Repository: storm
Updated Branches:
  refs/heads/master 0b3203239 -> 09d95f7eb


STORM-2935 update autocredential metric documentation


Project: http://git-wip-us.apache.org/repos/asf/storm/repo
Commit: http://git-wip-us.apache.org/repos/asf/storm/commit/318b49e6
Tree: http://git-wip-us.apache.org/repos/asf/storm/tree/318b49e6
Diff: http://git-wip-us.apache.org/repos/asf/storm/diff/318b49e6

Branch: refs/heads/master
Commit: 318b49e6c4b59dfaf962ae9817c7bd41cf6b5d92
Parents: b5aca6c
Author: Aaron Gresch <agre...@yahoo-inc.com>
Authored: Thu Feb 8 14:25:40 2018 -0600
Committer: Aaron Gresch <agre...@yahoo-inc.com>
Committed: Thu Feb 8 14:25:40 2018 -0600

----------------------------------------------------------------------
 docs/SECURITY.md | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/storm/blob/318b49e6/docs/SECURITY.md
----------------------------------------------------------------------
diff --git a/docs/SECURITY.md b/docs/SECURITY.md
index 6a96704..d4d7964 100644
--- a/docs/SECURITY.md
+++ b/docs/SECURITY.md
@@ -429,7 +429,9 @@ To hide this from them in the common case plugins can be 
used to populate the cr
 `topology.auto-credentials` is a list of java plugins, all of which must 
implement the `IAutoCredentials` interface, that populate the credentials on 
gateway 
 and unpack them on the worker side. On a kerberos secure cluster they should 
be set by default to point to `org.apache.storm.security.auth.kerberos.AutoTGT`
 
-`nimbus.credential.renewers.classes` should also be set to 
`org.apache.storm.security.auth.kerberos.AutoTGT` so that nimbus can 
periodically renew the TGT on behalf of the user.
+`nimbus.credential.renewers.classes` should also be set to 
`org.apache.storm.security.auth.kerberos.AutoTGT` so that nimbus can 
periodically renew the TGT on behalf of the user.  
+
+All autocredential classes that desire to implement the IMetricsRegistrant 
interface can register metrics automatically for each topology.  The AutoTGT 
class currently implements this interface and adds a metric named 
TGT-TimeToExpiryMsecs showing the remaining time until the TGT needs to be 
renewed.
 
 `nimbus.credential.renewers.freq.secs` controls how often the renewer will 
poll to see if anything needs to be renewed, but the default should be fine.
 
@@ -518,4 +520,4 @@ nimbus.groups:
  | storm.zookeeper.topology.auth.scheme | The topology Zookeeper 
authentication scheme to use, e.g. "digest". It is the internal config and user 
shouldn't set it. |
  | storm.zookeeper.topology.auth.payload | A string representing the payload 
for topology Zookeeper authentication. |
  
- Note: If storm.zookeeper.topology.auth.payload isn't set,storm will generate 
a ZooKeeper secret payload for MD5-digest with 
generateZookeeperDigestSecretPayload() method.
\ No newline at end of file
+ Note: If storm.zookeeper.topology.auth.payload isn't set,storm will generate 
a ZooKeeper secret payload for MD5-digest with 
generateZookeeperDigestSecretPayload() method.

Reply via email to