workflow for password changes of auto created service principals for hive and hdfs
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- kubernetes, rust
- Ambito
- authentication, security
Direzione di ricerca
Non vengono indicati file, test o punti di ingresso. Inizia esaminando il comportamento di Kerberos keytab e secret-provisioning di secret-operator, quindi determina come la rotazione delle password potrebbe preservare la disponibilità per i client Hive e HDFS e supportare i sistemi LDAP provisionati esternamente. Il lavoro è completato quando è definito un workflow di rotazione automatizzato e concordato, con un comportamento di rollover sicuro.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
when creating a kerberized hive or hdfs cluster the service principals hive/hive.namespace.xy for hive and nn/hdfs.namespace.xy, dn/hdfs.namespace.xy, jn/hdfs.namespace.xy for hdfs will be created automatically and get an initial password at creation time. rolling those passwords would be great to satisfy security guidelines that require yearly or monthly password changes of the service principals.
the complexity might hide in keeping the clusters safe and available while rolling the password because there might be clients talking to hdfs permanently. these clients should not recognise any change of passwords
this should work especially for external ldap systems centrally provisioned by a certain team.
best case for a user would be that the password is automatically rolled without any human action similar to rolling certificates. beyond that comfort a fully automated routine would enable user to decrease the password lifetime to a minimum.
@soenkeliebau as mentioned today
- Lingua principale
- Rust
- Stelle
- 13
- Fork
- 8
- Merge medio
- 1g 8h
- PR unite (30g)
- 10
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di stackabletech/secret-operator
-
type/bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
stackabletech/secret-operator#754 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 48/100
stackabletech/secret-operator#753 · 1 commento ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
stackabletech/secret-operator#720 · 1 commento ·
-
customer-request type/bug
Difficoltà 3/5 1-2 giorni Idoneità per principianti 38/100
stackabletech/secret-operator#666 · 2 commenti ·
-
customer-request type/feature-improvement
stackabletech/secret-operator#630 · 7 commenti · 1 assegnatario ·
Tutte le issue di stackabletech/secret-operator
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
web-infra-dev/rspack#15847 ·