Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-13780

Default to 700 for HDFS root dir permissions for secure deployments

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      Secure mode deployments should protect the files under HDFS root dir. We should check and set the root dirs permissions on a kerberos setup so that users does not have to.

      We have hbase.data.umask.enable and hbase.data.umask for data files, but those are not that useful since we should protect dir listing, and access to WAL files, snapshot files, etc.

      See HBASE-13768 which has an integration test for this.

      Attachments

        1. HBASE-13780-0.98.patch
          10 kB
          Andrew Kyle Purtell
        2. hbase-13780_v1.patch
          9 kB
          Enis Soztutar

        Activity

          People

            enis Enis Soztutar
            enis Enis Soztutar
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: