{"repo":"OKDP/okdp-spark-auth-filter","free":true,"listed":false,"github":"https://github.com/OKDP/okdp-spark-auth-filter","clone":"git clone https://github.com/OKDP/okdp-spark-auth-filter.git","description":"Oauth2/OIDC Authentication filter for Apache Spark Apps/History UIs","language":"Java","stars":12,"topics":["apache-spark","docker","k8s-spark","kubernetes","oauth2","spark-kubernetes","openid-connect","oidc-client"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"OKDP Spark Auth Filter OAuth2/OpenID Connect authentication and authorization for Apache Spark Web UIs and the Spark History Server. It is a lightweight Java servlet filter you drop into the Spark classpath: it authenticates users against any standard OAuth2/OIDC provider using the Authorization Code flow (with PKCE), and optionally maps their email, groups and roles onto native Spark ACLs, without deploying any extra component in front of Spark. Why this project Apache Spark Web UIs and the Spark History Server expose detailed information about jobs, environment and logs, but their built-in access control is limited: Spark provides the servlet-filter hook ( spark.ui.filters ) and the ACL settings, but ships no ready-to-use OAuth2/OIDC filter. Securing the UIs therefore usually means writing a custom filter or putting a separate reverse-proxy / identity-aware proxy in front of every UI. As part of the OKDP (Open Kubernetes Data Platform) ecosystem, this project fills that gap by providing: - A turnkey OAuth2/OIDC authentication filter that works with any standard-compliant provider, with no additional infrastructure to deploy. - An optional authorization layer that translates the identity claims returned by the provider (email, groups, roles) into the native Spark ACLs Spark already understands, so existing spark. .acls settings keep working. What the project does - Intercepts requests to the Spark UI / History UI and runs the OAuth2/OIDC Authorization Code flow when a reques","default_branch":null,"files":null,"tree":[],"storefront":"/r/OKDP","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/OKDP/okdp-spark-auth-filter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}