Behavioral Changes in Spark
Behavioral changes denote a marked change in behavior from the previously released version to this version of Spark.
Cloudera Runtime 7.3.2.20000 SP2
There are no behavioral changes in this release.
Cloudera Runtime 7.3.2.10000 SP1
- CDPD-98799: Rebase on Apache Spark 3.5.8
- Previous behavior:
Bundled Spark in Cloudera Runtime 7.3.2.0 was based on Apache Spark 3.5.4.
When you enable Encrypt all ports in Cloudera Manager, Cloudera Manager applies the Spark property changes in this section automatically. For an overview, see Encryption in transit for Spark and Livy in Cloudera Runtime 7.3.2.10000 SP1.
- OPSAPS-76333: Spark authentication and network encryption when Encrypt all ports is enabled
- Previous behavior:
spark.authenticateandspark.network.crypto.enabledwere not enabled automatically when you turned on cluster-wide port encryption. - OPSAPS-75940: Spark IO encryption key size and algorithm defaults in Cloudera Manager
- Previous behavior:
Cloudera Manager exposed
spark.io.encryption.keySizeBitswith a default of 128 and did not surfacespark.io.encryption.keygen.algorithmon the Spark configuration page. - CDPD-94374, OPSAPS-75458: HTTPS-only Spark History Server and Spark UI when Encrypt all ports is enabled
- Previous behavior:
When TLS was enabled, Jetty could still bind an HTTP port for the History Server or Spark UI unless you configured HTTPS-only listeners manually.
- CDPD-87464, OPSAPS-76633:
spark.cloudera.auto.disable.insecure.spark.ui.enabled - Previous behavior:
The Spark UI could start without SSL even when insecure UI access was not intended.
- CDPD-87464, OPSAPS-76633: YARN auto-certificate for Spark UI in cluster mode
- Previous behavior:
Spark did not use YARN ResourceManager ApplicationMaster certificates for the Spark UI in cluster mode unless you configured certificate policy manually.
- Summary: Default JVM trust store password for BCFKS
cacerts - Previous behavior:
Spark did not set
javax.net.ssl.trustStorePasswordwhen the JVM default trust store was BCFKS, which could cause Spark History Server or jobs to fail on FIPS 140-3 clusters.
Cloudera Runtime 7.3.2.100 CHF 1
There are no behavioral changes in this release.
Cloudera Runtime 7.3.2
Cloudera Runtime 7.3.2 introduces functional adjustments, behavioral updates for Spark, and includes all service packs and cumulative hotfixes from 7.3.1.100 through 7.3.1.706. For a comprehensive record of all functional adjustments in Cloudera Runtime 7.3.1.x, see Spark Behavioral Changes.
- Summary: Enhanced the security of Spark by implementing new default configuration settings
- Previous behavior:
spark.ui.enabled=true: possible initiation of an HTTP service that can be accessed from external hosts.spark.io.encryption.keySizeBits=128: the default Spark keySizeBits
