Enabling security for Apache Flink
Since Flink is essentially just a YARN application, you mainly need to configure service level security settings for the Flink Dashboard and Gateway in Cloudera Manager. You can configure security during the installation or later in the Configuration menu for Flink.
Kerberos
Kerberos authentication can be enabled for Flink by simply checking the corresponding checkbox in the service wizard while adding the service or later in the service configuration page in Cloudera Manager. The service wizard in Cloudera Manager enables the Kerberos service, and no further action is required to be able to use the authentication with Flink.
For more information about enabling Kerberos authentication using the service wizard, see Enabling Kerberos Authentication for Cloudera.
TLS encryption
If AutoTLS is enabled on the cluster, the TLS-related configuration fields can be auto-populated
for the Flink History Server (global Flink Dashboard). Flink is deployed as a Gateway-type service, so Cloudera Manager does not create keystores for Flink internal or REST endpoints. You can set {{CM_AUTO_TLS}} as the value for Dashboard and Gateway security properties when using AutoTLS in Cloudera Manager. Configure internal and REST TLS for running Flink jobs separately. If AutoTLS is not used, the settings have to be configured manually.
- Generate TLS certificates
- Configure TLS for Admin Console and Agents
- Enable server certificate verification on Agents
- Configure agent certificate authentication
- Configure agent certificate authentication
To configure TLS on Flink external REST endpoints for direct client access to running jobs, see Securing Flink external REST endpoints with TLS. To configure TLS for Flink internal and REST services cluster-wide with manually distributed keystores, see Configuring TLS/SSL encryption manually for Flink services.
