[ 
https://issues.apache.org/jira/browse/SPARK-5159?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15884979#comment-15884979
 ] 

Mridul Muralidharan commented on SPARK-5159:
--------------------------------------------


For 1.6.x and earlier, we found that doAs support did not work for spark thrift 
server - I have not tested it for spark 2.x though.
What is broken :

* All jobs executed as "hive" user - there is no enforcement of impersonated 
user.
** As queries are run as the hive user, read access for hive user is enforced.
** Output generated (tables created, etc) as hive user.
* Data cached is shared across all queries - essentially available across users.

In a nutshell, impersonation does not work.


> Thrift server does not respect hive.server2.enable.doAs=true
> ------------------------------------------------------------
>
>                 Key: SPARK-5159
>                 URL: https://issues.apache.org/jira/browse/SPARK-5159
>             Project: Spark
>          Issue Type: Bug
>          Components: SQL
>    Affects Versions: 1.2.0
>            Reporter: Andrew Ray
>         Attachments: spark_thrift_server_log.txt
>
>
> I'm currently testing the spark sql thrift server on a kerberos secured 
> cluster in YARN mode. Currently any user can access any table regardless of 
> HDFS permissions as all data is read as the hive user. In HiveServer2 the 
> property hive.server2.enable.doAs=true causes all access to be done as the 
> submitting user. We should do the same.



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to