feat(yarn_client): auth config for YARN REST (none/simple/basic/kerberos)
Add per-Connection authentication so CDH 5 / Kerberos / HTTP Basic clusters can be queried. - auth_type: none / simple / basic / kerberos - auth_user / auth_password for HTTP Basic - auth_principal / auth_keytab stored for audit/display; actual SPNEGO handled by httpx-kerberos using the system Kerberos credential cache - YarnClientConfig.auth_for_httpx() returns the right httpx.Auth object - _request passes auth= through to httpx.request alongside verify= New dependency: httpx-kerberos. Tests cover none/simple (no auth object), Basic auth header, Kerberos auth object, missing basic user, invalid auth_type, and tool-layer config propagation.
This commit is contained in:
@@ -53,6 +53,13 @@ class Connection(BaseModel):
|
||||
# overrides the global default for this connection.
|
||||
ssl_verify: bool | None = None
|
||||
ssl_ca_bundle: str | None = None
|
||||
# Authentication for YARN REST calls.
|
||||
auth_type: str = "none" # "none" | "simple" | "basic" | "kerberos"
|
||||
auth_user: str | None = None
|
||||
auth_password: str | None = None
|
||||
# Display/audit only for kerberos; actual SPNEGO uses the system cache.
|
||||
auth_principal: str | None = None
|
||||
auth_keytab: str | None = None
|
||||
|
||||
@field_validator("master")
|
||||
@classmethod
|
||||
@@ -67,6 +74,15 @@ class Connection(BaseModel):
|
||||
f"or 'local[/N]'; got {v!r}"
|
||||
)
|
||||
|
||||
@field_validator("auth_type")
|
||||
@classmethod
|
||||
def _check_auth_type(cls, v: str) -> str:
|
||||
if v not in {"none", "simple", "basic", "kerberos"}:
|
||||
raise ValueError(
|
||||
f"auth_type must be one of none/simple/basic/kerberos; got {v!r}"
|
||||
)
|
||||
return v
|
||||
|
||||
|
||||
class PendingSubmission(BaseModel):
|
||||
pending_id: str
|
||||
|
||||
Reference in New Issue
Block a user