Skip to content

ci: test Kerberos authenticator without Hadoop (fork CI verification) - #1

Closed
GorML wants to merge 1 commit into
mainfrom
kerberos-ci
Closed

ci: test Kerberos authenticator without Hadoop (fork CI verification)#1
GorML wants to merge 1 commit into
mainfrom
kerberos-ci

Conversation

@GorML

@GorML GorML commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Self-PR inside the fork to exercise the pull_request workflow before opening the upstream PR for dask#924.

The Kerberos authenticator test was gated on the Hadoop/YARN CI
environment removed in dask#923 and has been skipped ever since. Recreate
the coverage with a self-contained setup: an ephemeral MIT Kerberos
realm managed by k5test directly on the runner, exercising the real
client/server SPNEGO handshake against the existing authenticator code.

- tests/test_auth.py: gate the test on TEST_DASK_GATEWAY_KERBEROS and
  create the realm, HTTP service principal, and keytab in a fixture
  instead of relying on the Hadoop container's KDC
- .github/workflows/test.yaml: add a kerberos-tests job
- tests/requirements.txt: update the Kerberos testing docs
@GorML

GorML commented Jul 20, 2026

Copy link
Copy Markdown
Owner Author

CI verification done — kerberos job green 3/3. Superseded by the upstream PR dask#941.

@GorML GorML closed this Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant