Jason Fehr has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24367 )

Change subject: IMPALA-15017: Add secure-cluster Helm options
......................................................................


Patch Set 47:

(4 comments)

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/README.md
File helm/impala/README.md:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/README.md@219
PS47, Line 219: ### 3) (Optional) Enable Istio sidecar injection
If Istio is enabled, will the externally facing hs2 and debug webserver ports 
automatically be TLS encrypted?  If so, external clients will see a different 
TLS certificate than the one set up in `security.tls.secretName`.  Usually, 
Istio and 'security.tls.secretName' would be mutually exclusive (either one or 
the other but not both would be set up).


http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/catalogd-deployment.yaml
File helm/impala/templates/catalogd-deployment.yaml:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/catalogd-deployment.yaml@91
PS47, Line 91: {{- if .Values.security.tls.enabled }}
             :             - -ssl_server_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
             :             - -ssl_private_key={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
             : {{- if .Values.security.tls.clientCaFileName }}
             :             - -ssl_client_ca_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.clientCaFileName }}
             : {{- end }}
These flags cover the beeswax/hs2 servers but do not cover the debug http 
webserver.  That server uses '-webserver_certificate_file' and 
`-webserver_private_key_file` flags.


http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/impalad-deployment.yaml
File helm/impala/templates/impalad-deployment.yaml:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/impalad-deployment.yaml@122
PS47, Line 122: {{- if .Values.security.tls.enabled }}
              :             - -ssl_server_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
              :             - -ssl_private_key={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
              : {{- if .Values.security.tls.clientCaFileName }}
              :             - -ssl_client_ca_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.clientCaFileName }}
              : {{- end }}
              : {{- end }}
These flags cover the beeswax/hs2 servers but do not cover the debug http 
webserver.  That server uses '-webserver_certificate_file' and 
`-webserver_private_key_file` flags.


http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/statestored-deployment.yaml
File helm/impala/templates/statestored-deployment.yaml:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/statestored-deployment.yaml@79
PS47, Line 79: {{- if .Values.security.tls.enabled }}
             :             - -ssl_server_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
             :             - -ssl_private_key={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
             : {{- if .Values.security.tls.clientCaFileName }}
             :             - -ssl_client_ca_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.clientCaFileName }}
             : {{- end }}
             : {{- end }}
These flags cover the beeswax/hs2 servers but do not cover the debug http 
webserver.  That server uses '-webserver_certificate_file' and 
`-webserver_private_key_file` flags.



--
To view, visit http://gerrit.cloudera.org:8080/24367
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I02e4c4b466424a938151bd69b28bf99ae405fae7
Gerrit-Change-Number: 24367
Gerrit-PatchSet: 47
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Comment-Date: Tue, 04 Aug 2026 17:46:06 +0000
Gerrit-HasComments: Yes

Reply via email to