Github user vanzin commented on the pull request:
https://github.com/apache/spark/pull/4106#issuecomment-75859364
> I'm confused as to how this case is different from anywhere else we use
Kerberos authentication to HDFS in Spark.
You're opening up the possibility that user code will find the keytab to
the HDFS super user (since it needs read access to it, otherwise your executor
can't log in).
The user can then login with that keytab and voila! Instant super user
access. Or it can upload the keytab somewhere else...
---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at [email protected] or file a JIRA ticket
with INFRA.
---
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]