-1 (binding).

Ui2 does not seem to support same origin policy for cross site scripting 
prevention.
The following parameters has no effect for /ui2:

hadoop.http.cross-origin.enabled = true
yarn.resourcemanager.webapp.cross-origin.enabled = true

This is because ui2 is designed as a separate web application.  WebFilters 
setup for existing resource manager doesn’t apply to the new web application.
Please open JIRA to track the security issue and resolve the problem prior to 
backporting this to branch-2.
This would minimize the risk to open up security hole in branch-2.  

Thank you

Regards,
Eric

On 10/16/17, 1:03 PM, "Vrushali C" <vrushalic2...@gmail.com> wrote:

    We are planning to include the new YARN UI as part of 2.9 release.  There
    is work in progress for back-porting the UI to branch2.
    
    Details at https://issues.apache.org/jira/browse/YARN-7169.
    
    
    
    On Mon, Nov 7, 2016 at 7:22 AM, Rohith Sharma K S <rohithsharm...@apache.org
    > wrote:
    
    > I just noticed that my voted mail has been sent to Wangda and forgotten to
    > keep yarn-dev in cc. Its my bad:-(  I am forwarding my voted mail to
    > yarn-dev.
    >
    > Thanks & Regards
    > Rohith Sharma K S
    >
    >
    > ---------- Forwarded message ----------
    > From: Rohith Sharma K S <rohithsharm...@apache.org>
    > Date: 3 November 2016 at 12:06
    > Subject: Re: [VOTE] Merge YARN-3368 (new web UI) to trunk
    > To: Wangda Tan <wheele...@gmail.com>
    >
    >
    > +1
    >
    > Built from YARN-3368 branch and hosted in cluster. It is pretty much good
    > user experience UI.
    > I hosted new web UI in same port as existing UI. I was able to experience
    > Queue, Application and Nodes pages.
    >
    >
    > Thanks & Regards
    > Rohith Sharma K S
    >
    > On 1 November 2016 at 04:23, Wangda Tan <wheele...@gmail.com> wrote:
    >
    > > YARN Devs,
    > >
    > > We propose to merge YARN-3368 (YARN next generation web UI) development
    > > branch into trunk for better development, would like to hear your
    > thoughts
    > > before sending out vote mail.
    > >
    > > The new UI will co-exist with the old YARN UI, by default it is 
disabled.
    > > Please refer to User documentation of the new YARN UI
    > > <https://github.com/apache/hadoop/blob/YARN-3368/hadoop-yarn
    > > -project/hadoop-yarn/hadoop-yarn-site/src/site/markdown/YarnUI2.md>
    > > for
    > > more details.
    > >
    > > In addition, There’re two working-in-progress features need the new UI 
to
    > > be merged to trunk for further development.
    > >
    > >   1) UI of YARN Timeline Server v2 (YARN-2928)
    > >   2) UI of YARN ResourceManager Federation (YARN-2915).
    > >
    > > *Status of YARN next generation web UI*
    > >
    > > Completed features
    > >
    > >    - Cluster Overview Page
    > >    - Scheduler page
    > >    - Applications / Application / Application-attempts pages
    > >    - Nodes / Node page
    > >
    > > Integration to YARN
    > >
    > >    - Hosts new web UI in RM
    > >    - Integrates to maven build / package
    > >
    > > Miscs:
    > >
    > >    - Added dependencies to LICENSE.txt/NOTICE.txt
    > >    - Documented how to use it. (In hadoop-yarn-project/hadoop-
    > yarn/hadoop-
    > >    yarn-site/src/site/markdown/YarnUI2.md)
    > >
    > > Major items will finish on trunk:
    > >
    > >    - Security support
    > >
    > > We have run the new UI in our internal cluster for more than 3 months,
    > lots
    > > of people have tried the new UI and gave lots of valuable feedbacks and
    > > reported suggestions / issues to us. We fixed many of them so now we
    > > believe it is more ready for wider folks to try.
    > >
    > > Merge JIRA for Jenkins is: https://issues.apache.org/
    > jira/browse/YARN-4734
    > > .
    > > The latest Jenkins run
    > > <https://issues.apache.org/jira/browse/YARN-4734?focusedComm
    > > entId=15620808&page=com.atlassian.jira.plugin.system.
    > > issuetabpanels:comment-tabpanel#comment-15620808>
    > > gave
    > > +1.
    > >
    > > The vote will run for 7 days, ending Sun, 11/06/2016. Please feel free 
to
    > > comment if you have any questions/doubts. I'll start with my +1
    > (binding).
    > >
    > > Please share your thoughts about this.
    > >
    > > Thanks,
    > > Wangda
    > >
    >
    


---------------------------------------------------------------------
To unsubscribe, e-mail: yarn-dev-unsubscr...@hadoop.apache.org
For additional commands, e-mail: yarn-dev-h...@hadoop.apache.org

Reply via email to