[
https://issues.apache.org/jira/browse/YARN-896?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13734983#comment-13734983
]
Robert Joseph Evans commented on YARN-896:
------------------------------------------
Sorry I have not responded sooner. I have been out on vacation and had a high
severity issue that has consumed a lot of my time.
[~lmccay] and [~thw] There are many different services that long lived
processes need to communicate with. Many of these services use tokens and
others may not. Each of these tokens or other credentials are specific to the
services being accessed. In some cases like with HBase we probably can take
advantage of the existing renewal feature in the RM. With other tokens or
credentials it may be different, and may require AM specific support for them.
I am not really that concerned with solving the renewal problem for all
possible credentials here, although if we can solve this for a lot of common
tokens at the same time that would be great. What I care most about is being
sure that a long lived YARN application does not necessarily have to stop and
restart because an HDFS token cannot be renewed any longer. If there are
changes going into the HDFS security model that would make YARN-941 unnecessary
that is great. I have not had much time to follow the security discussion so
thank you for pointing this out. But it is also a question of time frames.
YARN-941 and YARN-1041 would allow for secure, robust, long lived applications
on YARN, and do not appear to be that difficult to accomplish. Do you know the
time frame for the security rework?
> Roll up for long lived YARN
> ---------------------------
>
> Key: YARN-896
> URL: https://issues.apache.org/jira/browse/YARN-896
> Project: Hadoop YARN
> Issue Type: New Feature
> Reporter: Robert Joseph Evans
>
> YARN is intended to be general purpose, but it is missing some features to be
> able to truly support long lived applications and long lived containers.
> This ticket is intended to
> # discuss what is needed to support long lived processes
> # track the resulting JIRA.
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira