dask / dask/dask-gateway

Mechanism to mount existing Kubernetes Secret for sensitive auth, e.g. `gateway.auth.kerberos.keytab`?

Open
#417 6 comments 0 reactions 0 assignees View on GitHub
codebase:helm-chart enhancement
Dominant language
Python
Stars
148
Forks
93
PR merge metrics
No merged PRs in 30d

Description

Hey y'all!

I was scoping the possibility of using dask-gateway (via Kubernetes and the daskhub chart) with Google-manged Notebooks on GCP's AI Platform (They're Jupyter notebooks). My idea was to deploy dask-gateway to a GKE cluster on the same network/VPC, with dask-gateway configured for Kerebos authentication.

I noticed that `gateway.auth.kerberos.keytab` takes a path to an existing keytab on the machine. I would have thought that we'd want to mount an existing Kubernetes Secret to a path with the desired permissions...? I was wondering if this is a planned feature or maybe I'm simply going about this the wrong way...?

In general, it looks like a lot of sensitive material is passed in raw through the helm configs, rather than through Kubernetes Secrets?

Thanks so much for your time and consideration! I really appreciate the work on this project.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.