Gokul Kolady has posted comments on this change. ( http://gerrit.cloudera.org:8080/24367 )
Change subject: IMPALA-15017: Add secure-cluster Helm options ...................................................................... Patch Set 46: (1 comment) http://gerrit.cloudera.org:8080/#/c/24367/46/helm/impala/templates/impalad-deployment.yaml File helm/impala/templates/impalad-deployment.yaml: http://gerrit.cloudera.org:8080/#/c/24367/46/helm/impala/templates/impalad-deployment.yaml@113 PS46, Line 113: - -principal={{ .Values.security.kerberos.principal }} `security.kerberos.enabled=true` does not currently require `security.kerberos.principal`. If `principal` is empty, this renders `-principal=` and Impala treats Kerberos as disabled, which can silently deploy an insecure cluster while users think Kerberos is enabled. Can we make `security.kerberos.principal` required when Kerberos is enabled (similar to `keytabSecretName`) and apply the same check in catalogd/statestored templates? -- To view, visit http://gerrit.cloudera.org:8080/24367 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I02e4c4b466424a938151bd69b28bf99ae405fae7 Gerrit-Change-Number: 24367 Gerrit-PatchSet: 46 Gerrit-Owner: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Abhishek Rawat <[email protected]> Gerrit-Reviewer: Anubhav Jindal <[email protected]> Gerrit-Reviewer: Gokul Kolady <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Jason Fehr <[email protected]> Gerrit-Comment-Date: Tue, 28 Jul 2026 20:34:13 +0000 Gerrit-HasComments: Yes
