diff --git a/docs/deployment/index.rst b/docs/deployment/index.rst index e68268088d6..ffc8c167b4e 100644 --- a/docs/deployment/index.rst +++ b/docs/deployment/index.rst @@ -29,6 +29,7 @@ Basics kyuubi_on_kubernetes hive_metastore high_availability_guide + migration-guide Configurations -------------- @@ -50,4 +51,4 @@ Engines engine_on_kubernetes engine_share_level engine_lifecycle - spark/index \ No newline at end of file + spark/index diff --git a/docs/deployment/migration-guide.md b/docs/deployment/migration-guide.md new file mode 100644 index 00000000000..067932cc071 --- /dev/null +++ b/docs/deployment/migration-guide.md @@ -0,0 +1,30 @@ + + + +# Kyuubi Migration Guide + +## Upgrading from Kyuubi 1.6.0 to 1.6.1 +* Since Kyuubi 1.6.1, `kyuubi.ha.zookeeper.engine.auth.type` does not fallback to `kyuubi.ha.zookeeper.auth.type`. + When Kyuubi engine does Kerberos authentication with Zookeeper, user needs to explicitly set `kyuubi.ha.zookeeper.engine.auth.type` to `KERBEROS`. + +## Upgrading from Kyuubi 1.5 to 1.6 +* Kyuubi engine gets Zookeeper principal & keytab from `kyuubi.ha.zookeeper.auth.principal` & `kyuubi.ha.zookeeper.auth.keytab`. + `kyuubi.ha.zookeeper.auth.principal` & `kyuubi.ha.zookeeper.auth.keytab` fallback to `kyuubi.kinit.principal` & `kyuubi.kinit.keytab` when not set. + Since Kyuubi 1.6, `kyuubi.kinit.principal` & `kyuubi.kinit.keytab` are filtered out from Kyuubi engine's conf for better security. + When Kyuubi engine does Kerberos authentication with Zookeeper, user needs to explicitly set `kyuubi.ha.zookeeper.auth.principal` & `kyuubi.ha.zookeeper.auth.keytab`. + diff --git a/kyuubi-ha/src/main/scala/org/apache/kyuubi/ha/HighAvailabilityConf.scala b/kyuubi-ha/src/main/scala/org/apache/kyuubi/ha/HighAvailabilityConf.scala index baa741abd3f..d33dccf982f 100644 --- a/kyuubi-ha/src/main/scala/org/apache/kyuubi/ha/HighAvailabilityConf.scala +++ b/kyuubi-ha/src/main/scala/org/apache/kyuubi/ha/HighAvailabilityConf.scala @@ -88,7 +88,9 @@ object HighAvailabilityConf { .doc("The type of zookeeper authentication for engine, all candidates are " + s"${AuthTypes.values.mkString("