charlesconnell opened a new pull request, #8803:
URL: https://github.com/apache/hadoop/pull/8803
### Description of PR
GetJournalEditServlet contains special authorization logic beyond all the
stuff in the HTTP stack. It checks to see if the requester has the principal
matching the value of `dfs.namenode.kerberos.principal` or
`dfs.secondary.namenode.kerberos.principal`. If one has two NameNodes in their
cluster, one could just supply their two names in those fields. Unfortunately,
providing a value for `dfs.namenode.kerberos.principal` also triggers
`ServiceAuthorizationManager` to check whether every request expected to come
from a NameNode is coming from that value. Since we have two NameNodes, we
cannot supply a value for `dfs.namenode.kerberos.principal` that will match
them both. Reverse DNS lookups are another way to validate the requester here,
but many network setups do not support that.
This PR gives users a way out of this situation. Omit
`dfs.namenode.kerberos.principal` from your JournalNode configuration so that
`ServiceAuthorizationManager` no-ops, but supply
`dfs.namenode.kerberos.principal.pattern` so that `GetJournalEditServlet` can
use it for validation.
### How was this patch tested?
This patch has been running inside HubSpot for several years
### For code changes:
- [x] Does the title of this PR start with the corresponding JIRA issue id
(e.g. 'HADOOP-17799. Your PR title ...')?
- [ ] Object storage: Have the integration tests been executed and the
endpoint
declared according to the connector-specific documentation? *Note:
Automated CI
testing doesn't cover all cases so manual testing with cloud storage
is still
required.*
- [ ] If adding new dependencies to the code, are these dependencies
licensed in a way that is compatible for inclusion under [ASF
2.0](http://www.apache.org/legal/resolved.html#category-a)?
- [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`,
`NOTICE-binary` files?
### AI Tooling
No AI tooling was used
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]