charlesconnell opened a new pull request, #8803:
URL: https://github.com/apache/hadoop/pull/8803

   ### Description of PR
   
   GetJournalEditServlet contains special authorization logic beyond all the 
stuff in the HTTP stack. It checks to see if the requester has the principal 
matching the value of `dfs.namenode.kerberos.principal` or 
`dfs.secondary.namenode.kerberos.principal`. If one has two NameNodes in their 
cluster, one could just supply their two names in those fields. Unfortunately, 
providing a value for `dfs.namenode.kerberos.principal` also triggers 
`ServiceAuthorizationManager` to check whether every request expected to come 
from a NameNode is coming from that value. Since we have two NameNodes, we 
cannot supply a value for `dfs.namenode.kerberos.principal` that will match 
them both. Reverse DNS lookups are another way to validate the requester here, 
but many network setups do not support that.
   
   This PR gives users a way out of this situation. Omit 
`dfs.namenode.kerberos.principal` from your JournalNode configuration so that 
`ServiceAuthorizationManager` no-ops, but supply 
`dfs.namenode.kerberos.principal.pattern` so that `GetJournalEditServlet` can 
use it for validation.
   
   ### How was this patch tested?
   
   This patch has been running inside HubSpot for several years
   
   ### For code changes:
   
   - [x] Does the title of this PR start with the corresponding JIRA issue id 
(e.g. 'HADOOP-17799. Your PR title ...')?
   - [ ] Object storage: Have the integration tests been executed and the 
endpoint
         declared according to the connector-specific documentation? *Note: 
Automated CI
         testing doesn't cover all cases so manual testing with cloud storage 
is still
         required.*
   - [ ] If adding new dependencies to the code, are these dependencies 
licensed in a way that is compatible for inclusion under [ASF 
2.0](http://www.apache.org/legal/resolved.html#category-a)?
   - [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`, 
`NOTICE-binary` files?
   
   ### AI Tooling
   
   No AI tooling was used


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to