afedulov opened a new pull request, #22810:
URL: https://github.com/apache/flink/pull/22810

   ## What is the purpose of the change
   
   SQL Client gateway mode allows to submit SQL queries to remote Flink 
clusters.The target clusters are often placed behind proxies, such as K8S 
ingresses. [FLINK-32030](https://issues.apache.org/jira/browse/FLINK-32030) 
expanded the capability to connect to SQL gateways using URLs. This PR 
addresses the limitation caused by the tight coupling between the underlying 
`RestClient` and internal cluster SSL configuration. It makes it possible to 
connect to HTTPS endpoints using built-in JDK keystores rather than forcing 
usage of user-supplied once. 
   
   ## Brief change log
   
   - Makes  user-supplied `TrustManager` configuration optional when enabling 
SSL
   - Automatically enables SSL in RestClient for `https://` URLs
   - Makes use of encrypted endpoints in SQL Client
   
   ## Verifying this change
     - Added test to verify that a HTTPS connection using built-in JDK 
truststore works as expected
   
   ## Does this pull request potentially affect one of the following parts:
   
     - Dependencies (does it add or upgrade a dependency): (yes / **no**)
     - The public API, i.e., is any changed class annotated with 
`@Public(Evolving)`: (yes / **no**)
     - The serializers: (yes / **no** / don't know)
     - The runtime per-record code paths (performance sensitive): (yes / **no** 
/ don't know)
     - Anything that affects deployment or recovery: JobManager (and its 
components), Checkpointing, Kubernetes/Yarn, ZooKeeper: (yes / no / don't know)
     - The S3 file system connector: (yes / **no** / don't know)
   
   ## Documentation
   
     - Does this pull request introduce a new feature? (**yes** / no)
     - A follow up docs PR will be created to document URLs support in SQL 
Client gateway mode
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to