Spark security

When you create an environment in Cloudera Management Console, it automatically creates a Kerberos- and TLS-enabled data lake cluster. Data hub clusters are linked to environments, and therefore also have Kerberos enabled by default. You do not need to do anything to enable Kerberos or TLS for Apache Spark in Cloudera. Disabling security is not supported.

To submit Spark jobs to the cluster, users must authenticate with their Kerberos credentials. For more information, see the Environments documentation.

FIPS 140-3

For Spark 3 and Livy for Spark 3 on FIPS 140-3 clusters, see Spark and Livy on FIPS 140-3 clusters.

Encryption in transit (7.3.2.10000 SP1)

For TLS 1.3, Encrypt all ports, and Spark network encryption in service pack 1, see Encryption in transit for Spark and Livy in Cloudera Runtime 7.3.2.10000 SP1.