NIFI-8973 Implement KerberosUserService API with keytab, password, and ticket cache implementations#5277
Closed
bbende wants to merge 6 commits intoapache:mainfrom
Closed
NIFI-8973 Implement KerberosUserService API with keytab, password, and ticket cache implementations#5277bbende wants to merge 6 commits intoapache:mainfrom
bbende wants to merge 6 commits intoapache:mainfrom
Conversation
gresockj
reviewed
Aug 12, 2021
.../nifi-security-kerberos/src/main/java/org/apache/nifi/security/krb/AbstractKerberosUser.java
Outdated
Show resolved
Hide resolved
.../nifi-security-kerberos/src/main/java/org/apache/nifi/security/krb/AbstractKerberosUser.java
Outdated
Show resolved
Hide resolved
...-kerberos-user-service/src/main/java/org/apache/nifi/kerberos/KerberosKeytabUserService.java
Outdated
Show resolved
Hide resolved
...erberos-user-service/src/main/java/org/apache/nifi/kerberos/KerberosPasswordUserService.java
Outdated
Show resolved
Hide resolved
...eros-user-service/src/main/java/org/apache/nifi/kerberos/KerberosTicketCacheUserService.java
Outdated
Show resolved
Hide resolved
… ticket cache implementations NIFI-8974 Integrate KerberosUserService with HDFS processors
- Introduced SelfContainerKerberosUserService to restrict which impls can be used with Kafka - Add variations of KerberosUser doAs that allow setting the context ClassLoader - Add additional unit tests for configurations
Contributor
exceptionfactory
left a comment
There was a problem hiding this comment.
Thanks for putting this together @bbende, it looks like a great improvement to managing Kerberos authentication handling. The overall approach looks good, I noted a handful of small suggestions and questions.
.../nifi-security-kerberos/src/main/java/org/apache/nifi/security/krb/AbstractKerberosUser.java
Outdated
Show resolved
Hide resolved
.../nifi-security-kerberos/src/main/java/org/apache/nifi/security/krb/AbstractKerberosUser.java
Outdated
Show resolved
Hide resolved
...-6-processors/src/main/java/org/apache/nifi/processors/kafka/pubsub/CustomKerberosLogin.java
Outdated
Show resolved
Hide resolved
...-6-processors/src/main/java/org/apache/nifi/processors/kafka/pubsub/KafkaProcessorUtils.java
Outdated
Show resolved
Hide resolved
...-6-processors/src/main/java/org/apache/nifi/processors/kafka/pubsub/KafkaProcessorUtils.java
Outdated
Show resolved
Hide resolved
...fi-standard-services/nifi-kerberos-user-service-bundle/nifi-kerberos-user-service/.gitignore
Outdated
Show resolved
Hide resolved
...eros-user-service/src/main/java/org/apache/nifi/kerberos/KerberosTicketCacheUserService.java
Outdated
Show resolved
Hide resolved
Contributor
Author
|
@exceptionfactory thanks for the review, I think all comments should be addressed now, let me know if there is anything else |
exceptionfactory
approved these changes
Aug 19, 2021
Contributor
exceptionfactory
left a comment
There was a problem hiding this comment.
Thanks for the updates @bbende! Verified using GetHDFS with all three types of KerberosUserService implementations as well using existing properties. +1 Merging.
krisztina-zsihovszki
pushed a commit
to krisztina-zsihovszki/nifi
that referenced
this pull request
Jun 28, 2022
… ticket cache implementations NIFI-8974 Integrate KerberosUserService with HDFS processors NIFI-8980 Integrate KerberosUserService with Kafka 2.6 processors - Introduced SelfContainerKerberosUserService to restrict which impls can be used with Kafka - Add variations of KerberosUser doAs that allow setting the context ClassLoader - Add additional unit tests for configurations This closes apache#5277 Signed-off-by: David Handermann <exceptionfactory@apache.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thank you for submitting a contribution to Apache NiFi.
Also includes - NIFI-8974 Integrate KerberosUserService with HDFS processors
Enables X functionality; fixes bug NIFI-YYYY.
In order to streamline the review of the contribution we ask you
to ensure the following steps have been taken:
For all changes:
Is there a JIRA ticket associated with this PR? Is it referenced
in the commit message?
Does your PR title start with NIFI-XXXX where XXXX is the JIRA number you are trying to resolve? Pay particular attention to the hyphen "-" character.
Has your PR been rebased against the latest commit within the target branch (typically
main)?Is your initial contribution a single, squashed commit? Additional commits in response to PR reviewer feedback should be made on this branch and pushed to allow change tracking. Do not
squashor use--forcewhen pushing to allow for clean monitoring of changes.For code changes:
mvn -Pcontrib-check clean installat the rootnififolder?LICENSEfile, including the mainLICENSEfile undernifi-assembly?NOTICEfile, including the mainNOTICEfile found undernifi-assembly?.displayNamein addition to .name (programmatic access) for each of the new properties?For documentation related changes:
Note:
Please ensure that once the PR is submitted, you check GitHub Actions CI for build issues and submit an update to your PR as soon as possible.