<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: What are the best practices to secure spark on HDP 2.3 in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96330#M9787</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj&lt;/A&gt; The docs are conflicting.
It is recommending "use HiveContext" in secure mode (with kerberos):
&lt;STRONG&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_installing-kerb-spark.html#spark-kerb-access-hive" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_installing-kerb-spark.html#spark-kerb-access-hive&lt;/A&gt;&lt;/STRONG&gt;
and under best practices it states that it is not supported with Kerberos:
&lt;STRONG&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_practices-spark.html" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_practices-spark.html&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2015 04:14:16 GMT</pubDate>
    <dc:creator>ldaluz</dc:creator>
    <dc:date>2015-11-04T04:14:16Z</dc:date>
    <item>
      <title>What are the best practices to secure spark on HDP 2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96326#M9783</link>
      <description />
      <pubDate>Sat, 31 Oct 2015 08:08:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96326#M9783</guid>
      <dc:creator>Eran</dc:creator>
      <dc:date>2015-10-31T08:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practices to secure spark on HDP 2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96327#M9784</link>
      <description>&lt;P&gt;@&lt;A href="http://community.hortonworks.com/users/111/eorgad.html"&gt;eorgad@hortonworks.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_installing-kerb-spark.html"&gt;Spark and Kerberos &lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2015 08:18:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96327#M9784</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2015-10-31T08:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practices to secure spark on HDP 2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96328#M9785</link>
      <description>&lt;P&gt;So the real problem in our documentation - Best practices, has a conflicting message "use HiveContext (instead of SQLContext) whenever possible" but In YARN cluster mode with Kerberos, use &lt;CODE&gt;SQLContext !&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_practices-spark.html" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_practices-spark.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 03:59:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96328#M9785</guid>
      <dc:creator>Eran</dc:creator>
      <dc:date>2015-11-04T03:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practices to secure spark on HDP 2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96329#M9786</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/111/eorgad.html" nodeid="111"&gt;@eorgad@hortonworks.com&lt;/A&gt; because "In YARN cluster mode with Kerberos, use &lt;CODE&gt;SQLContext&lt;/CODE&gt;. &lt;CODE&gt;&lt;STRONG&gt;HiveContext&lt;/STRONG&gt;&lt;/CODE&gt;&lt;STRONG&gt; is not supported on YARN in a Kerberos-enabled cluster.&lt;/STRONG&gt;"&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 04:05:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96329#M9786</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2015-11-04T04:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practices to secure spark on HDP 2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96330#M9787</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj&lt;/A&gt; The docs are conflicting.
It is recommending "use HiveContext" in secure mode (with kerberos):
&lt;STRONG&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_installing-kerb-spark.html#spark-kerb-access-hive" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_installing-kerb-spark.html#spark-kerb-access-hive&lt;/A&gt;&lt;/STRONG&gt;
and under best practices it states that it is not supported with Kerberos:
&lt;STRONG&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_practices-spark.html" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_spark-guide/content/ch_practices-spark.html&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 04:14:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96330#M9787</guid>
      <dc:creator>ldaluz</dc:creator>
      <dc:date>2015-11-04T04:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practices to secure spark on HDP 2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96331#M9788</link>
      <description>&lt;P&gt;This is a doc bug, filed BUG-47289&lt;/P&gt;&lt;P&gt;Use HiveContext and it should work in Kerberized Cluster with HDP 2.3.2&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 04:56:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96331#M9788</guid>
      <dc:creator>vshukla</dc:creator>
      <dc:date>2015-11-04T04:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practices to secure spark on HDP 2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96332#M9789</link>
      <description>&lt;P&gt;Spark reads from HDFS and sends jobs to YARN. So security for both HDFS, YARN  managed by Ranger works with Spark.  From security point of view this is very similar to MR jobs being run on YARN.&lt;/P&gt;&lt;P&gt;Since Spark reads from HDFS using HDFS client, the HDFS TDE feature is transparent to Spark and with right key permissions for user running Spark job, there is nothing in Spark to configure.&lt;/P&gt;&lt;P&gt;Knox isn’t yet relevant to Spark. In future when we have a REST API for Spark, we will integrate Knox with it.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 04:57:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practices-to-secure-spark-on-HDP-2-3/m-p/96332#M9789</guid>
      <dc:creator>vshukla</dc:creator>
      <dc:date>2015-11-04T04:57:24Z</dc:date>
    </item>
  </channel>
</rss>

