Repository navigation
Conversation
…ed without SPNEGO Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The documentation misstates SCM authorization behavior and omits OM’s /v2/dbCheckpoint endpoint.
2 open findings
What changed in this PR
Documents SPNEGO requirements and checkpoint endpoint exposure for OM and SCM.
Changes:
- Clarifies HTTP authentication configuration.
- Adds SPNEGO hardening guidance to the threat model.
| File | Description |
|---|---|
THREAT_MODEL.md |
Documents default HTTP authentication and operator hardening. |
hadoop-hdds/common/src/main/resources/ozone-default.xml |
Expands OM and SCM authentication descriptions. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…default behavior in THREAT_MODEL.md Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
smengcl
marked this pull request as ready for review
October 7, 2026 18:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Generated-by: Claude Code (Opus 5.5)
What changes were proposed in this pull request?
The OM and SCM web servers authenticate requests only when HTTP Kerberos (SPNEGO) is enabled. It is off by default, also when
ozone.security.enabled=true. The admin check of the DB checkpoint endpoints (OM/dbCheckpointand/v2/dbCheckpoint, SCM/dbCheckpoint) needs an authenticated caller, so it is applied only with SPNEGO. Neither the docs nor the config descriptions say so.Documentation only, no behavior change:
ozone-default.xml: the descriptions ofozone.om.http.auth.typeandhdds.scm.http.auth.typenow say thatkerberostakes effect only whenozone.security.http.kerberos.enabledis true, and that withsimplethe admin check of/dbCheckpointis not applied.THREAT_MODEL.md: HTTP authentication is added to the controls that are off by default (section 5a) and to the operator hardening checklist (section 10).The website page is updated in apache/ozone-site#567.
What is the link to the Apache JIRA
https://issues.apache.org/jira/browse/HDDS-16759
How was this patch tested?
Documentation only. Checked with
xmllintthatozone-default.xmlis still well formed.🤖 Generated with Claude Code