服务端扩展

配置 Kyuubi 使用自定义认证

师成师成· 更新于 2026-09-29· 阅读 4 分钟· 0 次阅读

登录后可跨设备保存划线和私人笔记登录

除了内置认证方式之外,Kyuubi 还支持基于 org.apache.kyuubi.service.authentication.PasswdAuthenticationProvider 的自定义认证实现。

package org.apache.kyuubi.service.authentication

import javax.security.sasl.AuthenticationException

trait PasswdAuthenticationProvider {

  /**
   * The authenticate method is called by the Kyuubi Server authentication layer
   * to authenticate users for their requests.
   * If a user is to be granted, return nothing/throw nothing.
   * When a user is to be disallowed, throw an appropriate [[AuthenticationException]].
   *
   * @param user     The username received over the connection request
   * @param password The password received over the connection request
   *
   * @throws AuthenticationException When a user is found to be invalid by the implementation
   */
  @throws[AuthenticationException]
  def authenticate(user: String, password: String): Unit
}

构建自定义认证器

要创建继承自上述接口的自定义 Authenticator 类,我们需要:

  • 引用相应的库
<dependency>
   <groupId>org.apache.kyuubi</groupId>
   <artifactId>kyuubi-common_2.12</artifactId>
   <version>1.9.1</version>
   <scope>provided</scope>
</dependency>

启用自定义认证

要启用自定义认证方式,我们需要

  • 将 jar 包放入 $KYUUBI_HOME/jars 目录,使其对 Kyuubi 服务器的类路径可见。
  • 在每个安装了 Kyuubi 服务器的节点上,将以下配置项添加到 $KYUUBI_HOME/conf/kyuubi-defaults.conf 文件中。
kyuubi.authentication=CUSTOM
kyuubi.authentication.custom.class=YourAuthenticationProvider
  • 重启所有 Kyuubi 服务实例

评论

登录后参与评论

正在加载评论…