[
https://issues.apache.org/jira/browse/SPARK-5159?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15884979#comment-15884979
]
Mridul Muralidharan commented on SPARK-5159:
--------------------------------------------
For 1.6.x and earlier, we found that doAs support did not work for spark thrift
server - I have not tested it for spark 2.x though.
What is broken :
* All jobs executed as "hive" user - there is no enforcement of impersonated
user.
** As queries are run as the hive user, read access for hive user is enforced.
** Output generated (tables created, etc) as hive user.
* Data cached is shared across all queries - essentially available across users.
In a nutshell, impersonation does not work.
> Thrift server does not respect hive.server2.enable.doAs=true
> ------------------------------------------------------------
>
> Key: SPARK-5159
> URL: https://issues.apache.org/jira/browse/SPARK-5159
> Project: Spark
> Issue Type: Bug
> Components: SQL
> Affects Versions: 1.2.0
> Reporter: Andrew Ray
> Attachments: spark_thrift_server_log.txt
>
>
> I'm currently testing the spark sql thrift server on a kerberos secured
> cluster in YARN mode. Currently any user can access any table regardless of
> HDFS permissions as all data is read as the hive user. In HiveServer2 the
> property hive.server2.enable.doAs=true causes all access to be done as the
> submitting user. We should do the same.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]