Go to file
Josh Elser 5fc1141f63 HBASE-17115 Define UI admins via an ACL
The Hadoop AccessControlList allows us to specify admins of the webUI
via a list of users and/or groups. Admins of the WebUI can mutate the
system, potentially seeing sensitive data or modifying the system.

hbase.security.authentication.spnego.admin.users is a comma-separated
list of users who are admins.
hbase.security.authentication.spnego.admin.groups is a comma-separated
list of groups whose membership are admins. Either of these
configuration properties may also contain an asterisk (*) which denotes
"any entity" (e.g user, group).

Previously, when a user was denied from some endpoint that was
designated for admins, they received an HTTP/401. In this case, it is
more correct to return HTTP/403 as they were correctly authenticated,
but they were disallowed from fetching the given resource. This commit
incorporates this change.

hbase.security.authentication.ui.config.protected also exists for users
who have sensitive information stored in the Hadoop service
configuration and want to limit access to this endpoint. By default,
the Hadoop configuration endpoint is not protected and any
authenticated user can access it.

The test is based off of work by Nihal Jain in HBASE-20472.

Co-authored-by: Nihal Jain <nihaljain.cs@gmail.com>
Signed-off-by: Sean Busbey <busbey@apache.org>
2020-01-29 16:45:25 -05:00
.idea HBASE-23707 Add IntelliJ check style plugin configuration (#1064) (#1092) 2020-01-27 10:45:27 -08:00
bin HBASE-23165 [hbtop] Some modifications from HBASE-22988 (#987) 2020-01-11 21:22:14 +09:00
conf HBASE-23165 [hbtop] Some modifications from HBASE-22988 (#987) 2020-01-11 21:22:14 +09:00
dev-support HBASE-23347 Allow custom authentication methods for RPCs 2020-01-16 11:04:08 -05:00
hbase-annotations HBASE-22572 Javadoc Warnings: @link reference not found (#306) 2019-07-01 21:18:11 -07:00
hbase-archetypes HBASE-22449 https everywhere in Maven metadata (#247) 2019-05-21 12:38:42 -07:00
hbase-assembly HBASE-23156 start-hbase.sh failed with ClassNotFoundException when build with hadoop3 (#1067) 2020-01-20 13:24:27 +08:00
hbase-build-configuration HBASE-23675 Move to Apache parent POM version 22 2020-01-11 11:19:24 +01:00
hbase-checkstyle HBASE-23686 Revert binary incompatible change in ByteRangeUtils and removed reflections in CommonFSUtils 2020-01-24 20:28:01 +01:00
hbase-client HBASE-23753 Update of errorprone generated failures 2020-01-28 17:01:30 -08:00
hbase-common Revert "Revert "HBASE-23705 Add CellComparator to HFileContext (#1062)"" 2020-01-27 07:40:56 -08:00
hbase-endpoint HBASE-22572 Javadoc Warnings: @link reference not found (#306) 2019-07-01 21:18:11 -07:00
hbase-examples HBASE-23347 Allow custom authentication methods for RPCs 2020-01-16 11:04:08 -05:00
hbase-external-blockcache HBASE-22463 Some paths in HFileScannerImpl did not consider block#release which will exhaust the ByteBuffAllocator (#257) 2019-06-25 22:17:07 +08:00
hbase-hadoop-compat HBASE-23590 : Update maxStoreFileRefCount to maxCompactedStoreFileRefCount for auto region recovery based on old reader references 2020-01-01 22:50:37 +05:30
hbase-hadoop2-compat HBASE-23590 : Update maxStoreFileRefCount to maxCompactedStoreFileRefCount for auto region recovery based on old reader references 2020-01-01 22:50:37 +05:30
hbase-hbtop HBASE-23165 [hbtop] Some modifications from HBASE-22988 (#987) 2020-01-11 21:22:14 +09:00
hbase-http HBASE-17115 Define UI admins via an ACL 2020-01-29 16:45:25 -05:00
hbase-it HBASE-23566: Fix package/packet terminology problem in chaos monkeys (#933) 2019-12-12 16:34:31 -06:00
hbase-mapreduce Revert "Revert "HBASE-23705 Add CellComparator to HFileContext (#1062)"" 2020-01-27 07:40:56 -08:00
hbase-metrics HBASE-23245 : MutableHistogram constructor changes and provide HistogramImpl maxExpected as long (#787) 2019-11-12 01:03:32 +08:00
hbase-metrics-api HBASE-22449 https everywhere in Maven metadata (#247) 2019-05-21 12:38:42 -07:00
hbase-procedure HBASE-23727 Port HBASE-20981 in 2.2 & 2.3 2020-01-24 10:59:02 -08:00
hbase-protocol HBASE-23590 : Update maxStoreFileRefCount to maxCompactedStoreFileRefCount for auto region recovery based on old reader references 2020-01-01 22:50:37 +05:30
hbase-protocol-shaded HBASE-23304: RPCs needed for client meta information lookup (apache#904) (#1098) 2020-01-28 16:45:49 -08:00
hbase-replication HBASE-23642 Reintroduce ReplicationUtils.contains as deprecated (#983) 2020-01-04 12:14:19 +01:00
hbase-resource-bundle HBASE-22954 Update license for net.java.dev.jna. 2019-09-03 12:55:30 -05:00
hbase-rest HBASE-23661 Reduced number of Checkstyle violations in hbase-rest 2020-01-19 18:17:14 +01:00
hbase-rsgroup HBASE-23729 [Flakeys] TestRSGroupsBasics#testClearNotProcessedDeadServer fails most of the time 2020-01-23 16:44:49 -08:00
hbase-server HBASE-17115 Define UI admins via an ACL 2020-01-29 16:45:25 -05:00
hbase-shaded HBASE-22927 Upgrade Mockito version for jdk11 - ADDENDUM (#643) 2019-09-19 15:40:15 +02:00
hbase-shell HBASE-23055 Alter hbase:meta (#1043) 2020-01-21 13:17:27 -08:00
hbase-testing-util HBASE-22449 https everywhere in Maven metadata (#247) 2019-05-21 12:38:42 -07:00
hbase-thrift HBASE-23627 Resolved remaining Checkstyle violations in hbase-thrift 2020-01-01 22:56:17 +01:00
hbase-zookeeper HBASE-23304: RPCs needed for client meta information lookup (apache#904) (#1098) 2020-01-28 16:45:49 -08:00
src HBASE-17115 Define UI admins via an ACL 2020-01-29 16:45:25 -05:00
.editorconfig HBASE-23234 Provide .editorconfig based on checkstyle configuration (#846) 2019-11-21 11:23:51 -08:00
.gitattributes HBASE-6816. [WINDOWS] line endings on checkout for .sh files 2013-01-23 19:30:14 +00:00
.gitignore HBASE-22593 Added Jenv file to gitignore (#314) 2019-06-17 10:07:41 +02:00
.pylintrc HBASE-21712 : Make submit-patch.py python3 compatible 2019-01-16 09:28:25 +01:00
.rubocop.yml HBASE-22692 Rubocop definition is not used in the /bin directory 2019-07-24 11:17:28 +02:00
CHANGES.txt HBASE-18548 Move sources of website gen and check jobs into source control 2017-12-19 23:40:46 +08:00
LICENSE.txt HBASE-18548 Move sources of website gen and check jobs into source control 2017-12-19 23:40:46 +08:00
NOTICE.txt HBASE-15666 shaded dependencies for hbase-testing-util 2019-08-07 07:43:44 -07:00
README.txt HBASE-18548 Move sources of website gen and check jobs into source control 2017-12-19 23:40:46 +08:00
pom.xml HBASE-23751 Move core to hbase-thirdparty 3.2.0 2020-01-27 22:08:57 -08:00

README.txt

Apache HBase [1] is an open-source, distributed, versioned, column-oriented
store modeled after Google' Bigtable: A Distributed Storage System for
Structured Data by Chang et al.[2]  Just as Bigtable leverages the distributed
data storage provided by the Google File System, HBase provides Bigtable-like
capabilities on top of Apache Hadoop [3].

To get started using HBase, the full documentation for this release can be
found under the doc/ directory that accompanies this README.  Using a browser,
open the docs/index.html to view the project home page (or browse to [1]).
The hbase 'book' at http://hbase.apache.org/book.html has a 'quick start'
section and is where you should being your exploration of the hbase project.

The latest HBase can be downloaded from an Apache Mirror [4].

The source code can be found at [5]

The HBase issue tracker is at [6]

Apache HBase is made available under the Apache License, version 2.0 [7]

The HBase mailing lists and archives are listed here [8].

The HBase distribution includes cryptographic software. See the export control
notice here [9].

1. http://hbase.apache.org
2. http://research.google.com/archive/bigtable.html
3. http://hadoop.apache.org
4. http://www.apache.org/dyn/closer.cgi/hbase/
5. https://hbase.apache.org/source-repository.html
6. https://hbase.apache.org/issue-tracking.html
7. http://hbase.apache.org/license.html
8. http://hbase.apache.org/mail-lists.html
9. https://hbase.apache.org/export_control.html