MartijnVisser opened a new pull request, #29185:
URL: https://github.com/apache/flink/pull/29185
## What is the purpose of the change
* Fix the Kerberized and PyFlink YARN Docker e2e tests, which can't build
their KDC image anymore now that Debian 11 is EOL and its security pool has
been emptied
## Brief change log
* Build the test KDC image from `debian:bookworm` instead of
`debian:bullseye`
## Verifying this change
This change is already covered by existing tests, such as `Running
Kerberized YARN per-job on Docker test` and `PyFlink YARN per-job on Docker
test`, neither of which can run today.
Verified locally by building the image: it fails on `f319666879` with
`apt-get install locales krb5-kdc krb5-admin-server` returning 404s, passes
with this change, and fails again when the `FROM` line is reverted. The
resulting KDC issues a TGT to a krb5 1.19.2 client and to a JDK 8
`Krb5LoginModule` keytab login, which is what the Hadoop containers in this
cluster do.
## Does this pull request potentially affect one of the following parts:
- Dependencies (does it add or upgrade a dependency): yes
- The public API, i.e., is any changed class annotated with
`@Public(Evolving)`: no
- The serializers: no
- The runtime per-record code paths (performance sensitive): no
- Anything that affects deployment or recovery: JobManager (and its
components), Checkpointing, Kubernetes/Yarn, ZooKeeper: no
- The S3 file system connector: no
## Documentation
- Does this pull request introduce a new feature? no
- If yes, how is the feature documented? not applicable
---
##### Was generative AI tooling used to co-author this PR?
- [X] Yes (please specify the tool below)
Generated-by: Claude Code (Claude Opus 5)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]