Uploaded image for project: 'Flink'
  1. Flink
  2. FLINK-1702

Authenticate via Kerberos from the client only

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Not A Problem
    • None
    • 1.0.0
    • Runtime / Coordination
    • None

    Description

      FLINK-1504 implemented support for Kerberos authentication for HDFS in Flink. Currently, the authentication has to be performed on every node when the job or task manager comes up. That implies that all nodes are already authenticated using Kerberos.

      For the Hadoop security mechanism it would be sufficient if the Client authenticated once using Kerberos and received the Hadoop DelegationToken. This Token could then be passed to all nodes. It would be renewed using the Hadoop security mechanisms.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              mxm Maximilian Michels
              Votes:
              1 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: