mderela
Contributor

The error isn’t actually about MongoDB. HikariCP failing on port 3306 via DataNucleus is your Hive Metastore losing its SSL connection to MySQL on the driver.
Setting javax.net.ssl.keyStore globally in extraJavaOptions overwrites the default JVM truststore for every SSL connection on the driver, including the Metastore. The RDS certificate is no longer trusted because your keystore only contains the X.509 key for MongoDB, not the CA for RDS.
One approach worth trying: instead of replacing the truststore, extend it in your init script by importing the MongoDB cert into the existing JVM cacerts rather than pointing to a separate keystore file:


keytool -importcert -keystore $JAVA_HOME/lib/security/cacerts -storepass changeit -alias mongo-atlas -file /tmp/mongo.crt -noprompt


That way the default truststore stays intact for Metastore and everything else, and MongoDB gets its cert alongside it.

as soon as you confirmed that it is working - we can try to deep dive to find the root cause of the issue.