spark-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Apache Spark (JIRA)" <>
Subject [jira] [Commented] (SPARK-25825) Kerberos Support for Long Running Jobs in Kubernetes
Date Wed, 31 Oct 2018 21:00:00 GMT


Apache Spark commented on SPARK-25825:

User 'ifilonenko' has created a pull request for this issue:

> Kerberos Support for Long Running Jobs in Kubernetes 
> -----------------------------------------------------
>                 Key: SPARK-25825
>                 URL:
>             Project: Spark
>          Issue Type: New Feature
>          Components: Kubernetes
>    Affects Versions: 3.0.0
>            Reporter: Ilan Filonenko
>            Priority: Major
> When provided with a --keytab and --principal combination, there is an expectation that
Kubernetes would leverage the Driver to spin up a renewal thread to handle token renewal.
However, in the case that a --keytab and --principal are not provided and instead a secretName
and secretItemKey is provided, there should be an option to specify a config that specifies
that a external renewal service exists. The driver should, therefore, be responsible for discovering
changes to the secret and send the updated token data to the executor with the UpdateDelegationTokens
message. Thereby enabling token renewal given just a secret in addition to the traditional
use-case via --keytab and --principal

This message was sent by Atlassian JIRA

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message