Behavioral changes

Learn about the change in certain functionality of Flink and Cloudera SQL Stream Builder that has resulted in a change in behavior from the previously released version of Cloudera Streaming Analytics.

TLS 1.3 for Cloudera Streaming Analytics network endpoints

Cloudera Streaming Analytics services now consume the central TLS cipher and protocol configuration from Cloudera Manager. Streaming Analytics network endpoints are configured by default to allow TLS 1.3 connections only. Clients that attempt to connect with TLS versions earlier than 1.3 are rejected.

Review the global TLS cipher suite settings in Cloudera Manager before upgrading production clusters. For Flink Dashboard and Gateway TLS, see Enabling security for Apache Flink. For external REST endpoint TLS on running jobs, see Securing Flink external REST endpoints with TLS.

project-permissions REST API

The project-permissions REST API now restricts data requests to the user's own user ID or their assigned projects, and the endpoint now returns BasicUserView.

CSA-6280 - Git import review when the remote project does not exist

When you import from Git and the remote project path does not yet exist in the repository, the source control diff API returns all local assets as added. The import review UI uses this result to show what an initial push would contain instead of returning an error.

CSA-5986 - Connector JAR Type validation

When you upload a custom SQL connector JAR, Cloudera SQL Stream Builder validates that the Type value matches a factory identifier declared in the archive. If the Type is incorrect, Cloudera SQL Stream Builder reports the error and lists the factory identifiers available in the JAR. If the JAR does not contain an org.apache.flink.table.factories.Factory implementation, Cloudera SQL Stream Builder reports that the file is not a valid SQL connector archive.

java.io.tmpdir for Cloudera SQL Stream Builder and Flink

Cloudera SQL Stream Builder and Flink processes now use /var/tmp as the value for java.io.tmpdir for internal file operations. On some operating systems, /tmp is mounted with the noexec flag, which prevents JVM processes from executing temporary files there.