-
Notifications
You must be signed in to change notification settings - Fork 29k
[branch-1.5][SPARK-11821] Propagate Kerberos keytab for all environments #9837
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Can one of the admins verify this patch? |
… case of Kerberos mode
|
I also see, that a change of authentication method from a simple to a kerberos was required while renewing credentials. I've made a commit. |
|
@woj-i please open the patch against the master branch instead. Committers will backport it into branch-1.5 when they merge it. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This seems wrong. If you are talking to hadoop cluster that is secure, your client configuration should already have this. Setting this here alone is not going to help, since all other instances used all over Spark will not have this information (where required).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi!
I think it is required because of another context of execution in this part of code. Here is a context of the classloader, which cause an empty environment, with default value of authentication, which is "simple". In case of "simple" a keytab is not used and credentials cannot be granted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ah, ok. Did you hit this issue when running an app?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, I did.
|
@woj-i would you mind tagging this one as |
|
Title changed. |
|
I made comments on #9859. |
|
@woj-i could you close this PR? |
I prepared a patch for recent bugfix. The scope of the previous bugfix is too narrow- it works only on YARN. I need it on local mode and I think the other modes also need the information (because reflection works the same for each environment having JVM).