[
https://issues.apache.org/jira/browse/FLINK-5091?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15715490#comment-15715490
]
ASF GitHub Bot commented on FLINK-5091:
---------------------------------------
Github user mxm commented on a diff in the pull request:
https://github.com/apache/flink/pull/2915#discussion_r90664782
--- Diff:
flink-runtime/src/main/java/org/apache/flink/runtime/clusterframework/overlays/KeytabOverlay.java
---
@@ -0,0 +1,102 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements. See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership. The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.flink.runtime.clusterframework.overlays;
+
+import org.apache.flink.configuration.ConfigConstants;
+import org.apache.flink.configuration.Configuration;
+import org.apache.flink.core.fs.Path;
+import org.apache.flink.runtime.clusterframework.ContainerSpecification;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
+
+import javax.annotation.Nullable;
+import java.io.File;
+import java.io.IOException;
+
+
+/**
+ * Overlays cluster-level Kerberos credentials (i.e. keytab) into a
container.
+ *
+ * The folloowing Flink configuration entries are updated:
+ * - security.keytab
+ */
+public class KeytabOverlay extends AbstractContainerOverlay {
+
+ private static final Logger LOG =
LoggerFactory.getLogger(KeytabOverlay.class);
+
+ static final Path TARGET_PATH = new Path("krb5.keytab");
+
+ final Path keytab;
+
+ public KeytabOverlay(@Nullable File keytab) {
+ this.keytab = keytab != null ? new Path(keytab.toURI()) : null;
+ }
+
+ public KeytabOverlay(@Nullable Path keytab) {
+ this.keytab = keytab;
+ }
+
+ @Override
+ public void configure(ContainerSpecification container) throws
IOException {
+ if(keytab != null) {
+
container.getArtifacts().add(ContainerSpecification.Artifact.newBuilder()
+ .setSource(keytab)
+ .setDest(TARGET_PATH)
+ .setCachable(false)
+ .build());
+
container.getDynamicConfiguration().setString(ConfigConstants.SECURITY_KEYTAB_KEY,
TARGET_PATH.getPath());
+ }
+ }
+
+ public static Builder newBuilder() {
+ return new Builder();
+ }
+
+ /**
+ * A builder for the {@link HadoopUserOverlay}.
+ */
+ public static class Builder {
+
+ File keytabPath;
+
+ /**
+ * Configures the overlay using the current environment (and
global configuration).
+ *
+ * The following Flink configuration settings are checked for a
keytab:
+ * - security.keytab
+ */
--- End diff --
indention is off here
> Formalize the AppMaster environment for docker compability
> ----------------------------------------------------------
>
> Key: FLINK-5091
> URL: https://issues.apache.org/jira/browse/FLINK-5091
> Project: Flink
> Issue Type: Sub-task
> Components: Cluster Management, Mesos
> Reporter: Eron Wright
> Assignee: Eron Wright
> Fix For: 1.2.0
>
>
> For scenarios where the AppMaster is launched from a docker image, it would
> be ideal to use the installed Flink rather than rely on a special file layout
> in the sandbox directory.
> This is related to DCOS integration, which (in 1.2) will launch the AppMaster
> via Marathon (as a top-level DCOS service). The existing code assumed that
> only the dispatcher (coming in 1.3) would launch the AppMaster.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)