1. Add public IP of CDP public cloud 7.2.x to etc/hosts file
2. Create HDFS connection shared resource
3. select Connection Type: Gateway
4. Fill in the following connection details:
URL - User can get this details from Data hub cluster
Username - Workload Username
Password - Password for that user
5. Test the shared resource connection.
Note: HDFS is unable to connect to the CDP 7.2.x environment through the Namenode connection type. Since the Templeton API is removed from CDP 7.2.x. CDP public cloud is TLS v1.2 enabled by default.
6. Cloudera CDP public cloud uses Knox gateway for authentication and that implements Kerberos underneath. So if someone uses Knox using the workload username and password, there is no need to provide Kerberos authentication details (Keytab and principal). Please see the below image explanation.
Even if someone implements their own Kerberos on a cluster, they will need to go through Knox gateway. So the verdict is with CDP public cloud there is no need to configure the shared resource with Kerberos.
Please follow the link below for details.
https://docs.cloudera.com/cdp-public-cloud/cloud/security-overview/topics/security-authentication-with-knox.html