Gokul Kolady has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24367 )

Change subject: IMPALA-15017: Add secure-cluster Helm options
......................................................................


Patch Set 46:

(1 comment)

http://gerrit.cloudera.org:8080/#/c/24367/46/helm/impala/templates/impalad-deployment.yaml
File helm/impala/templates/impalad-deployment.yaml:

http://gerrit.cloudera.org:8080/#/c/24367/46/helm/impala/templates/impalad-deployment.yaml@113
PS46, Line 113:             - -principal={{ .Values.security.kerberos.principal 
}}
`security.kerberos.enabled=true` does not currently require 
`security.kerberos.principal`.
If `principal` is empty, this renders `-principal=` and Impala treats Kerberos 
as disabled, which can silently deploy an insecure cluster while users think 
Kerberos is enabled.
Can we make `security.kerberos.principal` required when Kerberos is enabled 
(similar to `keytabSecretName`) and apply the same check in 
catalogd/statestored templates?



--
To view, visit http://gerrit.cloudera.org:8080/24367
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I02e4c4b466424a938151bd69b28bf99ae405fae7
Gerrit-Change-Number: 24367
Gerrit-PatchSet: 46
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Comment-Date: Tue, 28 Jul 2026 20:34:13 +0000
Gerrit-HasComments: Yes

Reply via email to