Skip to main content

How to Stop New Hadoop MapReduce Jobs Using Queue ACLs

Struggling with delivery, architecture alignment, or platform stability?

I help teams fix systemic engineering issues: processes, architecture, and clarity.
→ See how I work with teams.


This article shows how to temporarily stop new Hadoop MapReduce jobs from being submitted by enabling ACLs and configuring mapred-queue-acls.xml. Existing jobs continue to run, which makes this pattern useful for maintenance windows or decommissioning work on a classic MapReduce cluster.

In a classic Hadoop MapReduce (MRv1) cluster, there are situations where you want to stop accepting new MapReduce jobs while allowing already running jobs to finish. This is especially useful during maintenance, node decommissioning or cluster reconfiguration.

One simple way to achieve this is to enable ACLs on the MapReduce job queue and then configure the submission ACL so that effectively nobody is allowed to submit new jobs.

1. Enable ACLs for MapReduce queues

First, configure queue ACLs in $HADOOP/conf/mapred-queue-acls.xml. A typical configuration might allow a set of users and groups to submit jobs and a smaller set of admins to manage them:

<configuration>
  <property>
    <name>mapred.queue.default.acl-submit-job</name>
    <value>user1,user2,group1,group2,admins</value>
  </property>

  <property>
    <name>mapred.queue.default.acl-administer-jobs</name>
    <value>admins</value>
  </property>
</configuration>

Next, enable ACL handling in the MapReduce framework by editing conf/mapred-site.xml and setting:

<property>
  <name>mapred.acls.enabled</name>
  <value>true</value>
</property>

With this in place, the MapReduce framework will enforce the ACLs defined in mapred-queue-acls.xml.

2. Temporarily block new job submissions

To block new jobs from being submitted to the default queue, you can set the submit ACL to a single space character. This is effectively an ACL that matches nobody:

<configuration>
  <property>
    <name>mapred.queue.default.acl-submit-job</name>
    <value> </value>  <!-- note: a single space -->
  </property>

  <property>
    <name>mapred.queue.default.acl-administer-jobs</name>
    <value>admins</value>
  </property>
</configuration>

Because mapred-queue-acls.xml is polled regularly by the JobTracker, these changes take effect without restarting the whole cluster. From this point on:

  • All new job submissions to the default queue are rejected due to ACLs.
  • All already running jobs continue to run until completion.

This gives operations teams a controlled way to put a cluster effectively into a “no new jobs” mode while letting current workloads drain naturally.

3. Re-enabling submissions

When maintenance is finished, simply restore the original ACLs in mapred-queue-acls.xml (for example, user1,user2,group1,group2,admins) and the cluster will start accepting new jobs again, without requiring a full restart.

Note on newer Hadoop/YARN setups

In modern YARN-based clusters with Capacity or Fair Scheduler, the same idea is implemented by adjusting queue ACLs and scheduler configuration on the ResourceManager side. The details differ, but the core pattern remains the same: restrict who can submit jobs to a queue to temporarily block new workloads while existing applications finish.

If you need help with distributed systems, backend engineering, or data platforms, check my Services.

Most read articles

Building a Model-Agnostic Multi-Agent System with OpenClaw

Over one week we rebuilt our AI stack around OpenClaw’s multi-agent architecture to avoid provider lock-in and stop wasting premium tokens. By aligning models to tasks, diversifying fallbacks across providers, enforcing minimal tool access, and switching to memory-first workflows with ephemeral sessions, we reduced token usage per task by about 70% and cut our monthly bill by 77% while improving operational resilience. How We Achieved 77% Cost Reduction and Provider Independence Over the past week, we rebuilt our AI infrastructure around OpenClaw’s multi-agent architecture. The result was a 77% cost reduction , provider independence , and a delegation system that routes work to the most cost-effective model for each job. Below is the technical journey of optimizing a 7-agent squad with OpenClaw. The Challenge: Model Provider Lock-In We started with a simple problem: our entire squad defaulted to a single model provider. This created three issues: Cost inefficiency beca...

BacNet => MQTT in Production: The Real Cost of Bridging BACnet to MQTT at Scale

bacnet2mqtt looks simple in a README and expensive in production. Once BACnet polling, reconnection behavior, stale state, and MQTT publishing collide, teams discover they are not deploying a lightweight adapter but operating infrastructure. This article breaks down where bacnet2mqtt works, where it becomes a bottleneck, and which production patterns reduce the operational damage before incidents, backlogs, and silent data loss turn a building integration into a long-running engineering problem. I inherited a building controls integration problem 18 months ago. Three office floors. 217 BACnet sensors covering temperature, occupancy, and HVAC actuators. The data was trapped inside the building automation network while the business wanted analytics, reporting, and compliance visibility in the data platform. The obvious answer looked easy enough: deploy bacnet2mqtt, bridge BACnet into MQTT, and push the stream into the lakehouse stack. The repository made it sound like a w...

Connect BACnet to the Cloud with bacnet-mqtt-gateway

The bacnet-mqtt-gateway project is an open source protocol bridge that translates BACnet building automation traffic into MQTT messages for cloud and IoT systems. It provides discovery, polling, bidirectional writes, APIs, security, and easy deployment via Docker. Many enterprises struggle to unify BACnet with modern data pipelines and cloud platforms because BACnet is local-network only and not cloud ready. This gateway provides a scalable, secure, production-ready adapter for MQTT ecosystems and smart building integrations. The Problem with BACnet Building automation runs on BACnet . HVAC controllers, lighting systems, metering equipment: they all speak ASHRAE 135 . The protocol handles local control loops well. It fails at cloud ingress. BACnet relies on UDP broadcasts. These do not route over the internet or into VPCs. Your chiller controller cannot talk to AWS IoT Core . Your VAV box cannot publish to an MQTT broker. The air gap between operational technology and modern cl...