Jason Fehr has posted comments on this change. ( http://gerrit.cloudera.org:8080/24367 )
Change subject: IMPALA-15017: Add secure-cluster Helm options ...................................................................... Patch Set 47: (4 comments) http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/README.md File helm/impala/README.md: http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/README.md@219 PS47, Line 219: ### 3) (Optional) Enable Istio sidecar injection If Istio is enabled, will the externally facing hs2 and debug webserver ports automatically be TLS encrypted? If so, external clients will see a different TLS certificate than the one set up in `security.tls.secretName`. Usually, Istio and 'security.tls.secretName' would be mutually exclusive (either one or the other but not both would be set up). http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/catalogd-deployment.yaml File helm/impala/templates/catalogd-deployment.yaml: http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/catalogd-deployment.yaml@91 PS47, Line 91: {{- if .Values.security.tls.enabled }} : - -ssl_server_certificate={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.certFileName }} : - -ssl_private_key={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.keyFileName }} : {{- if .Values.security.tls.clientCaFileName }} : - -ssl_client_ca_certificate={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.clientCaFileName }} : {{- end }} These flags cover the beeswax/hs2 servers but do not cover the debug http webserver. That server uses '-webserver_certificate_file' and `-webserver_private_key_file` flags. http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/impalad-deployment.yaml File helm/impala/templates/impalad-deployment.yaml: http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/impalad-deployment.yaml@122 PS47, Line 122: {{- if .Values.security.tls.enabled }} : - -ssl_server_certificate={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.certFileName }} : - -ssl_private_key={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.keyFileName }} : {{- if .Values.security.tls.clientCaFileName }} : - -ssl_client_ca_certificate={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.clientCaFileName }} : {{- end }} : {{- end }} These flags cover the beeswax/hs2 servers but do not cover the debug http webserver. That server uses '-webserver_certificate_file' and `-webserver_private_key_file` flags. http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/statestored-deployment.yaml File helm/impala/templates/statestored-deployment.yaml: http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/statestored-deployment.yaml@79 PS47, Line 79: {{- if .Values.security.tls.enabled }} : - -ssl_server_certificate={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.certFileName }} : - -ssl_private_key={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.keyFileName }} : {{- if .Values.security.tls.clientCaFileName }} : - -ssl_client_ca_certificate={{ printf "%s/%s" .Values.security.tls.mountPath .Values.security.tls.clientCaFileName }} : {{- end }} : {{- end }} These flags cover the beeswax/hs2 servers but do not cover the debug http webserver. That server uses '-webserver_certificate_file' and `-webserver_private_key_file` flags. -- To view, visit http://gerrit.cloudera.org:8080/24367 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I02e4c4b466424a938151bd69b28bf99ae405fae7 Gerrit-Change-Number: 24367 Gerrit-PatchSet: 47 Gerrit-Owner: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Abhishek Rawat <[email protected]> Gerrit-Reviewer: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Gokul Kolady <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Jason Fehr <[email protected]> Gerrit-Comment-Date: Tue, 04 Aug 2026 17:46:06 +0000 Gerrit-HasComments: Yes
