[ 
https://issues.apache.org/jira/browse/ATLAS-5422?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120448#comment-18120448
 ] 

ASF subversion and git services commented on ATLAS-5422:
--------------------------------------------------------

Commit dba84066732830ae5cf58d2a113baef50cea6a2c in atlas's branch 
refs/heads/master from bhor-sanket
[ https://gitbox.apache.org/repos/asf?p=atlas.git;h=dba840667 ]

ATLAS-5422:Support no-auth REST notification mode for header-based 
authentication environments (#775)


Co-authored-by: sanket.bhor <[email protected]>

> Support no-auth REST notification mode in trino-atlas for header-based 
> authentication environments
> --------------------------------------------------------------------------------------------------
>
>                 Key: ATLAS-5422
>                 URL: https://issues.apache.org/jira/browse/ATLAS-5422
>             Project: Atlas
>          Issue Type: Task
>            Reporter: sanket bhor
>            Assignee: sanket bhor
>            Priority: Major
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> h3. Background
> The trino-atlas plugin currently sends Atlas hook notifications via the Kafka 
> channel with Kerberos SASL/SSL authentication. The Atlas client library 
> (atlas-apache) also supports a REST notification channel with Kerberos 
> SPNEGO, Basic Auth, or JWT Bearer token authentication.
> In UDF environments, Kerberos and other traditional authentication mechanisms 
> are not used. Instead, these environments rely on header-based authentication 
> where an external gateway/proxy intercepts requests and injects auth headers 
> (x-awc-username, x-awc-roles, x-awc-requestid) before forwarding to the Atlas 
> server. The Atlas server is configured to trust these headers via 
> atlas.authn.header.enabled=true.
> h3. Problem
> When REST notification is enabled 
> (atlas.hook.rest.notification.enabled=true), the RestNotification class 
> (RestNotification.java:L86-96) forces one of two auth modes:
>  * Kerberos enabled → creates AtlasClientV2 with SPNEGO
>  * Kerberos disabled → creates AtlasClientV2 with Basic Auth (defaults to 
> admin/admin123)
> There is no option to create the client without any authentication, which is 
> required when the external gateway handles auth. Additionally, if Basic Auth 
> username/password resolves to null, the client calls
> System.console() which triggers System.exit(1) in daemon mode — crashing the 
> Trino JVM.
> h3. Requirement
> Provide a flag-based configuration to enable no-auth REST notification mode 
> where:
>  * The trino-atlas hook sends notifications via the REST channel without 
> attaching any client-side authentication (no Kerberos, no Basic Auth, no JWT)
>  * The external gateway/proxy is responsible for injecting the required auth 
> headers before the request reaches the Atlas server
>  * This mode should be opt-in via a configuration property to avoid 
> accidental misconfiguration
>  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to