Anubhav Jindal has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24367 )

Change subject: IMPALA-15017: Add secure-cluster Helm options
......................................................................


Patch Set 48:

(4 comments)

Done

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/README.md
File helm/impala/README.md:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/README.md@219
PS47, Line 219: ### 3) (Optional) Enable Istio sidecar injection
> If Istio is enabled, will the externally facing hs2 and debug webserver por
Added explicit README guidance that Istio external TLS termination and chart 
TLS secret config should generally not be combined unless intentionally 
configured.


http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/catalogd-deployment.yaml
File helm/impala/templates/catalogd-deployment.yaml:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/catalogd-deployment.yaml@91
PS47, Line 91: {{- if .Values.security.tls.enabled }}
             :             - -ssl_server_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
             :             - -ssl_private_key={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
             :             - -webserver_certificate_file={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
             :             - -webserver_private_key_file={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
             : {{- if .Va
> These flags cover the beeswax/hs2 servers but do not cover the debug http w
Added -webserver_certificate_file and -webserver_private_key_file under TLS


http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/impalad-deployment.yaml
File helm/impala/templates/impalad-deployment.yaml:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/impalad-deployment.yaml@122
PS47, Line 122: {{- if .Values.security.tls.enabled }}
              :             - -ssl_server_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
              :             - -ssl_private_key={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
              :             - -webserver_certificate_file={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
              :             - -webserver_private_key_file={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
              : {{- if .Values.security.tls.clientCaFileName }}
              :          
> These flags cover the beeswax/hs2 servers but do not cover the debug http w
Added -webserver_certificate_file and -webserver_private_key_file under TLS


http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/statestored-deployment.yaml
File helm/impala/templates/statestored-deployment.yaml:

http://gerrit.cloudera.org:8080/#/c/24367/47/helm/impala/templates/statestored-deployment.yaml@79
PS47, Line 79: {{- if .Values.security.tls.enabled }}
             :             - -ssl_server_certificate={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
             :             - -ssl_private_key={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
             :             - -webserver_certificate_file={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.certFileName }}
             :             - -webserver_private_key_file={{ printf "%s/%s" 
.Values.security.tls.mountPath .Values.security.tls.keyFileName }}
             : {{- if .Values.security.tls.clientCaFileName }}
             :  
> These flags cover the beeswax/hs2 servers but do not cover the debug http w
Added -webserver_certificate_file and -webserver_private_key_file under TLS



--
To view, visit http://gerrit.cloudera.org:8080/24367
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I02e4c4b466424a938151bd69b28bf99ae405fae7
Gerrit-Change-Number: 24367
Gerrit-PatchSet: 48
Gerrit-Owner: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Abhishek Rawat <[email protected]>
Gerrit-Reviewer: Anubhav Jindal <[email protected]>
Gerrit-Reviewer: Gokul Kolady <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Jason Fehr <[email protected]>
Gerrit-Comment-Date: Tue, 04 Aug 2026 22:14:54 +0000
Gerrit-HasComments: Yes

Reply via email to