Description
RM, NM, job history, and application master httpservers are not created with access Control lists. I believe this means that anyone can access any of the standard servlets that check to see if the user has administrator access - like /jmx, /stacks, etc and ops has no way to restrict access to these things.
Attachments
Attachments
Issue Links
- is blocked by
-
MAPREDUCE-3104 Implement Application ACLs, Queue ACLs and their interaction
- Closed
-
HADOOP-7764 Allow both ACL list and global path spec filters to HttpServer
- Closed