This doc describes how to set up a Kerberos Key Distribution Center (KDC) and a SPNEGO/Kerberos-authenticated web application on an Amazon Linux 2023 EC2 instance, and how to configure the synthetics job manager (SJM) to run monitors with Kerberos authentication support.
Placeholder values
Before you begin, identify the following values for your environment. Replace each placeholder with your own value wherever it appears in this doc.
Placeholder
Description
Example
<REALM_NAME>
Kerberos realm (must be uppercase)
KERBTEST.LOCAL
<EC2_PRIVATE_IP>
Private IPv4 address of the EC2 instance
10.8.9.172
<EC2_INTERNAL_HOSTNAME>
Fully qualified domain name (FQDN) of the web app
ip-X-X-X-X.ec2.internal
<CLIENT_PRINCIPAL>
Kerberos identity assigned to synthetics workers
synthetics-test
<CLIENT_KEYTAB_PATH>
Full path on the host where the client keytab is stored
/home/ec2-user/kerb-test/synthetics-test.keytab
<PRIVATE_LOCATION_KEY>
New Relic private location key
NRSP-us...
Part 1: Set up the host environment
Install the Kerberos KDC server and administration tools on the host EC2 instance:
bash
$
sudo dnf install-y krb5-server krb5-workstation
Configure /etc/krb5.conf to direct realm requests to your KDC:
bash
$
sudotee /etc/krb5.conf > /dev/null <<'EOF'
$
[libdefaults]
$
default_realm = <REALM_NAME>
$
dns_lookup_realm = false
$
dns_lookup_kdc = false
$
rdns = false
$
$
[realms]
$
<REALM_NAME> = {
$
kdc = <EC2_PRIVATE_IP>
$
admin_server = <EC2_PRIVATE_IP>
$
}
$
$
[domain_realm]
$
<EC2_INTERNAL_HOSTNAME> = <REALM_NAME>
$
EOF
Define the port and encryption rules for the KDC service:
Generate keytab files holding non-interactive credentials for both the client (synthetics worker) and the target web server service principal name (SPN):
bash
$
mkdir-p /home/ec2-user/kerb-test
$
$
# 1. Create client principal & keytab for synthetics runners
A successful test responds with HTTP/1.1 200 OK and displays the protected web page content.
Part 2: Configure the synthetics job manager for Kerberos
To allow synthetics browser runner containers to automatically resolve the KDC, acquire Kerberos tickets, and authenticate against protected endpoints, add the following Kerberos environment variables and volume mounts to your standard SJM docker run command.
Standard command (without Kerberos)
bash
$
docker run -ePRIVATE_LOCATION_KEY=<PRIVATE_LOCATION_KEY>\
>
-d--restart unless-stopped \
>
-v /var/run/docker.sock:/var/run/docker.sock:rw \
>
newrelic/synthetics-job-manager
Required command (with Kerberos support enabled)
Add the following environment variables (-e) and keytab volume mount (-v) to your docker run command: