• /
  • EnglishEspañolFrançais日本語한국어Português
  • ログイン今すぐ開始

Kerberos (SPNEGO) authentication support for private locations

|View as Markdown (English)

This doc describes how to set up a Kerberos Key Distribution Center (KDC) and a SPNEGO/Kerberos-authenticated web application on an Amazon Linux 2023 EC2 instance, and how to configure the synthetics job manager (SJM) to run monitors with Kerberos authentication support.

Placeholder values

Before you begin, identify the following values for your environment. Replace each placeholder with your own value wherever it appears in this doc.

Placeholder

Description

Example

<REALM_NAME>

Kerberos realm (must be uppercase)

KERBTEST.LOCAL

<EC2_PRIVATE_IP>

Private IPv4 address of the EC2 instance

10.8.9.172

<EC2_INTERNAL_HOSTNAME>

Fully qualified domain name (FQDN) of the web app

ip-X-X-X-X.ec2.internal

<CLIENT_PRINCIPAL>

Kerberos identity assigned to synthetics workers

synthetics-test

<CLIENT_KEYTAB_PATH>

Full path on the host where the client keytab is stored

/home/ec2-user/kerb-test/synthetics-test.keytab

<PRIVATE_LOCATION_KEY>

New Relic private location key

NRSP-us...

Part 1: Set up the host environment

Part 2: Configure the synthetics job manager for Kerberos

To allow synthetics browser runner containers to automatically resolve the KDC, acquire Kerberos tickets, and authenticate against protected endpoints, add the following Kerberos environment variables and volume mounts to your standard SJM docker run command.

Standard command (without Kerberos)

bash
$
docker run -e PRIVATE_LOCATION_KEY=<PRIVATE_LOCATION_KEY> \
>
-d --restart unless-stopped \
>
-v /var/run/docker.sock:/var/run/docker.sock:rw \
>
newrelic/synthetics-job-manager

Required command (with Kerberos support enabled)

Add the following environment variables (-e) and keytab volume mount (-v) to your docker run command:

bash
$
docker run -d \
>
--name sjm-container \
>
--restart unless-stopped \
>
-e PRIVATE_LOCATION_KEY=<PRIVATE_LOCATION_KEY> \
>
-e KERBEROS_REALM=<REALM_NAME> \
>
-e KERBEROS_KDC=<EC2_PRIVATE_IP> \
>
-e KERBEROS_HOST_ALLOWLIST=<EC2_INTERNAL_HOSTNAME> \
>
-e KERBEROS_KEYTAB_HOST_PATH=<CLIENT_KEYTAB_PATH> \
>
-e RUNTIME_EXTRA_HOSTS=<EC2_INTERNAL_HOSTNAME>:<EC2_PRIVATE_IP> \
>
-v /var/run/docker.sock:/var/run/docker.sock:rw \
>
-v <CLIENT_KEYTAB_PATH>:<CLIENT_KEYTAB_PATH>:ro \
>
newrelic/synthetics-job-manager
Copyright © 2026 New Relic株式会社。

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.