Basically in CDP public cloud, FreeIPA acts a KDC server
So when the cluster is created, CM server will create necessary Kerberos SP’s in FreeIPA database and it is handled automatically, Similarly when a user is synced to FreeIPA, a kerberos principal will be created in FreeIPA