Skip to content

HBASE-30130 Add a security-model section to the website#8170

Open
apurtell wants to merge 1 commit intoapache:masterfrom
apurtell:HBASE-30130
Open

HBASE-30130 Add a security-model section to the website#8170
apurtell wants to merge 1 commit intoapache:masterfrom
apurtell:HBASE-30130

Conversation

@apurtell
Copy link
Copy Markdown
Contributor

Add a "Security Model" page to the Apache HBase website, following the ASF Security Team's recommendation for projects to document their security assumptions.

The page defines HBase's trust boundaries, explains that HBase's default unauthenticated configuration is intended only for development and testing, and clarifies security expectations for gateway services, coprocessors, web UIs, and transport encryption. It enumerates what constitutes a valid vulnerability versus what does not, providing clear guidance for operators, security researchers, and the ASF Security Team when triaging incoming reports.

@apurtell apurtell requested a review from PDavid April 29, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant