ambari-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Robert Levas" <rle...@hortonworks.com>
Subject Review Request 36342: Ambari storm deployment fails in secure mode due to storm principal name
Date Thu, 09 Jul 2015 03:09:18 GMT

-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/36342/
-----------------------------------------------------------

Review request for Ambari, Mahadev Konar, Parth Brahmbhatt, and Sriharsha Chintalapani.


Bugs: AMBARI-12343
    https://issues.apache.org/jira/browse/AMBARI-12343


Repository: ambari


Description
-------

Storm cannot dynamically translate Kerberos principal names to local account ids using common
auth-to-local rules.  It can only strip the realm portion of the principal and use that value
as the local user id.  Because of this, automatically adding the cluster name to the principal
name of the Storm user Kerberos Identity will lead to issues for Storm.  Therefore the default
behavior for generating the Storm user's Kerberos should be to use the storm-env/storm_user
value.


Diffs
-----

  ambari-server/src/main/resources/common-services/STORM/0.9.1.2.1/kerberos.json 0f38600 
  ambari-web/app/assets/data/stacks/HDP-2.1/service_components.json ed8d624 

Diff: https://reviews.apache.org/r/36342/diff/


Testing
-------

Manually tested

#Local test results:
[INFO] ------------------------------------------------------------------------
[INFO] BUILD SUCCESS
[INFO] ------------------------------------------------------------------------
[INFO] Total time: 48:24.443s
[INFO] Finished at: Wed Jul 08 22:48:15 EDT 2015
[INFO] Final Memory: 66M/1651M
[INFO] ------------------------------------------------------------------------

#Jenkins test results: PENDING


Thanks,

Robert Levas


Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message