Securing Flink external REST endpoints with TLS

Configure TLS for Flink external REST endpoints when clients connect directly to the Flink REST API or web dashboard. Internal RPC and data transport traffic uses separate security.ssl.internal.* settings.

Flink exposes two classes of TLS-protected endpoints:

  • Internal endpoints — RPC, blob server, and data transport between Flink processes. Configure these with security.ssl.internal.* properties when you submit jobs. For an example, see Securing Apache Flink jobs.
  • External REST endpoints — the REST API and web dashboard that operators and clients reach from outside the Flink process. Configure these with security.ssl.rest.* properties.

On a Kerberos-enabled cluster, the YARN proxy or Knox Gateway typically fronts the Flink dashboard. If you disable direct external access, you might not need explicit REST TLS on every job. Enable REST TLS when users, monitoring tools, or automation connect directly to the JobManager REST port or TaskManager REST endpoints.

  1. Enable REST TLS on the Flink cluster or job submission.

    Set the following Flink configuration properties on the JobManager and TaskManagers. You can pass them with -yD on flink run or in a flink-conf.yaml fragment shipped with the application:

    security.ssl.rest.enabled: true
    security.ssl.rest.keystore: /path/to/rest-keystore.jks
    security.ssl.rest.keystore-password: <password>
    security.ssl.rest.key-password: <password>
    security.ssl.rest.truststore: /path/to/rest-truststore.jks
    security.ssl.rest.truststore-password: <password>

    Optional properties include security.ssl.rest.keystore-type, security.ssl.rest.truststore-type, security.ssl.rest.authentication-enabled for mutual TLS, and security.ssl.rest.cert.fingerprint to pin the REST certificate.

  2. Align TLS protocol settings with your cluster policy.

    Cloudera Streaming Analytics services honor the central TLS protocol and cipher settings from Cloudera Manager. The Flink security.ssl.protocol property accepts a comma-separated list such as TLSv1.3. Ensure client libraries and browsers support the configured protocol.

  3. Distribute keystore and truststore files to hosts that run Flink containers.

    Ship keystores with -yt on flink run or place them on a path accessible to YARN containers, similar to internal TLS setup in Securing Apache Flink jobs.

  4. Verify REST connectivity over HTTPS.

    Confirm that the Flink dashboard and REST API respond on the HTTPS port and that clients trust the REST certificate. If you access Flink through Knox Gateway, configure Knox Gateway to trust the Flink REST certificate or terminate TLS at the gateway.

For a full secured Flink deployment walkthrough, see the Flink secure tutorial and Securing Apache Flink jobs.