.30.0 이전의 MD5 체크섬 동작을 복원하려면 useLegacyMd5Plugin 옵션을 활성화하세요:
pinot.controller.storage.factory.s3.useLegacyMd5Plugin=true
이렇게 하면 S3 클라이언트에 LegacyMd5Plugin이 추가되어 이 스토어들이 기대하는 Content-MD5 헤더를 보내요.
경고
useLegacyMd5Plugin은 S3 호환 스토어가 레거시 MD5 헤더를 요구할 때만 활성화하세요. 표준 AWS S3에서는 기본 체크섬 동작이 권장돼요.
예제
잡 스펙
executionFrameworkSpec:
name: 'standalone'
segmentGenerationJobRunnerClassName: 'org.apache.pinot.plugin.ingestion.batch.standalone.SegmentGenerationJobRunner'
segmentTarPushJobRunnerClassName: 'org.apache.pinot.plugin.ingestion.batch.standalone.SegmentTarPushJobRunner'
segmentUriPushJobRunnerClassName: 'org.apache.pinot.plugin.ingestion.batch.standalone.SegmentUriPushJobRunner'
jobType: SegmentCreationAndTarPush
inputDirURI: 's3://pinot-bucket/pinot-ingestion/batch-input/'
outputDirURI: 's3://pinot-bucket/pinot-ingestion/batch-output/'
overwriteOutput: true
pinotFSSpecs:
- scheme: s3
className: org.apache.pinot.plugin.filesystem.S3PinotFS
configs:
region: 'ap-southeast-1'
recordReaderSpec:
dataFormat: 'csv'
className: 'org.apache.pinot.plugin.inputformat.csv.CSVRecordReader'
configClassName: 'org.apache.pinot.plugin.inputformat.csv.CSVRecordReaderConfig'
tableSpec:
tableName: 'students'
pinotClusterSpecs:
- controllerURI: 'http://localhost:9000'
컨트롤러 구성
controller.data.dir=s3://path/to/data/directory/
controller.local.temp.dir=/path/to/local/temp/directory
controller.enable.split.commit=true
pinot.controller.storage.factory.class.s3=org.apache.pinot.plugin.filesystem.S3PinotFS
pinot.controller.storage.factory.s3.region=ap-southeast-1
pinot.controller.segment.fetcher.protocols=file,http,s3
pinot.controller.segment.fetcher.s3.class=org.apache.pinot.common.utils.fetcher.PinotFSSegmentFetcher
서버 구성
pinot.server.instance.enable.split.commit=true
pinot.server.storage.factory.class.s3=org.apache.pinot.plugin.filesystem.S3PinotFS
pinot.server.storage.factory.s3.region=ap-southeast-1
pinot.server.storage.factory.s3.httpclient.maxConnections=50
pinot.server.storage.factory.s3.httpclient.socketTimeout=30s
pinot.server.storage.factory.s3.httpclient.connectionTimeout=2s
pinot.server.storage.factory.s3.httpclient.connectionTimeToLive=0s
pinot.server.storage.factory.s3.httpclient.connectionAcquisitionTimeout=10s
pinot.server.segment.fetcher.protocols=file,http,s3
pinot.server.segment.fetcher.s3.class=org.apache.pinot.common.utils.fetcher.PinotFSSegmentFetcher
Minion 구성
pinot.minion.storage.factory.class.s3=org.apache.pinot.plugin.filesystem.S3PinotFS
pinot.minion.storage.factory.s3.region=ap-southeast-1
pinot.minion.segment.fetcher.protocols=file,http,s3
pinot.minion.segment.fetcher.s3.class=org.apache.pinot.common.utils.fetcher.PinotFSSegmentFetcher