[
https://issues.apache.org/jira/browse/ATLAS-5422?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120448#comment-18120448
]
ASF subversion and git services commented on ATLAS-5422:
--------------------------------------------------------
Commit dba84066732830ae5cf58d2a113baef50cea6a2c in atlas's branch
refs/heads/master from bhor-sanket
[ https://gitbox.apache.org/repos/asf?p=atlas.git;h=dba840667 ]
ATLAS-5422:Support no-auth REST notification mode for header-based
authentication environments (#775)
Co-authored-by: sanket.bhor <[email protected]>
> Support no-auth REST notification mode in trino-atlas for header-based
> authentication environments
> --------------------------------------------------------------------------------------------------
>
> Key: ATLAS-5422
> URL: https://issues.apache.org/jira/browse/ATLAS-5422
> Project: Atlas
> Issue Type: Task
> Reporter: sanket bhor
> Assignee: sanket bhor
> Priority: Major
> Time Spent: 20m
> Remaining Estimate: 0h
>
> h3. Background
> The trino-atlas plugin currently sends Atlas hook notifications via the Kafka
> channel with Kerberos SASL/SSL authentication. The Atlas client library
> (atlas-apache) also supports a REST notification channel with Kerberos
> SPNEGO, Basic Auth, or JWT Bearer token authentication.
> In UDF environments, Kerberos and other traditional authentication mechanisms
> are not used. Instead, these environments rely on header-based authentication
> where an external gateway/proxy intercepts requests and injects auth headers
> (x-awc-username, x-awc-roles, x-awc-requestid) before forwarding to the Atlas
> server. The Atlas server is configured to trust these headers via
> atlas.authn.header.enabled=true.
> h3. Problem
> When REST notification is enabled
> (atlas.hook.rest.notification.enabled=true), the RestNotification class
> (RestNotification.java:L86-96) forces one of two auth modes:
> * Kerberos enabled → creates AtlasClientV2 with SPNEGO
> * Kerberos disabled → creates AtlasClientV2 with Basic Auth (defaults to
> admin/admin123)
> There is no option to create the client without any authentication, which is
> required when the external gateway handles auth. Additionally, if Basic Auth
> username/password resolves to null, the client calls
> System.console() which triggers System.exit(1) in daemon mode — crashing the
> Trino JVM.
> h3. Requirement
> Provide a flag-based configuration to enable no-auth REST notification mode
> where:
> * The trino-atlas hook sends notifications via the REST channel without
> attaching any client-side authentication (no Kerberos, no Basic Auth, no JWT)
> * The external gateway/proxy is responsible for injecting the required auth
> headers before the request reaches the Atlas server
> * This mode should be opt-in via a configuration property to avoid
> accidental misconfiguration
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)