apache / apache/kyuubi

[Bug] In the kerberos environment, the flink engine cannot be started, and the message "Delegation token is not supported" is displayed.

Open
#2,249 2 comments 0 reactions 1 assignee Claimed by @SteNicholas View on GitHub
kind:bug priority:major
Dominant language
Scala
Stars
2.4k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

### Code of Conduct

- [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

### Search before asking

- [X] I have searched in the [issues](https://github.com/apache/incubator-kyuubi/issues?q=is%3Aissue) and found no similar issues.

### Describe the bug

In the kerberos environment, the flink engine cannot be started, and the message "Delegation token is not supported" is displayed.

### Affects Version(s)

1.5.0

### Kyuubi Server Log Output

```logtalk
10:11:48.766 WARN org.apache.kyuubi.client.KyuubiSyncThriftClient: TRenewDelegationTokenReq(sessionHandle:TSessionHandle(sessionId:THandleIdentifier(guid:47 F7 06 64 A5 BC 48 3D AA B0 8C 93 C0 91 3F 47, secret:E9 55 2B 1B B3 2E 44 99 BC 27 3C 69 11 D4 26 52)), delegationToken:SERUUwABETEwLjE5LjI5LjE3Mjo4MDIwPQAEb2NkcARvY2RwH3NwYXJrL29jZHAxNzIuYXNpYWlu^M
Zm8uY29tQG9jZHCKAX/Yd/tRigF//IR/UY4N2lEUJ5ccTLbM5cNPwuu6GFWKp5OZluQVSERGU19E^M
RUxFR0FUSU9OX1RPS0VOETEwLjE5LjI5LjE3Mjo4MDIwAA==) failed on engine side
org.apache.kyuubi.KyuubiSQLException: Delegation token is not supported
at org.apache.kyuubi.KyuubiSQLException$.apply(KyuubiSQLException.scala:69) ~[kyuubi-common_2.12-1.5.0-incubating.jar:1.5.0-incubating]
at org.apache.kyuubi.KyuubiSQLException$.apply(KyuubiSQLException.scala:81) ~[kyuubi-common_2.12-1.5.0-incubating.jar:1.5.0-incubating]
at org.apache.kyuubi.client.KyuubiSyncThriftClient.sendCredentials(KyuubiSyncThriftClient.scala:244) ~[kyuubi-server_2.12-1.5.0-incubating.jar:1.5.0-incubating]
```

### Kyuubi Engine Log Output

_No response_

### Kyuubi Server Configurations

```yaml
kyuubi-env.sh:
export JAVA_HOME=/usr/jdk64/jdk1.8.0_271
export HADOOP_CONF_DIR=/etc/hadoop/conf
export FLINK_HOME=/home/jiaoqingbo/flink-1.14.4
export HADOOP_CLASSPATH=`hadoop classpath`

kyuubi-defaults.conf
kyuubi.engine.type FLINK_SQL
kyuubi.authentication KERBEROS
```

### Kyuubi Engine Configurations

_No response_

### Additional context

The default values of kyuubi.credentials.hadoopfs.enabled and kyuubi.credentials.hive.enabled are both true,then LaunchEngine will call renewEngineCredentials() method。
However, FlinkTBinaryFrontendService does not implement the RenewDelegationToken method

### Are you willing to submit PR?

- [ ] Yes I am willing to submit a PR!

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.