Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Support Questions

Find answers, ask questions, and share your expertise
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

Can Apache Hadoop run reliably inside Istio service mesh with mTLS enabled?

avatar
Contributor

Hi Everyone,

We are evaluating whether Apache Hadoop can run inside an Istio service mesh and would like to understand if this is a supported or practical setup.

Our environment:

Hadoop cluster running on physical machines (bare metal)

No Kerberos

Istio is mandatory

Istio mTLS must be enabled

Hadoop services (NameNode, DataNode, YARN, etc.) would need to communicate through Istio

Our concerns:

Hadoop uses long-lived TCP connections and custom RPC protocols

Istio mTLS intercepts and terminates connections

Unsure if Hadoop components work reliably behind Envoy proxies

Uncertain about the performance and stability impact

Questions:

Has anyone successfully run Hadoop inside Istio with mTLS enabled?

Is this officially supported or just theoretically possible?

Are there known limitations or failure cases (HDFS, YARN, shuffle, etc.)?

Any real-world experience or guidance would be greatly appreciated.

Thanks!

1 REPLY 1

avatar
Community Manager

@KPG1 If you have not tried yet, I'd suggest asking in Istio's discussion board.

Keep the questions coming