Skip to content

HDDS-16759. Document that DB checkpoint endpoints are not authenticated without SPNEGO - #11439

Open
smengcl wants to merge 2 commits into
apache:masterfrom
smengcl:HDDS-16759
Open

smengcl wants to merge 2 commits into
apache:masterfrom
smengcl:HDDS-16759

Conversation

@smengcl

@smengcl smengcl commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Generated-by: Claude Code (Opus 5.5)

What changes were proposed in this pull request?

The OM and SCM web servers authenticate requests only when HTTP Kerberos (SPNEGO) is enabled. It is off by default, also when ozone.security.enabled=true. The admin check of the DB checkpoint endpoints (OM /dbCheckpoint and /v2/dbCheckpoint, SCM /dbCheckpoint) needs an authenticated caller, so it is applied only with SPNEGO. Neither the docs nor the config descriptions say so.

Documentation only, no behavior change:

  • ozone-default.xml: the descriptions of ozone.om.http.auth.type and hdds.scm.http.auth.type now say that kerberos takes effect only when ozone.security.http.kerberos.enabled is true, and that with simple the admin check of /dbCheckpoint is not applied.
  • THREAT_MODEL.md: HTTP authentication is added to the controls that are off by default (section 5a) and to the operator hardening checklist (section 10).

The website page is updated in apache/ozone-site#567.

What is the link to the Apache JIRA

https://issues.apache.org/jira/browse/HDDS-16759

How was this patch tested?

Documentation only. Checked with xmllint that ozone-default.xml is still well formed.

🤖 Generated with Claude Code

…ed without SPNEGO

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The documentation misstates SCM authorization behavior and omits OM’s /v2/dbCheckpoint endpoint.

2 open findings
What changed in this PR

Documents SPNEGO requirements and checkpoint endpoint exposure for OM and SCM.

Changes:

  • Clarifies HTTP authentication configuration.
  • Adds SPNEGO hardening guidance to the threat model.
File Description
THREAT_MODEL.md Documents default HTTP authentication and operator hardening.
hadoop-hdds/​common/​src/​main/​resources/​ozone-default.xml Expands OM and SCM authentication descriptions.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread THREAT_MODEL.md Outdated
Comment thread hadoop-hdds/common/src/main/resources/ozone-default.xml Outdated
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Oct 7, 2026
…default behavior in THREAT_MODEL.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@smengcl
smengcl marked this pull request as ready for review October 7, 2026 18:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants