123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206 |
- /**
- * Licensed to the Apache Software Foundation (ASF) under one
- * or more contributor license agreements. See the NOTICE file
- * distributed with this work for additional information
- * regarding copyright ownership. The ASF licenses this file
- * to you under the Apache License, Version 2.0 (the
- * "License"); you may not use this file except in compliance
- * with the License. You may obtain a copy of the License at
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
- * Unless required by applicable law or agreed to in writing, software
- * distributed under the License is distributed on an "AS IS" BASIS,
- * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- * See the License for the specific language governing permissions and
- * limitations under the License.
- */
- module.exports = {
- "properties": {
- "realm": "${cluster-env/kerberos_domain}",
- "keytab_dir": "/etc/security/keytabs"
- },
- "identities": [
- {
- "name": "spnego",
- "principal": {
- "value": "HTTP/_HOST@${realm}"
- },
- "keytab": {
- "file": "${keytab_dir}/spnego.service.keytab",
- "owner": {
- "name": "root",
- "access": "r"
- },
- "group": {
- "name": "${cluster-env/user_group}",
- "access": "r"
- }
- }
- }
- ],
- "configurations": [
- {
- "core-site": {
- "hadoop.security.authentication": "kerberos",
- "hadoop.rpc.protection": "authentication; integrity; privacy",
- "hadoop.security.authorization": "true"
- }
- }
- ],
- "services": [
- {
- "name": "HDFS",
- "components": [
- {
- "name": "NAMENODE",
- "identities": [
- {
- "name": "namenode_nn",
- "principal": {
- "value": "nn/_HOST@${realm}",
- "configuration": "hdfs-site/dfs.namenode.kerberos.principal"
- },
- "keytab": {
- "file": "${keytab_dir}/nn.service.keytab",
- "owner": {
- "name": "${hadoop-env/hdfs_user}",
- "access": "r"
- },
- "group": {
- "name": "${cluster-env/user_group}",
- "access": ""
- },
- "configuration": "hdfs-site/dfs.namenode.keytab.file"
- }
- },
- {
- "name": "namenode_host",
- "principal": {
- "value": "host/_HOST@${realm}",
- "configuration": "hdfs-site/dfs.namenode.kerberos.https.principal"
- },
- "keytab": {
- "file": "${keytab_dir}/host.keytab",
- "owner": {
- "name": "${hadoop-env/hdfs_user}",
- "access": "r"
- },
- "group": {
- "name": "${cluster-env/user_group}",
- "access": ""
- },
- "configuration": "hdfs-site/dfs.namenode.keytab.file"
- }
- },
- {
- "name": "/spnego",
- "principal": {
- "configuration": "hdfs-site/dfs.web.authentication.kerberos.principal"
- },
- "keytab": {
- "configuration": "hdfs/dfs.web.authentication.kerberos.keytab"
- }
- }
- ]
- },
- {
- "name": "DATANODE",
- "identities": [
- {
- "name": "datanode_dn",
- "principal": {
- "value": "dn/_HOST@${realm}",
- "configuration": "hdfs-site/dfs.namenode.kerberos.principal"
- },
- "keytab": {
- "file": "${keytab_dir}/dn.service.keytab",
- "owner": {
- "name": "${hadoop-env/hdfs_user}",
- "access": "r"
- },
- "group": {
- "name": "${cluster-env/user_group}",
- "access": ""
- },
- "configuration": "hdfs-site/dfs.namenode.keytab.file"
- }
- },
- {
- "name": "datanode_host",
- "principal": {
- "value": "host/_HOST@${realm}",
- "configuration": "hdfs-site/dfs.datanode.kerberos.https.principal"
- },
- "keytab": {
- "file": "${keytab_dir}/host.keytab.file",
- "owner": {
- "name": "${hadoop-env/hdfs_user}",
- "access": "r"
- },
- "group": {
- "name": "${cluster-env/user_group}",
- "access": ""
- },
- "configuration": "hdfs-site/dfs.namenode.secondary.keytab.file"
- }
- }
- ]
- },
- {
- "name": "SECONDARY_NAMENODE",
- "identities": [
- {
- "name": "secondary_namenode_nn",
- "principal": {
- "value": "nn/_HOST@${realm}",
- "configuration": "hdfs-site/dfs.namenode.secondary.kerberos.principal"
- },
- "keytab": {
- "file": "${keytab_dir}/snn.service.keytab",
- "owner": {
- "name": "${hadoop-env/hdfs_user}",
- "access": "r"
- },
- "group": {
- "name": "${cluster-env/user_group}",
- "access": ""
- },
- "configuration": "hdfs-site/dfs.namenode.secondary.keytab.file"
- }
- },
- {
- "name": "secondary_namenode_host",
- "principal": {
- "value": "host/_HOST@${realm}",
- "configuration": "hdfs-site/dfs.namenode.secondary.kerberos.https.principal"
- },
- "keytab": {
- "file": "${keytab_dir}/host.keytab.file",
- "owner": {
- "name": "${hadoop-env/hdfs_user}",
- "access": "r"
- },
- "group": {
- "name": "${cluster-env/user_group}",
- "access": ""
- },
- "configuration": "hdfs-site/dfs.namenode.secondary.keytab.file"
- }
- },
- {
- "name": "/spnego",
- "principal": {
- "configuration": "hdfs-site/dfs.web.authentication.kerberos.principal"
- },
- "keytab": {
- "configuration": "hdfs/dfs.web.authentication.kerberos.keytab"
- }
- }
- ]
- }
- ]
- }
- ]
- };
|