spark-reviews mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From ifilonenko <...@git.apache.org>
Subject [GitHub] spark pull request #21669: [SPARK-23257][K8S] Kerberos Support for Spark on ...
Date Thu, 27 Sep 2018 01:26:21 GMT
Github user ifilonenko commented on a diff in the pull request:

    https://github.com/apache/spark/pull/21669#discussion_r220770479
  
    --- Diff: docs/security.md ---
    @@ -722,6 +722,62 @@ with encryption, at least.
     The Kerberos login will be periodically renewed using the provided credentials, and new
delegation
     tokens for supported will be created.
     
    +## Secure Interaction with Kubernetes
    +
    +When talking to Hadoop-based services behind Kerberos, it was noted that Spark needs
to obtain delegation tokens
    +so that non-local processes can authenticate. These delegation tokens in Kubernetes are
stored in Secrets that are 
    +shared by the Driver and its Executors. As such, there are three ways of submitting a
kerberos job: 
    +
    --- End diff --
    
    Thank you for these comments. Done!


---

---------------------------------------------------------------------
To unsubscribe, e-mail: reviews-unsubscribe@spark.apache.org
For additional commands, e-mail: reviews-help@spark.apache.org


Mime
View raw message