diff --git a/docs/security/index.md b/docs/security/index.md index eca34161887..0c85c499164 100644 --- a/docs/security/index.md +++ b/docs/security/index.md @@ -25,6 +25,7 @@ and encryption, etc. Authentication Authorization +Session Configuration kinit hadoop_credentials_manager internal_secure_access diff --git a/docs/security/session_configuration.md b/docs/security/session_configuration.md new file mode 100644 index 00000000000..b61f71b759d --- /dev/null +++ b/docs/security/session_configuration.md @@ -0,0 +1,40 @@ + + +# Protect Session Configurations + +For a multi-tenant deployment, configure at least one of +`kyuubi.session.conf.ignore.list` or `kyuubi.session.conf.restrict.list`. Both +lists are empty by default, so clients can otherwise override sensitive +session-level configurations during engine bootstrap and connection setup. + +One conservative starting point is: + +```properties +kyuubi.session.conf.ignore.list=spark.driver.memory,spark.executor.memory +kyuubi.session.conf.restrict.list=kyuubi.session.engine.spark.main.resource,kyuubi.engine.share.level,spark.master,spark.submit.deployMode,spark.sql.extensions,spark.sql.optimizer.excludedRules +``` + +This example is not comprehensive. Tailor both lists to the deployment. The +ignore list silently drops matching client values, while the restrict list +rejects the connection. Some settings are static or consumed during engine +startup and therefore cannot be changed later. For other settings, configure +the engine's operation-level restrictions when changes through `SET` statements +must also be prevented. + +See the [session configuration settings](../configuration/settings.md#session) +for details.