Configure Livy on Kerberos

This topic describes how to configure Livy on Kerberos.

To configure Livy on Kerberos, add the following properties to the livy.conf file:
livy.server.auth.type = kerberos
livy.server.auth.kerberos.principal = HTTP/_HOST@HADOOP.LOCALDOMAIN
livy.server.auth.kerberos.keytab = $KEYTAB
livy.server.launch.kerberos.principal = $USER/_HOST@HADOOP.LOCALDOMAIN
livy.server.launch.kerberos.keytab = $KEYTAB  
For example:
livy.server.auth.type = kerberos
livy.server.auth.kerberos.principal = HTTP/node2.cluster@NODE1
livy.server.auth.kerberos.keytab = /opt/mapr/conf/mapr.keytab
livy.server.launch.kerberos.principal = mapr/node2.cluster@NODE1
livy.server.launch.kerberos.keytab = /opt/mapr/conf/mapr.keytab

Livy UI on Kerberos

Note: You can login to the Livy UI on a Kerberos setup only using a web browser configured with SPNEGO.

The other option is to configure multiauth authentication on Kerberized configurations to allow you to login to Livy UI not only with SPNEGO/Mapr-Negotiation mechanisms but also with PAM credentials.