On the dev meetup notes in Shenzhen after HBaseCon Asia, there is a topic about the permission to read hfiles on HDFS directly.
For client-side scanner going against hfiles directly; is there a means of being able to pass the permissions from hbase to hdfs?
And at Xiaomi we also face the same problem. SnapshotScanner is much faster and consumes less resources, but only super use has the ability to read hfile directly on HDFS.
So here we want to use HDFS ACL to address this problem.
The basic idea is to set acl and default acl on the ns/table/cf directory on HDFS for the users who have the permission to read the table on HBase.
Suggestions are welcomed.