feat(yarn_client): auth config for YARN REST (none/simple/basic/kerberos)

Add per-Connection authentication so CDH 5 / Kerberos / HTTP Basic
clusters can be queried.

- auth_type: none / simple / basic / kerberos
- auth_user / auth_password for HTTP Basic
- auth_principal / auth_keytab stored for audit/display; actual SPNEGO
  handled by httpx-kerberos using the system Kerberos credential cache
- YarnClientConfig.auth_for_httpx() returns the right httpx.Auth object
- _request passes auth= through to httpx.request alongside verify=

New dependency: httpx-kerberos.

Tests cover none/simple (no auth object), Basic auth header,
Kerberos auth object, missing basic user, invalid auth_type, and
tool-layer config propagation.
This commit is contained in:
Claude
2026-06-26 13:57:57 +08:00
parent ad557b5984
commit 10f075ab7f
9 changed files with 256 additions and 8 deletions
+23
View File
@@ -81,6 +81,29 @@ def test_save_connection_preserves_ssl_fields(_fresh_store):
assert out["ssl_ca_bundle"] == "/tmp/ca.crt"
def test_save_connection_with_basic_auth(_fresh_store):
connections.save_connection(
name="secure",
master="yarn",
auth_type="basic",
auth_user="hdfs",
auth_password="secret",
)
out = connections.get_connection("secure")
assert out["auth_type"] == "basic"
assert out["auth_user"] == "hdfs"
assert out["auth_password"] == "secret"
def test_save_connection_invalid_auth_type_raises(_fresh_store):
with pytest.raises(ValueError, match="auth_type must be one of none/simple/basic/kerberos"):
connections.save_connection(
name="bad",
master="yarn",
auth_type="oauth",
)
def test_get_connection_unknown_raises(_fresh_store):
with pytest.raises(KeyError):
connections.get_connection("missing")