Securing Flink external REST endpoints with TLS
Configure TLS for Flink external REST endpoints when clients connect directly to the Flink REST API or web dashboard. Internal RPC and data transport traffic uses separate security.ssl.internal.* settings.
Flink exposes two classes of TLS-protected endpoints:
- Internal endpoints — RPC, blob server, and data transport between Flink processes. Configure these with
security.ssl.internal.*properties when you submit jobs. For an example, see Securing Apache Flink jobs. - External REST endpoints — the REST API and web dashboard that operators and clients reach from outside the Flink process. Configure these with
security.ssl.rest.*properties.
On a Kerberos-enabled cluster, the YARN proxy or Knox Gateway typically fronts the Flink dashboard. If you disable direct external access, you might not need explicit REST TLS on every job. Enable REST TLS when users, monitoring tools, or automation connect directly to the JobManager REST port or TaskManager REST endpoints.
For a full secured Flink deployment walkthrough, see the Flink secure tutorial and Securing Apache Flink jobs.
