In T212259 we verified that critical things like oozie, camus and hue could work with Kerberos authentication. This task is meant to track the work to find the configurations needed by the following tools to work with Kerberos:
* Druid (namely authentication to HDFS)
* Hue (should be done, but we'd need to verify all use cases from our users)
* Puppet alarms that require authentication with Hadoop (for example, force the standby namenode to fetch the current image from the master, nagios checks, etc..)
* Beeline (that will replace Hive, not compatible with Kerberos)
* Spark
* Hcatalog actions used by the Search team (see T225310)
* /mnt/hdfs (https://github.com/EDS-APHP/py-hdfs-mount)
* geoip::data::archive cron (user is root, probably will need to be changed)
* labstore100[6,7] rsyncs
At the end of this task, ideally we should be able to say "we are ready to enable kerberos auth on the Analytics Hadoop cluster".