link3280 opened a new pull request #7895: [FLINK-11126][YARN][security] Filter 
out AMRMToken in TaskManager‘s credentials
URL: https://github.com/apache/flink/pull/7895
 
 
   ## What is the purpose of the change
   
   Currently, Flink JobManager propagates its storage tokens to TaskManager to 
meet the requirement of YARN log aggregation (see FLINK-6376). But in this way 
the AMRMToken is also included in the TaskManager credentials, which could be 
potentially insecure.
   
   The PR filters out AMRMToken before setting the tokens to TaskManager's 
container launch context, and adds checks for delegation tokens that JobManager 
prepares for TaskManagers.
   
   ## Brief change log
   
     - Filter out AMRMToken before setting the tokens to the TaskManager 
container context.
   
   ## Verifying this change
   
   This change added tests and can be verified as follows:
   
     - Added a unit test to check delegation tokens in the TaskManager executor 
context.
   
   ## Does this pull request potentially affect one of the following parts:
   
     - Dependencies (does it add or upgrade a dependency):  no
     - The public API, i.e., is any changed class annotated with 
`@Public(Evolving)`: no
     - The serializers: no
     - The runtime per-record code paths (performance sensitive): no
     - Anything that affects deployment or recovery: JobManager (and its 
components), Checkpointing, Yarn/Mesos, ZooKeeper: yes
     - The S3 file system connector: no
   
   ## Documentation
   
     - Does this pull request introduce a new feature? no
     - If yes, how is the feature documented? (not applicable / docs / JavaDocs 
/ not documented)
   

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


With regards,
Apache Git Services

Reply via email to