18 ms·
I was going to mention the same guide. Not only it has been really helpful but also the Kerberos/Lovecraft analogies are spot on. Also, it has the best introduc
by loopbit 9y ago
I was going to mention the same guide. Not only it has been really helpful but also the Kerberos/Lovecraft analogies are spot on. Also, it has the best introduction I've ever read in a technical manual:
When HP Lovecraft wrote his books about forbidden knowledge which would reduce the reader to insanity, of "Elder Gods" to whom all of humanity were a passing inconvenience, most people assumed that he was making up a fantasy world. In fact he was documenting Kerberos.
What is remarkable is that he did this fifty years before kerberos was developed. This makes him less of an author, instead: a prophet.
What he wrote was true: there are some things humanity was not meant to know. Most people are better off living lives of naive innocence, never having to see an error message about SASL or GSS, never fear building up scripts of incantations to kadmin.local, incantations which you hope to keep evil and chaos away. To never stare in dismay at the code whose true name must never be spoken, but instead it's initials whispered, "UGI". For those of us who have done all this, our lives are forever ruined. From now on we will cherish any interaction with a secure Hadoop cluster —from a client application to HDFS, or application launch on a YARN cluster, and simply viewing a web page in a locked down web UI —all as a miracle against the odds, against the forces of chaos struggling to destroy order. And forever more, we shall fear those voices calling out to us in the night, the machines by our bed talking to us, saying things like "we have an urgent support call related to REST clients on a remote kerberos cluster —can you help?"