Configuring TLS/SSL encryption manually for Flink services

Enable TLS for Flink internal and REST endpoints across the cluster when Cloudera Manager cannot yet generate Flink keystores automatically. Configure central protocol and cipher settings, distribute host keystores, and apply Flink safety-valve properties.

Starting in Cloudera Runtime 7.3.2 SP1 (7.3.2.10000), Cloudera Manager can control TLS protocols and cipher suites for Flink, Cloudera SQL Stream Builder, and Knox Gateway when you enable the CMF_FF_TLS_ADVANCED_CONTROL feature flag. For background on the flag and global TLS settings, see Transport Layer Security Support and Custom Protocol Configuration.

Flink is deployed as a Gateway-type service. Cloudera Manager can auto-generate keystores for Cloudera SQL Stream Builder, but Flink keystore generation in Cloudera Manager is not available in this release. Until that support ships, use this procedure to configure TLS for Flink internal and REST services cluster-wide. For per-job REST TLS when you submit applications, see Securing Flink external REST endpoints with TLS.

  1. Enable advanced TLS control and configure protocol and cipher settings for Flink and Cloudera SQL Stream Builder.
    1. Enable the CMF_FF_TLS_ADVANCED_CONTROL feature flag on the Cloudera Manager Server host, as described in Transport Layer Security Support and Custom Protocol Configuration.
    2. On the Flink and Cloudera SQL Stream Builder service configuration pages in Cloudera Manager, set Supported SSL/TLS versions and TLS Cipher List to match your cluster policy.

    Cloudera Manager writes these values to the corresponding service configuration properties and propagates them into flink-conf.yaml as security.ssl.protocol and security.ssl.algorithms. Flink and Cloudera SQL Stream Builder ports use these settings during the TLS handshake.

  2. Generate a signed keystore for each host that runs Flink containers.

    For each host, create a keystore that meets the following requirements:

    • Sign the certificate with your root CA.
    • Include a Subject Alternative Name (SAN) that lists the hostname, fully qualified domain name (FQDN), and IP addresses used by Flink services on that host.
    • Set Extended Key Usage (EKU) to include both serverAuth and clientAuth.
  3. Distribute the host-specific keystore files to every Flink node.

    Copy each keystore to the same persistent directory path on every host and use the same file name on all nodes. Flink shares a single flink-conf.yaml configuration, so every Flink service on every node must resolve the keystore from an identical path.

  4. Configure Flink to use the distributed keystores for internal and REST TLS.
    1. In Cloudera Manager, open the Flink service Configuration page.
    2. Locate flink-conf/flink-conf.yaml_service_safety_valve and add the following properties. Replace YOUR_KEYSTORE_PASSWORD and YOUR_KEYSTORE_COMMON_PATH with the password and path you used when you distributed the keystores in the previous step. Use the same values on every node.
    3. Read the global truststore path and password from the deployed Flink configuration, for example:
      grep truststore /etc/flink/conf/flink-conf.yaml
    4. Substitute those values for CM_GLOBAL_TRUSTSTORE_PATH and CM_GLOBAL_TRUSTSTORE_PASSWORD in the safety-valve block below.
    security.ssl.rest.enabled: 'true'
    security.ssl.rest.key-password: YOUR_KEYSTORE_PASSWORD
    security.ssl.rest.keystore: YOUR_KEYSTORE_COMMON_PATH
    security.ssl.rest.keystore-password: YOUR_KEYSTORE_PASSWORD
    security.ssl.internal.enabled: 'true'
    security.ssl.internal.key-password: YOUR_KEYSTORE_PASSWORD
    security.ssl.internal.keystore: YOUR_KEYSTORE_COMMON_PATH
    security.ssl.internal.keystore-password: YOUR_KEYSTORE_PASSWORD
    security.ssl.internal.truststore: CM_GLOBAL_TRUSTSTORE_PATH
    security.ssl.internal.truststore-password: CM_GLOBAL_TRUSTSTORE_PASSWORD

    When Cloudera Manager supports automatic Flink keystore generation in a future release, you will not need this manual safety-valve configuration.

  5. Add your root CA certificate to the Cloudera Manager global truststore if it is not already present.
    1. Go to Administration > Security > Update Auto-TLS Truststore.
    2. Leave Certificate Location empty.
    3. Choose Certificate File and upload your root CA certificate from your local machine.
    4. Set Update mode to Append to existing truststore.
    For more information, see Updating the Auto-TLS Global Truststore.
  6. Deploy the client configuration and restart dependent services.
    1. Deploy the client configuration for the cluster.
    2. Restart the following services:
      • Flink
      • YARN
      • Cloudera SQL Stream Builder
      • Knox Gateway
  7. Verify encrypted Flink endpoints.

    Submit or restart Flink jobs and confirm that Flink services expose encrypted internal and REST ports using the TLS settings you configured. Clients must trust the certificates in your distributed keystores and the Cloudera Manager global truststore.

For Flink History Server (global Dashboard) TLS through Cloudera Manager, see Enabling security for Apache Flink.