Uploaded image for project: 'Apache Gearpump'
  1. Apache Gearpump
  2. GEARPUMP-355

AppMasterResolver fails to run against a kerberized Hadoop cluster

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 0.8.4
    • 0.8.5
    • security, yarn
    • None

    Description

      When trying to launch a Gearpump cluster in a kerberized Hadoop/Yarn environment, after the Application Master address has been resolved as a prerequisite, the YarnAppMaster (responsible for starting GearPump masters, workers, UI servers as Yarn containers) address (actor reference) must be obtained via Kerberos/Spnego. (Kerberos over http)
      The current implementation for this resides in the AppMasterResolver class and is using an apache http client (version 3.x) for establishing a connection to the Application Master and obtain the above YarnAppMaster actor reference. Since the apache http client does not support the negotiate authentication scheme in version 3.x (required for a connection over kerberos/spnego) this step will always fail in a kerberized Yarn/Hadoop cluster set-up.
      I tested this in a secured/kerberized CDH 5.7.5 environment. I would like to provide a patch for this by adapting the SPNEGO-enabled Hadoop web connection code from WebHDFS.

      Attachments

        Issue Links

          Activity

            People

              Timea Magyar Timea Magyar
              Timea Magyar Timea Magyar
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: