blob: 9bdf06006b7a3b37d7e65fd4b3e30bdcd7f82c96 [file]
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="/favicon.ico"/><link rel="preload" as="font" href="/fonts/inter-latin-wght-normal.woff2" type="font/woff2" crossorigin="anonymous"/><link rel="prefetch" as="font" href="/fonts/inter-latin-wght-italic.woff2" type="font/woff2" crossorigin="anonymous"/><link rel="modulepreload" href="/assets/manifest-baf72bfa.js"/><link rel="modulepreload" href="/assets/entry.client-Bi9_frb9.js"/><link rel="modulepreload" href="/assets/chunk-QUQL4437-Bywy9pC_.js"/><link rel="modulepreload" href="/assets/index-CEjmR4aq.js"/><link rel="modulepreload" href="/assets/root-COkOICkm.js"/><link rel="modulepreload" href="/assets/theme-provider-CTLTtVKS.js"/><link rel="modulepreload" href="/assets/button-CZBw5Jwh.js"/><link rel="modulepreload" href="/assets/index-jbG8BFt3.js"/><link rel="modulepreload" href="/assets/utils-Cu_tFavh.js"/><link rel="modulepreload" href="/assets/docs-layout-5T1N7EZh.js"/><link rel="modulepreload" href="/assets/docs-layout-S669zXZ_.js"/><link rel="modulepreload" href="/assets/index-DWtaWGM5.js"/><link rel="modulepreload" href="/assets/index-DmTM9tZB.js"/><link rel="modulepreload" href="/assets/Combination-DE73542n.js"/><link rel="modulepreload" href="/assets/docs-DMCF1KDd.js"/><link rel="modulepreload" href="/assets/mdx-oaHE65CA.js"/><link rel="modulepreload" href="/assets/collapsible-DaM-YS37.js"/><link rel="modulepreload" href="/assets/external-link-5ojQeAUO.js"/><link rel="modulepreload" href="/assets/createLucideIcon-DJDbJL17.js"/><link rel="modulepreload" href="/assets/link-CC6yoZ4C.js"/><title>Secure Client Access to Apache HBase</title><meta name="description" content="Configuring Kerberos-based secure authentication for HBase clients, including server and client setup procedures."/><link rel="stylesheet" href="/assets/root-BtA_CDVx.css"/><link rel="stylesheet" href="/assets/app-DeiyQBOk.css"/><script>
(function() {
const theme = localStorage.getItem('theme');
const root = document.documentElement;
root.classList.remove('light', 'dark');
if (theme && ['light', 'dark'].includes(theme)) {
root.classList.add(theme);
} else {
const systemTheme = window.matchMedia('(prefers-color-scheme: dark)').matches ? 'dark' : 'light';
root.classList.add(systemTheme);
localStorage.setItem('theme', systemTheme);
}
})();
</script><noscript><style>.theme-toggle-wrapper { display: none !important; }</style></noscript></head><body class="font-base"><script>((e,i,s,u,m,a,l,h)=>{let d=document.documentElement,w=["light","dark"];function p(n){(Array.isArray(e)?e:[e]).forEach(y=>{let k=y==="class",S=k&&a?m.map(f=>a[f]||f):m;k?(d.classList.remove(...S),d.classList.add(a&&a[n]?a[n]:n)):d.setAttribute(y,n)}),R(n)}function R(n){h&&w.includes(n)&&(d.style.colorScheme=n)}function c(){return window.matchMedia("(prefers-color-scheme: dark)").matches?"dark":"light"}if(u)p(u);else try{let n=localStorage.getItem(i)||s,y=l&&n==="system"?c():n;p(y)}catch(n){}})("class","theme","system",null,["light","dark"],null,true,true)</script><div id="nd-docs-layout" class="grid min-h-(--fd-docs-height) auto-cols-auto auto-rows-auto overflow-x-clip transition-[grid-template-columns] [--fd-docs-height:100dvh] [--fd-header-height:0px] [--fd-sidebar-width:0px] [--fd-toc-popover-height:0px] [--fd-toc-width:285px] max-xl:[--fd-toc-popover-height:--spacing(10)] max-md:[--fd-header-height:--spacing(14)] md:[--fd-sidebar-width:285px]" data-sidebar-collapsed="false" style="grid-template:&quot;sidebar header toc&quot;
&quot;sidebar toc-popover toc&quot;
&quot;sidebar main toc&quot; 1fr / minmax(var(--fd-sidebar-col), 1fr) minmax(0, calc(var(--fd-layout-width,97rem) - var(--fd-sidebar-width) - var(--fd-toc-width))) minmax(min-content, 1fr);--fd-docs-row-1:var(--fd-banner-height, 0px);--fd-docs-row-2:calc(var(--fd-docs-row-1) + var(--fd-header-height));--fd-docs-row-3:calc(var(--fd-docs-row-2) + var(--fd-toc-popover-height));--fd-sidebar-col:var(--fd-sidebar-width)"><header data-transparent="false" id="nd-subnav" class="data-[transparent=false]:bg-fd-background/80 sticky top-(--fd-docs-row-1) z-30 flex h-(--fd-header-height) items-center border-b ps-4 pe-2.5 backdrop-blur-sm transition-colors [grid-area:header] md:hidden"><a class="inline-flex items-center gap-2.5 font-semibold" href="/" data-discover="true"><div class="flex items-center gap-2"><img src="/favicon.ico" alt="HBase favicon" width="16" height="16"/><p>Apache HBase</p></div></a><div class="flex-1"></div><button type="button" class="inline-flex items-center cursor-pointer justify-center gap-2 whitespace-nowrap rounded-md text-sm font-medium transition-all disabled:pointer-events-none disabled:opacity-50 [&amp;_svg]:pointer-events-none [&amp;_svg:not([class*=&#x27;size-&#x27;])]:size-4 shrink-0 [&amp;_svg]:shrink-0 outline-none focus-visible:border-ring focus-visible:ring-ring/50 focus-visible:ring-[3px] aria-invalid:ring-destructive/20 hover:bg-accent hover:text-accent-foreground size-8 p-2" data-search="" aria-label="Open Search"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-search"><circle cx="11" cy="11" r="8"></circle><path d="m21 21-4.3-4.3"></path></svg></button><button aria-label="Open Sidebar" class="inline-flex items-center cursor-pointer justify-center gap-2 whitespace-nowrap rounded-md text-sm font-medium transition-all disabled:pointer-events-none disabled:opacity-50 [&amp;_svg]:pointer-events-none [&amp;_svg:not([class*=&#x27;size-&#x27;])]:size-4 shrink-0 [&amp;_svg]:shrink-0 outline-none focus-visible:border-ring focus-visible:ring-ring/50 focus-visible:ring-[3px] aria-invalid:ring-destructive/20 hover:bg-accent hover:text-accent-foreground size-8 p-2"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-panel-left"><rect width="18" height="18" x="3" y="3" rx="2"></rect><path d="M9 3v18"></path></svg></button></header><div data-sidebar-placeholder="" class="pointer-events-none sticky top-(--fd-docs-row-1) z-20 h-[calc(var(--fd-docs-height)-var(--fd-docs-row-1))] [grid-area:sidebar] *:pointer-events-auto max-md:hidden"><aside id="nd-sidebar" data-collapsed="false" data-hovered="false" class="bg-fd-card absolute inset-y-0 start-0 flex flex-col items-end border-e text-sm duration-250 *:w-(--fd-sidebar-width)"><div class="flex flex-col gap-3 p-4 pb-2"><div class="flex"><a class="inline-flex text-[0.9375rem] items-center gap-2.5 font-medium me-auto" href="/" data-discover="true"><div class="flex items-center gap-2"><img src="/favicon.ico" alt="HBase favicon" width="16" height="16"/><p>Apache HBase</p></div></a><button type="button" aria-label="Collapse Sidebar" data-collapsed="false" class="inline-flex items-center cursor-pointer justify-center gap-2 whitespace-nowrap rounded-md text-sm font-medium transition-all disabled:pointer-events-none disabled:opacity-50 [&amp;_svg]:pointer-events-none [&amp;_svg:not([class*=&#x27;size-&#x27;])]:size-4 shrink-0 [&amp;_svg]:shrink-0 outline-none focus-visible:border-ring focus-visible:ring-ring/50 focus-visible:ring-[3px] aria-invalid:ring-destructive/20 hover:bg-accent hover:text-accent-foreground size-8 text-fd-muted-foreground mb-auto"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-panel-left"><rect width="18" height="18" x="3" y="3" rx="2"></rect><path d="M9 3v18"></path></svg></button></div><button type="button" data-search-full="" class="bg-fd-secondary/50 text-fd-muted-foreground hover:bg-fd-accent hover:text-fd-accent-foreground inline-flex items-center gap-2 rounded-lg border p-1.5 ps-2 text-sm transition-colors"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-search size-4"><circle cx="11" cy="11" r="8"></circle><path d="m21 21-4.3-4.3"></path></svg>Search<div class="ms-auto inline-flex gap-0.5"><kbd class="bg-fd-background rounded-md border px-1.5">⌘</kbd><kbd class="bg-fd-background rounded-md border px-1.5">K</kbd></div></button><button type="button" aria-haspopup="dialog" aria-expanded="false" aria-controls="radix-_R_r5aj5_" data-state="closed" class="bg-fd-secondary/50 text-fd-secondary-foreground hover:bg-fd-accent data-[state=open]:bg-fd-accent data-[state=open]:text-fd-accent-foreground flex items-center gap-2 rounded-lg border p-2 text-start transition-colors"><div class="size-9 shrink-0 empty:hidden md:size-5"></div><div><p class="text-sm font-medium">Multi-Page Documentation</p><p class="text-fd-muted-foreground text-sm empty:hidden md:hidden">Split across multiple pages</p></div><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevrons-up-down text-fd-muted-foreground ms-auto size-4 shrink-0"><path d="m7 15 5 5 5-5"></path><path d="m7 9 5-5 5 5"></path></svg></button></div><div dir="ltr" data-slot="scroll-area" class="relative min-h-0 flex-1" style="position:relative;--radix-scroll-area-corner-width:0px;--radix-scroll-area-corner-height:0px"><style>[data-radix-scroll-area-viewport]{scrollbar-width:none;-ms-overflow-style:none;-webkit-overflow-scrolling:touch;}[data-radix-scroll-area-viewport]::-webkit-scrollbar{display:none}</style><div data-radix-scroll-area-viewport="" data-slot="scroll-area-viewport" class="focus-visible:ring-ring/50 size-full rounded-[inherit] transition-[color,box-shadow] outline-none focus-visible:ring-[3px] focus-visible:outline-1" style="overflow-x:hidden;overflow-y:hidden"><div style="min-width:100%;display:table"><style>[data-radix-scroll-area-viewport]{scrollbar-width:none;-ms-overflow-style:none;-webkit-overflow-scrolling:touch;}[data-radix-scroll-area-viewport]::-webkit-scrollbar{display:none}</style><div data-radix-scroll-area-viewport="" class="overscroll-contain p-4" style="overflow-x:unset;overflow-y:unset;mask-image:linear-gradient(to bottom, transparent, white 12px, white calc(100% - 12px), transparent)"><div style="min-width:100%;display:table"><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Getting Started</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs" data-discover="true">Preface</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/getting-started" data-discover="true">Getting Started</a><a href="/llms-full.txt" rel="noreferrer noopener" target="_blank" data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-external-link"><path d="M15 3h6v6"></path><path d="M10 14 21 3"></path><path d="M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6"></path></svg>All docs for LLMs</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Configuration &amp; Setup</p><div data-state="closed" data-slot="collapsible" class="group"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors w-full" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/configuration" data-discover="true">Configuration<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down ms-auto transition-transform -rotate-90" data-icon="true"><path d="m6 9 6 6 6-6"></path></svg></a><div data-state="closed" id="radix-_R_dad5aj5_" hidden="" data-slot="collapsible-content" class="relative before:bg-fd-border before:absolute before:inset-y-1 before:start-2.5 before:w-px before:content-[&#x27;&#x27;]"></div></div><div data-state="closed" data-slot="collapsible" class="group"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors w-full" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/upgrading" data-discover="true">Upgrading<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down ms-auto transition-transform -rotate-90" data-icon="true"><path d="m6 9 6 6 6-6"></path></svg></a><div data-state="closed" id="radix-_R_fad5aj5_" hidden="" data-slot="collapsible-content" class="relative before:bg-fd-border before:absolute before:inset-y-1 before:start-2.5 before:w-px before:content-[&#x27;&#x27;]"></div></div><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/shell" data-discover="true">The Apache HBase Shell</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Core Concepts</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/datamodel" data-discover="true">Data Model</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/schema-design" data-discover="true">HBase and Schema Design</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/regionserver-sizing" data-discover="true">RegionServer Sizing Rules of Thumb</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/mapreduce" data-discover="true">HBase and MapReduce</a><div data-state="open" data-slot="collapsible" class="group"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors w-full" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/security" data-discover="true">Security<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down ms-auto transition-transform" data-icon="true"><path d="m6 9 6 6 6-6"></path></svg></a><div data-state="open" id="radix-_R_tad5aj5_" data-slot="collapsible-content" class="relative before:bg-fd-border before:absolute before:inset-y-1 before:start-2.5 before:w-px before:content-[&#x27;&#x27;]"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors data-[active=true]:before:content-[&#x27;&#x27;] data-[active=true]:before:bg-fd-primary data-[active=true]:before:absolute data-[active=true]:before:w-px data-[active=true]:before:inset-y-2.5 data-[active=true]:before:start-2.5" style="padding-inline-start:calc(5 * var(--spacing))" href="/docs/security/web-ui" data-discover="true">Web UI Security</a><a data-active="true" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors data-[active=true]:before:content-[&#x27;&#x27;] data-[active=true]:before:bg-fd-primary data-[active=true]:before:absolute data-[active=true]:before:w-px data-[active=true]:before:inset-y-2.5 data-[active=true]:before:start-2.5" style="padding-inline-start:calc(5 * var(--spacing))" href="/docs/security/client-access" data-discover="true">Secure Client Access to Apache HBase</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors data-[active=true]:before:content-[&#x27;&#x27;] data-[active=true]:before:bg-fd-primary data-[active=true]:before:absolute data-[active=true]:before:w-px data-[active=true]:before:inset-y-2.5 data-[active=true]:before:start-2.5" style="padding-inline-start:calc(5 * var(--spacing))" href="/docs/security/user-access" data-discover="true">Simple User Access to Apache HBase</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors data-[active=true]:before:content-[&#x27;&#x27;] data-[active=true]:before:bg-fd-primary data-[active=true]:before:absolute data-[active=true]:before:w-px data-[active=true]:before:inset-y-2.5 data-[active=true]:before:start-2.5" style="padding-inline-start:calc(5 * var(--spacing))" href="/docs/security/tls" data-discover="true">Transport Level Security (TLS) in HBase RPC communication</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors data-[active=true]:before:content-[&#x27;&#x27;] data-[active=true]:before:bg-fd-primary data-[active=true]:before:absolute data-[active=true]:before:w-px data-[active=true]:before:inset-y-2.5 data-[active=true]:before:start-2.5" style="padding-inline-start:calc(5 * var(--spacing))" href="/docs/security/hdfs-and-zookeeper-access" data-discover="true">Securing Access to HDFS and ZooKeeper</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors data-[active=true]:before:content-[&#x27;&#x27;] data-[active=true]:before:bg-fd-primary data-[active=true]:before:absolute data-[active=true]:before:w-px data-[active=true]:before:inset-y-2.5 data-[active=true]:before:start-2.5" style="padding-inline-start:calc(5 * var(--spacing))" href="/docs/security/data-access" data-discover="true">Securing Access To Your Data</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors data-[active=true]:before:content-[&#x27;&#x27;] data-[active=true]:before:bg-fd-primary data-[active=true]:before:absolute data-[active=true]:before:w-px data-[active=true]:before:inset-y-2.5 data-[active=true]:before:start-2.5" style="padding-inline-start:calc(5 * var(--spacing))" href="/docs/security/example" data-discover="true">Security Configuration Example</a></div></div><div data-state="closed" data-slot="collapsible" class="group"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors w-full" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/architecture" data-discover="true">Architecture<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down ms-auto transition-transform -rotate-90" data-icon="true"><path d="m6 9 6 6 6-6"></path></svg></a><div data-state="closed" id="radix-_R_vad5aj5_" hidden="" data-slot="collapsible-content" class="relative before:bg-fd-border before:absolute before:inset-y-1 before:start-2.5 before:w-px before:content-[&#x27;&#x27;]"></div></div><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Advanced Features</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/inmemory-compaction" data-discover="true">In-memory Compaction</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/offheap-read-write" data-discover="true">RegionServer Off-Heap Read/Write Path</a><div data-state="closed" data-slot="collapsible" class="group"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors w-full" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/backup-restore" data-discover="true">Backup and Restore<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down ms-auto transition-transform -rotate-90" data-icon="true"><path d="m6 9 6 6 6-6"></path></svg></a><div data-state="closed" id="radix-_R_17ad5aj5_" hidden="" data-slot="collapsible-content" class="relative before:bg-fd-border before:absolute before:inset-y-1 before:start-2.5 before:w-px before:content-[&#x27;&#x27;]"></div></div><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/sync-replication" data-discover="true">Synchronous Replication</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">APIs &amp; Integration</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/hbase-apis" data-discover="true">Apache HBase APIs</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/external-apis" data-discover="true">Apache HBase External APIs</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/thrift-filter-language" data-discover="true">Thrift API and Filter Language</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/spark" data-discover="true">HBase and Spark</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/cp" data-discover="true">Apache HBase Coprocessors</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Performance &amp; Troubleshooting</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/performance" data-discover="true">Apache HBase Performance Tuning</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/profiler" data-discover="true">Profiler Servlet</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/troubleshooting" data-discover="true">Troubleshooting and Debugging Apache HBase</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/case-studies" data-discover="true">Apache HBase Case Studies</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Operations &amp; Development</p><div data-state="closed" data-slot="collapsible" class="group"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors w-full" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/operational-management" data-discover="true">Apache HBase Operational Management<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down ms-auto transition-transform -rotate-90" data-icon="true"><path d="m6 9 6 6 6-6"></path></svg></a><div data-state="closed" id="radix-_R_23ad5aj5_" hidden="" data-slot="collapsible-content" class="relative before:bg-fd-border before:absolute before:inset-y-1 before:start-2.5 before:w-px before:content-[&#x27;&#x27;]"></div></div><div data-state="closed" data-slot="collapsible" class="group"><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors w-full" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/building-and-developing" data-discover="true">Building and Developing Apache HBase<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down ms-auto transition-transform -rotate-90" data-icon="true"><path d="m6 9 6 6 6-6"></path></svg></a><div data-state="closed" id="radix-_R_25ad5aj5_" hidden="" data-slot="collapsible-content" class="relative before:bg-fd-border before:absolute before:inset-y-1 before:start-2.5 before:w-px before:content-[&#x27;&#x27;]"></div></div><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/unit-testing" data-discover="true">Unit Testing HBase Applications</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Internals</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/protobuf" data-discover="true">Protobuf in HBase</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/pv2" data-discover="true">Procedure Framework (PV2)</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/amv2" data-discover="true">AMv2 Description for Devs</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Infrastructure &amp; Tools</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/zookeeper" data-discover="true">ZooKeeper</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/community" data-discover="true">Community</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/hbtop" data-discover="true">hbtop</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/tracing" data-discover="true">Tracing</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/store-file-tracking" data-discover="true">Store File Tracking</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/bulk-data-generator-tool" data-discover="true">Bulk Data Generator Tool</a><p class="mt-6 mb-1.5 inline-flex items-center gap-2 px-2 empty:mb-0 first:mt-0 [&amp;_svg]:size-4 [&amp;_svg]:shrink-0" style="padding-inline-start:calc(2 * var(--spacing))">Appendices</p><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/contributing-to-documentation" data-discover="true">Appendix: Contributing to Documentation</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/faq" data-discover="true">FAQ</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/acl-matrix" data-discover="true">Access Control Matrix</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/compression" data-discover="true">Compression and Data Block Encoding In HBase</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/sql" data-discover="true">SQL over HBase</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/ycsb" data-discover="true">YCSB</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/hfile-format" data-discover="true">HFile Format</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/other-info" data-discover="true">Other Information About HBase</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/hbase-history" data-discover="true">HBase History</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/asf" data-discover="true">HBase and the Apache Software Foundation</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/orca" data-discover="true">Apache HBase Orca</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/rpc" data-discover="true">0.95 RPC Specification</a><a data-active="false" class="relative flex flex-row items-center gap-2 rounded-lg p-2 text-start text-fd-muted-foreground wrap-anywhere [&amp;_svg]:size-4 [&amp;_svg]:shrink-0 transition-colors hover:bg-fd-accent/50 hover:text-fd-accent-foreground/80 hover:transition-none data-[active=true]:bg-fd-primary/10 data-[active=true]:text-fd-primary data-[active=true]:hover:transition-colors" style="padding-inline-start:calc(2 * var(--spacing))" href="/docs/hbase-incompatibilities" data-discover="true">Known Incompatibilities Among HBase Versions</a></div></div></div></div></div><div class="flex flex-col border-t p-4 pt-2 empty:hidden"><div class="text-fd-muted-foreground flex items-center empty:hidden"><a href="https://github.com/apache/hbase/" rel="noreferrer noopener" target="_blank" class="inline-flex items-center cursor-pointer justify-center gap-2 whitespace-nowrap rounded-md text-sm font-medium transition-all disabled:pointer-events-none disabled:opacity-50 [&amp;_svg]:pointer-events-none [&amp;_svg:not([class*=&#x27;size-&#x27;])]:size-4 shrink-0 [&amp;_svg]:shrink-0 outline-none focus-visible:border-ring focus-visible:ring-ring/50 focus-visible:ring-[3px] aria-invalid:ring-destructive/20 hover:bg-accent hover:text-accent-foreground size-8" aria-label="GitHub" data-active="false"><svg role="img" viewBox="0 0 24 24" fill="currentColor"><path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path></svg></a><button class="inline-flex items-center rounded-full border ms-auto p-0" aria-label="Toggle Theme" data-theme-toggle=""><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="currentColor" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-sun size-6.5 rounded-full p-1.5 text-fd-muted-foreground"><circle cx="12" cy="12" r="4"></circle><path d="M12 2v2"></path><path d="M12 20v2"></path><path d="m4.93 4.93 1.41 1.41"></path><path d="m17.66 17.66 1.41 1.41"></path><path d="M2 12h2"></path><path d="M20 12h2"></path><path d="m6.34 17.66-1.41 1.41"></path><path d="m19.07 4.93-1.41 1.41"></path></svg><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="currentColor" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-moon size-6.5 rounded-full p-1.5 text-fd-muted-foreground"><path d="M12 3a6 6 0 0 0 9 9 9 9 0 1 1-9-9Z"></path></svg></button></div></div></aside></div><div data-sidebar-panel="" class="bg-fd-muted text-fd-muted-foreground fixed start-4 top-[calc(--spacing(4)+var(--fd-docs-row-3))] z-10 flex rounded-xl border p-0.5 shadow-lg transition-opacity pointer-events-none opacity-0"><button type="button" aria-label="Collapse Sidebar" data-collapsed="false" class="inline-flex items-center cursor-pointer justify-center gap-2 whitespace-nowrap text-sm font-medium transition-all disabled:pointer-events-none disabled:opacity-50 [&amp;_svg]:pointer-events-none [&amp;_svg:not([class*=&#x27;size-&#x27;])]:size-4 shrink-0 [&amp;_svg]:shrink-0 outline-none focus-visible:border-ring focus-visible:ring-ring/50 focus-visible:ring-[3px] aria-invalid:ring-destructive/20 hover:bg-accent hover:text-accent-foreground size-8 rounded-lg"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-panel-left"><rect width="18" height="18" x="3" y="3" rx="2"></rect><path d="M9 3v18"></path></svg></button><button type="button" class="inline-flex items-center cursor-pointer justify-center gap-2 whitespace-nowrap text-sm font-medium transition-all disabled:pointer-events-none disabled:opacity-50 [&amp;_svg]:pointer-events-none [&amp;_svg:not([class*=&#x27;size-&#x27;])]:size-4 shrink-0 [&amp;_svg]:shrink-0 outline-none focus-visible:border-ring focus-visible:ring-ring/50 focus-visible:ring-[3px] aria-invalid:ring-destructive/20 hover:bg-accent hover:text-accent-foreground size-8 rounded-lg" data-search="" aria-label="Open Search"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-search"><circle cx="11" cy="11" r="8"></circle><path d="m21 21-4.3-4.3"></path></svg></button></div><div data-state="closed" data-slot="collapsible" class="group sticky top-(--fd-docs-row-2) z-10 h-(--fd-toc-popover-height) [grid-area:toc-popover] xl:hidden" data-toc-popover=""><header class="border-b backdrop-blur-sm transition-colors bg-fd-background/80"><button type="button" aria-controls="radix-_R_1ij5_" aria-expanded="false" data-state="closed" class="cursor-pointer text-fd-muted-foreground flex h-10 w-full items-center gap-2.5 px-4 py-2.5 text-start text-sm focus-visible:outline-none md:px-6 [&amp;_svg]:size-4" data-slot="collapsible-trigger" data-toc-popover-trigger=""><svg role="progressbar" viewBox="0 0 24 24" aria-valuenow="0" aria-valuemin="0" aria-valuemax="1" class="shrink-0"><circle cx="12" cy="12" r="11" fill="none" stroke-width="2" class="stroke-current/25"></circle><circle cx="12" cy="12" r="11" fill="none" stroke-width="2" stroke="currentColor" stroke-dasharray="69.11503837897544" stroke-dashoffset="69.11503837897544" stroke-linecap="round" transform="rotate(-90 12 12)" class="transition-all"></circle></svg><span class="grid flex-1 *:col-start-1 *:row-start-1 *:my-auto"><span class="truncate transition-[opacity,translate,color]">Secure Client Access to Apache HBase</span><span class="truncate transition-[opacity,translate] pointer-events-none translate-y-full opacity-0"></span></span><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-down mx-0.5 shrink-0 transition-transform"><path d="m6 9 6 6 6-6"></path></svg></button><div data-state="closed" id="radix-_R_1ij5_" hidden="" data-slot="collapsible-content" data-toc-popover-content="" class="flex max-h-[50vh] flex-col px-4 md:px-6"></div></header></div><article id="nd-page" data-full="false" class="mx-auto flex w-full max-w-[900px] flex-col gap-4 px-4 py-6 [grid-area:main] md:px-6 md:pt-8 xl:px-8 xl:pt-14 xl:[--fd-toc-width:285px]"><div class="text-fd-muted-foreground flex items-center gap-1.5 text-sm"><a class="truncate text-fd-primary font-medium transition-opacity hover:opacity-80" href="/docs/security" data-discover="true">Security</a></div><div class="no-print"><h1 class="text-[1.75em] font-semibold">Secure Client Access to Apache HBase</h1><p class="text-fd-muted-foreground mb-8 text-lg">Configuring Kerberos-based secure authentication for HBase clients, including server and client setup procedures.</p></div><div class="prose flex-1"><p class="wrap-anywhere">Newer releases of Apache HBase (&gt;= 0.92) support optional SASL authentication of clients. See also Matteo Bertozzi&#x27;s article on <a href="https://blog.cloudera.com/blog/2012/09/understanding-user-authentication-and-authorization-in-apache-hbase/">Understanding User Authentication and Authorization in Apache HBase</a>.</p>
<p class="wrap-anywhere">This describes how to set up Apache HBase and clients for connection to secure HBase resources.</p>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="security-client-access-prerequisites"><a data-card="" href="#security-client-access-prerequisites" class="peer">Prerequisites</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<h4 class="flex scroll-m-28 flex-row items-center gap-2" id="hadoop-authentication-configuration-toc"><a data-card="" href="#hadoop-authentication-configuration-toc" class="peer">Hadoop Authentication Configuration</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h4>
<p class="wrap-anywhere">To run HBase RPC with strong authentication, you must set <code>hbase.security.authentication</code> to <code>kerberos</code>. In this case, you must also set <code>hadoop.security.authentication</code> to <code>kerberos</code> in core-site.xml. Otherwise, you would be using strong authentication for HBase but not for the underlying HDFS, which would cancel out any benefit.</p>
<h4 class="flex scroll-m-28 flex-row items-center gap-2" id="kerberos-kdc-toc"><a data-card="" href="#kerberos-kdc-toc" class="peer">Kerberos KDC</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h4>
<p class="wrap-anywhere">You need to have a working Kerberos KDC.</p>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="server-side-configuration-for-secure-operation"><a data-card="" href="#server-side-configuration-for-secure-operation" class="peer">Server-side Configuration for Secure Operation</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<p class="wrap-anywhere">First, refer to <a href="/docs/security/client-access#security-client-access-prerequisites" data-discover="true">security.prerequisites</a> and ensure that your underlying HDFS configuration is secure.</p>
<p class="wrap-anywhere">Add the following to the <code>hbase-site.xml</code> file on every server machine in the cluster:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.security.authentication&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;kerberos&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.security.authorization&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;true&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.coprocessor.region.classes&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;org.apache.hadoop.hbase.security.token.TokenProvider&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">A full shutdown and restart of HBase service is required when deploying these configuration changes.</p>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="client-side-configuration-for-secure-operation"><a data-card="" href="#client-side-configuration-for-secure-operation" class="peer">Client-side Configuration for Secure Operation</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<p class="wrap-anywhere">First, refer to <a href="/docs/security/client-access#security-client-access-prerequisites" data-discover="true">Prerequisites</a> and ensure that your underlying HDFS configuration is secure.</p>
<p class="wrap-anywhere">Add the following to the <code>hbase-site.xml</code> file on every client:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.security.authentication&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;kerberos&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Before 2.2.0 version, the client environment must be logged in to Kerberos from KDC or keytab via the <code>kinit</code> command before communication with the HBase cluster will be possible.</p>
<p class="wrap-anywhere">Since 2.2.0, client can specify the following configurations in <code>hbase-site.xml</code>:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.client.keytab.file&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;/local/path/to/client/keytab&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.client.keytab.principal&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;foo@EXAMPLE.COM&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Then application can automatically do the login and credential renewal jobs without client interference.</p>
<p class="wrap-anywhere">It&#x27;s optional feature, client, who upgrades to 2.2.0, can still keep their login and credential renewal logic already did in older version, as long as keeping <code>hbase.client.keytab.file</code> and <code>hbase.client.keytab.principal</code> are unset.</p>
<p class="wrap-anywhere">Be advised that if the <code>hbase.security.authentication</code> in the client- and server-side site files do not match, the client will not be able to communicate with the cluster.</p>
<p class="wrap-anywhere">Once HBase is configured for secure RPC it is possible to optionally configure encrypted communication. To do so, add the following to the <code>hbase-site.xml</code> file on every client:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rpc.protection&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;privacy&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">This configuration property can also be set on a per-connection basis. Set it in the <code>Configuration</code> supplied to <code>Table</code>:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">Configuration conf </span><span style="--shiki-light:#D73A49;--shiki-dark:#F97583">=</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> HBaseConfiguration.</span><span style="--shiki-light:#6F42C1;--shiki-dark:#B392F0">create</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">();</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">Connection connection </span><span style="--shiki-light:#D73A49;--shiki-dark:#F97583">=</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> ConnectionFactory.</span><span style="--shiki-light:#6F42C1;--shiki-dark:#B392F0">createConnection</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">(conf);</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">conf.</span><span style="--shiki-light:#6F42C1;--shiki-dark:#B392F0">set</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">(</span><span style="--shiki-light:#032F62;--shiki-dark:#9ECBFF">&quot;hbase.rpc.protection&quot;</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">, </span><span style="--shiki-light:#032F62;--shiki-dark:#9ECBFF">&quot;privacy&quot;</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">);</span></span>
<span class="line"><span style="--shiki-light:#D73A49;--shiki-dark:#F97583">try</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> (Connection connection </span><span style="--shiki-light:#D73A49;--shiki-dark:#F97583">=</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> ConnectionFactory.</span><span style="--shiki-light:#6F42C1;--shiki-dark:#B392F0">createConnection</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">(conf);</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> Table table </span><span style="--shiki-light:#D73A49;--shiki-dark:#F97583">=</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> connection.</span><span style="--shiki-light:#6F42C1;--shiki-dark:#B392F0">getTable</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">(TableName.</span><span style="--shiki-light:#6F42C1;--shiki-dark:#B392F0">valueOf</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">(tablename))) {</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> .... do your stuff</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">}</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Expect a ~10% performance penalty for encrypted communication.</p>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="client-side-configuration-for-secure-operation---thrift-gateway"><a data-card="" href="#client-side-configuration-for-secure-operation---thrift-gateway" class="peer">Client-side Configuration for Secure Operation - Thrift Gateway</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<p class="wrap-anywhere">Add the following to the <code>hbase-site.xml</code> file for every Thrift gateway:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.thrift.keytab.file&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;/etc/hbase/conf/hbase.keytab&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.thrift.kerberos.principal&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$USER/_HOST@HADOOP.LOCALDOMAIN&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#6A737D;--shiki-dark:#6A737D"> &lt;!-- TODO: This may need to be HTTP/_HOST@&lt;REALM&gt; and _HOST may not work.</span></span>
<span class="line"><span style="--shiki-light:#6A737D;--shiki-dark:#6A737D"> You may have to put the concrete full hostname.</span></span>
<span class="line"><span style="--shiki-light:#6A737D;--shiki-dark:#6A737D"> --&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#6A737D;--shiki-dark:#6A737D">&lt;!-- Add these if you need to configure a different DNS interface from the default --&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.thrift.dns.interface&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;default&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.thrift.dns.nameserver&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;default&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Substitute the appropriate credential and keytab for <em>$USER</em> and <em>$KEYTAB</em> respectively.</p>
<p class="wrap-anywhere">In order to use the Thrift API principal to interact with HBase, it is also necessary to add the <code>hbase.thrift.kerberos.principal</code> to the <code>acl</code> table. For example, to give the Thrift API principal, <code>thrift_server</code>, administrative access, a command such as this one will suffice:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#D73A49;--shiki-dark:#F97583">grant</span><span style="--shiki-light:#032F62;--shiki-dark:#9ECBFF"> &#x27;thrift_server&#x27;</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">, </span><span style="--shiki-light:#032F62;--shiki-dark:#9ECBFF">&#x27;RWCA&#x27;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">For more information about ACLs, please see the <a href="/docs/security/data-access#access-control-labels-acls" data-discover="true">Access Control Labels (ACLs)</a> section</p>
<p class="wrap-anywhere">The Thrift gateway will authenticate with HBase using the supplied credential. No authentication will be performed by the Thrift gateway itself. All client access via the Thrift gateway will use the Thrift gateway&#x27;s credential and have its privilege.</p>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="configure-the-thrift-gateway-to-authenticate-on-behalf-of-the-client"><a data-card="" href="#configure-the-thrift-gateway-to-authenticate-on-behalf-of-the-client" class="peer">Configure the Thrift Gateway to Authenticate on Behalf of the Client</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<p class="wrap-anywhere"><a href="/docs/security/client-access#client-side-configuration-for-secure-operation---thrift-gateway" data-discover="true">Client-side Configuration for Secure Operation - Thrift Gateway</a> describes how to authenticate a Thrift client to HBase using a fixed user. As an alternative, you can configure the Thrift gateway to authenticate to HBase on the client&#x27;s behalf, and to access HBase using a proxy user. This was implemented in <a href="https://issues.apache.org/jira/browse/HBASE-11349">HBASE-11349</a> for Thrift 1, and <a href="https://issues.apache.org/jira/browse/HBASE-11474">HBASE-11474</a> for Thrift 2.</p>
<div class="flex gap-2 my-4 rounded-xl border bg-fd-card p-3 ps-1 text-sm text-fd-card-foreground shadow-md" style="--callout-color:var(--color-fd-info, var(--color-fd-muted))"><div role="none" class="w-0.5 bg-(--callout-color)/50 rounded-sm"></div><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-5 -me-0.5 fill-(--callout-color) text-fd-card"><circle cx="12" cy="12" r="10"></circle><path d="M12 16v-4"></path><path d="M12 8h.01"></path></svg><div class="flex flex-col gap-2 min-w-0 flex-1"><div class="text-fd-muted-foreground prose-no-margin empty:hidden"><p class="wrap-anywhere">If you use framed transport, you cannot yet take advantage of this feature, because SASL does not
work with Thrift framed transport at this time.</p></div></div></div>
<p class="wrap-anywhere">To enable it, do the following.</p>
<ol>
<li>Be sure Thrift is running in secure mode, by following the procedure described in <a href="/docs/security/client-access#client-side-configuration-for-secure-operation---thrift-gateway" data-discover="true">Client-side Configuration for Secure Operation - Thrift Gateway</a>.</li>
<li>Be sure that HBase is configured to allow proxy users, as described in <a href="/docs/security/client-access#rest-gateway-impersonation-configuration" data-discover="true">REST Gateway Impersonation Configuration</a>.</li>
<li>In <em>hbase-site.xml</em> for each cluster node running a Thrift gateway, set the property <code>hbase.thrift.security.qop</code> to one of the following three values:<!-- -->
<ul>
<li><code>privacy</code> - authentication, integrity, and confidentiality checking.</li>
<li><code>integrity</code> - authentication and integrity checking</li>
<li><code>authentication</code> - authentication checking only</li>
</ul>
</li>
<li>Restart the Thrift gateway processes for the changes to take effect. If a node is running Thrift, the output of the <code>jps</code> command will list a <code>ThriftServer</code> process. To stop Thrift on a node, run the command <code>bin/hbase-daemon.sh stop thrift</code>. To start Thrift on a node, run the command <code>bin/hbase-daemon.sh start thrift</code>.</li>
</ol>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="configure-the-thrift-gateway-to-use-the-doas-feature"><a data-card="" href="#configure-the-thrift-gateway-to-use-the-doas-feature" class="peer">Configure the Thrift Gateway to Use the <code>doAs</code> Feature</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<p class="wrap-anywhere"><a href="/docs/security/client-access#configure-the-thrift-gateway-to-authenticate-on-behalf-of-the-client" data-discover="true">Configure the Thrift Gateway to Authenticate on Behalf of the Client</a> describes how to configure the Thrift gateway to authenticate to HBase on the client&#x27;s behalf, and to access HBase using a proxy user. The limitation of this approach is that after the client is initialized with a particular set of credentials, it cannot change these credentials during the session. The <code>doAs</code> feature provides a flexible way to impersonate multiple principals using the same client. This feature was implemented in <a href="https://issues.apache.org/jira/browse/HBASE-12640">HBASE-12640</a> for Thrift 1, but is currently not available for Thrift 2.</p>
<p class="wrap-anywhere"><strong>To enable the <code>doAs</code> feature</strong>, add the following to the <em>hbase-site.xml</em> file for every Thrift gateway:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.regionserver.thrift.http&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;true&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.thrift.support.proxyuser&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;true&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere"><strong>To allow proxy users</strong> when using <code>doAs</code> impersonation, add the following to the <em>hbase-site.xml</em> file for every HBase node:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hadoop.security.authorization&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;true&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hadoop.proxyuser.$USER.groups&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$GROUPS&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hadoop.proxyuser.$USER.hosts&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$GROUPS&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Take a look at the <a href="https://github.com/apache/hbase/blob/master/hbase-examples/src/main/java/org/apache/hadoop/hbase/thrift/HttpDoAsClient.java">demo client</a> to get an overall idea of how to use this feature in your client.</p>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="client-side-configuration-for-secure-operation---rest-gateway"><a data-card="" href="#client-side-configuration-for-secure-operation---rest-gateway" class="peer">Client-side Configuration for Secure Operation - REST Gateway</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<p class="wrap-anywhere">Add the following to the <code>hbase-site.xml</code> file for every REST gateway:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.keytab.file&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$KEYTAB&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.kerberos.principal&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$USER/_HOST@HADOOP.LOCALDOMAIN&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Substitute the appropriate credential and keytab for <em>$USER</em> and <em>$KEYTAB</em> respectively.</p>
<p class="wrap-anywhere">The REST gateway will authenticate with HBase using the supplied credential.</p>
<p class="wrap-anywhere">In order to use the REST API principal to interact with HBase, it is also necessary to add the <code>hbase.rest.kerberos.principal</code> to the <code>acl</code> table. For example, to give the REST API principal, <code>rest_server</code>, administrative access, a command such as this one will suffice:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#D73A49;--shiki-dark:#F97583">grant</span><span style="--shiki-light:#032F62;--shiki-dark:#9ECBFF"> &#x27;rest_server&#x27;</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">, </span><span style="--shiki-light:#032F62;--shiki-dark:#9ECBFF">&#x27;RWCA&#x27;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">For more information about ACLs, please see the <a href="/docs/security/data-access#access-control-labels-acls" data-discover="true">Access Control Labels (ACLs)</a> section</p>
<p class="wrap-anywhere">HBase REST gateway supports <a href="https://hadoop.apache.org/docs/stable/hadoop-auth/index.html">SPNEGO HTTP authentication</a> for client access to the gateway. To enable REST gateway Kerberos authentication for client access, add the following to the <code>hbase-site.xml</code> file for every REST gateway.</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.support.proxyuser&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;true&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.authentication.type&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;kerberos&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.authentication.kerberos.principal&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;HTTP/_HOST@HADOOP.LOCALDOMAIN&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.authentication.kerberos.keytab&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$KEYTAB&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#6A737D;--shiki-dark:#6A737D">&lt;!-- Add these if you need to configure a different DNS interface from the default --&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.dns.interface&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;default&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.dns.nameserver&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;default&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Substitute the keytab for HTTP for <em>$KEYTAB</em>.</p>
<p class="wrap-anywhere">HBase REST gateway supports different &#x27;hbase.rest.authentication.type&#x27;: simple, kerberos. You can also implement a custom authentication by implementing Hadoop AuthenticationHandler, then specify the full class name as &#x27;hbase.rest.authentication.type&#x27; value. For more information, refer to <a href="https://hadoop.apache.org/docs/stable/hadoop-auth/index.html">SPNEGO HTTP authentication</a>.</p>
<h2 class="flex scroll-m-28 flex-row items-center gap-2" id="rest-gateway-impersonation-configuration"><a data-card="" href="#rest-gateway-impersonation-configuration" class="peer">REST Gateway Impersonation Configuration</a><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide size-3.5 shrink-0 text-fd-muted-foreground opacity-0 transition-opacity peer-hover:opacity-100" aria-hidden="true"><path d="M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71"></path><path d="M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71"></path></svg></h2>
<p class="wrap-anywhere">By default, the REST gateway doesn&#x27;t support impersonation. It accesses the HBase on behalf of clients as the user configured as in the previous section. To the HBase server, all requests are from the REST gateway user. The actual users are unknown. You can turn on the impersonation support. With impersonation, the REST gateway user is a proxy user. The HBase server knows the actual/real user of each request. So it can apply proper authorizations.</p>
<p class="wrap-anywhere">To turn on REST gateway impersonation, we need to configure HBase servers (masters and region servers) to allow proxy users; configure REST gateway to enable impersonation.</p>
<p class="wrap-anywhere">To allow proxy users, add the following to the <code>hbase-site.xml</code> file for every HBase server:</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hadoop.security.authorization&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;true&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hadoop.proxyuser.$USER.groups&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$GROUPS&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hadoop.proxyuser.$USER.hosts&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$GROUPS&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Substitute the REST gateway proxy user for <em>$USER</em>, and the allowed group list for <em>$GROUPS</em>.</p>
<p class="wrap-anywhere">To enable REST gateway impersonation, add the following to the <code>hbase-site.xml</code> file for every REST gateway.</p>
<figure dir="ltr" class="my-4 bg-fd-card rounded-xl shiki relative border shadow-sm not-prose overflow-hidden text-sm shiki shiki-themes github-light github-dark" style="--shiki-light:#24292e;--shiki-dark:#e1e4e8;--shiki-light-bg:#fff;--shiki-dark-bg:#24292e" tabindex="-1"><div class="empty:hidden absolute top-2 right-2 z-2 backdrop-blur-lg rounded-lg text-fd-muted-foreground"><button type="button" class="inline-flex items-center justify-center rounded-md text-sm font-medium transition-colors duration-100 disabled:pointer-events-none disabled:opacity-50 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-fd-ring p-1 [&amp;_svg]:size-4 hover:text-fd-accent-foreground data-checked:text-fd-accent-foreground" aria-label="Copy Text"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide"><rect width="8" height="4" x="8" y="2" rx="1" ry="1"></rect><path d="M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2"></path></svg></button></div><div role="region" tabindex="0" class="text-[13px] py-3.5 overflow-auto max-h-[600px] fd-scroll-container focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-inset focus-visible:ring-fd-ring" style="--padding-right:calc(var(--spacing) * 8)"><pre class="min-w-full w-max *:flex *:flex-col"><code><span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.authentication.type&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;kerberos&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.authentication.kerberos.principal&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;HTTP/_HOST@HADOOP.LOCALDOMAIN&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;hbase.rest.authentication.kerberos.keytab&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">name</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8"> &lt;</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;$KEYTAB&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">value</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span>
<span class="line"><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&lt;/</span><span style="--shiki-light:#22863A;--shiki-dark:#85E89D">property</span><span style="--shiki-light:#24292E;--shiki-dark:#E1E4E8">&gt;</span></span></code></pre></div></figure>
<p class="wrap-anywhere">Substitute the keytab for HTTP for <em>$KEYTAB</em>.</p></div><a href="https://github.com/apache/hbase/edit/master/hbase-website/app/pages/_docs/docs/_mdx/(multi-page)/security/client-access.mdx" rel="noreferrer noopener" target="_blank" class="no-print text-fd-secondary-foreground bg-fd-secondary hover:text-fd-accent-foreground hover:bg-fd-accent w-fit rounded-xl border p-2 text-sm font-medium transition-colors">Edit on GitHub</a><div class="@container grid gap-4 grid-cols-2"><a class="hover:bg-fd-accent/80 hover:text-fd-accent-foreground flex flex-col gap-2 rounded-lg border p-4 text-sm transition-colors @max-lg:col-span-full" href="/docs/security/web-ui" data-discover="true"><div class="inline-flex items-center gap-1.5 font-medium"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-left -mx-1 size-4 shrink-0 rtl:rotate-180"><path d="m15 18-6-6 6-6"></path></svg><p>Web UI Security</p></div><p class="text-fd-muted-foreground truncate">HBase provides mechanisms to secure various components and aspects of HBase and how it relates to the rest of the Hadoop infrastructure, as well as clients and resources outside Hadoop.</p></a><a class="hover:bg-fd-accent/80 hover:text-fd-accent-foreground flex flex-col gap-2 rounded-lg border p-4 text-sm transition-colors @max-lg:col-span-full text-end" href="/docs/security/user-access" data-discover="true"><div class="inline-flex items-center gap-1.5 font-medium flex-row-reverse"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chevron-right -mx-1 size-4 shrink-0 rtl:rotate-180"><path d="m9 18 6-6-6-6"></path></svg><p>Simple User Access to Apache HBase</p></div><p class="text-fd-muted-foreground truncate">Setting up simple SASL authentication for HBase clients without Kerberos, using username/password-based access control.</p></a></div></article><div id="nd-toc" class="sticky top-(--fd-docs-row-1) flex h-[calc(var(--fd-docs-height)-var(--fd-docs-row-1))] w-(--fd-toc-width) flex-col justify-self-end pe-4 pt-12 pb-2 [grid-area:toc] max-xl:hidden"><h3 id="toc-title" class="text-fd-muted-foreground inline-flex items-center gap-1.5 text-sm"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-text size-4"><path d="M17 6.1H3"></path><path d="M21 12.1H3"></path><path d="M15.1 18H3"></path></svg>On this page</h3><div class="relative ms-px min-h-0 overflow-auto mask-[linear-gradient(to_bottom,transparent,white_16px,white_calc(100%-16px),transparent)] py-3 text-sm [scrollbar-width:none]"><div class="flex flex-col"><a data-active="false" href="#security-client-access-prerequisites" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>Prerequisites</a><a data-active="false" href="#server-side-configuration-for-secure-operation" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>Server-side Configuration for Secure Operation</a><a data-active="false" href="#client-side-configuration-for-secure-operation" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>Client-side Configuration for Secure Operation</a><a data-active="false" href="#client-side-configuration-for-secure-operation---thrift-gateway" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>Client-side Configuration for Secure Operation - Thrift Gateway</a><a data-active="false" href="#configure-the-thrift-gateway-to-authenticate-on-behalf-of-the-client" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>Configure the Thrift Gateway to Authenticate on Behalf of the Client</a><a data-active="false" href="#configure-the-thrift-gateway-to-use-the-doas-feature" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>Configure the Thrift Gateway to Use the <code>doAs</code> Feature</a><a data-active="false" href="#client-side-configuration-for-secure-operation---rest-gateway" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>Client-side Configuration for Secure Operation - REST Gateway</a><a data-active="false" href="#rest-gateway-impersonation-configuration" style="padding-inline-start:14px" class="prose text-fd-muted-foreground hover:text-fd-accent-foreground data-[active=true]:text-fd-primary relative py-1.5 text-sm wrap-anywhere transition-colors first:pt-0 last:pb-0"><div class="bg-fd-foreground/10 absolute inset-y-0 w-px" style="inset-inline-start:0"></div>REST Gateway Impersonation Configuration</a></div></div></div></div><script>((storageKey2, restoreKey) => {
if (!window.history.state || !window.history.state.key) {
let key = Math.random().toString(32).slice(2);
window.history.replaceState({ key }, "");
}
try {
let positions = JSON.parse(sessionStorage.getItem(storageKey2) || "{}");
let storedY = positions[restoreKey || window.history.state.key];
if (typeof storedY === "number") {
window.scrollTo(0, storedY);
}
} catch (error) {
console.error(error);
sessionStorage.removeItem(storageKey2);
}
})("react-router-scroll-positions", null)</script><script>window.__reactRouterContext = {"basename":"/","future":{"unstable_optimizeDeps":false,"v8_passThroughRequests":false,"v8_trailingSlashAwareDataRequests":false,"unstable_previewServerPrerendering":false,"v8_middleware":false,"v8_splitRouteModules":false,"v8_viteEnvironmentApi":false},"routeDiscovery":{"mode":"initial"},"ssr":false,"isSpaMode":false};window.__reactRouterContext.stream = new ReadableStream({start(controller){window.__reactRouterContext.streamController = controller;}}).pipeThrough(new TextEncoderStream());</script><script type="module" async="">import "/assets/manifest-baf72bfa.js";
import * as route0 from "/assets/root-COkOICkm.js";
import * as route1 from "/assets/docs-layout-5T1N7EZh.js";
import * as route2 from "/assets/docs-DMCF1KDd.js";
window.__reactRouterRouteModules = {"root":route0,"pages/_docs/docs-layout":route1,"routes/_docs/docs":route2};
import("/assets/entry.client-Bi9_frb9.js");</script><!--$--><script>window.__reactRouterContext.streamController.enqueue("[{\"_1\":2,\"_3\":-5,\"_4\":-5},\"loaderData\",{\"_5\":6},\"actionData\",\"errors\",\"routes/_docs/docs\",{\"_7\":8,\"_9\":10,\"_11\":12},\"path\",\"(multi-page)/security/client-access.mdx\",\"url\",\"/docs/security/client-access\",\"tree\",{\"_13\":14,\"_15\":16,\"_17\":18},\"$id\",\"root\",\"name\",\"Docs\",\"children\",[19,20],{\"_21\":22,\"_15\":44,\"_24\":-7,\"_14\":25,\"_26\":-7,\"_27\":45,\"_29\":-7,\"_17\":46,\"_13\":47,\"_32\":48},{\"_21\":22,\"_15\":23,\"_24\":-7,\"_14\":25,\"_26\":-7,\"_27\":28,\"_29\":-7,\"_17\":30,\"_13\":31,\"_32\":33},\"type\",\"folder\",\"Single-Page Documentation\",\"icon\",true,\"defaultOpen\",\"description\",\"Entire docs on one page\",\"index\",[36],\"single-page\",\"$ref\",{\"_34\":35},\"metaFile\",\"single-page/meta.json\",{\"_13\":37,\"_21\":38,\"_15\":39,\"_27\":40,\"_24\":-7,\"_9\":41,\"_32\":42},\"single-page/index.mdx\",\"page\",\"Apache HBase Documentation\",\"Complete Apache HBase documentation in one continuous page.\",\"/docs/single-page\",{\"_43\":37},\"file\",\"Multi-Page Documentation\",\"Split across multiple pages\",[50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109],\"(multi-page)\",{\"_34\":49},\"(multi-page)/meta.json\",{\"_13\":727,\"_21\":176,\"_24\":-7,\"_15\":718},{\"_13\":722,\"_21\":38,\"_15\":723,\"_27\":724,\"_24\":-7,\"_9\":725,\"_32\":726},{\"_13\":717,\"_21\":38,\"_15\":718,\"_27\":719,\"_24\":-7,\"_9\":720,\"_32\":721},{\"_21\":38,\"_24\":-7,\"_15\":714,\"_9\":715,\"_716\":25},{\"_13\":712,\"_21\":176,\"_24\":-7,\"_15\":713},{\"_21\":22,\"_15\":660,\"_24\":-7,\"_14\":-7,\"_26\":-7,\"_27\":-7,\"_29\":661,\"_17\":662,\"_13\":663,\"_32\":664},{\"_21\":22,\"_15\":626,\"_24\":-7,\"_14\":-7,\"_26\":-7,\"_27\":-7,\"_29\":627,\"_17\":628,\"_13\":629,\"_32\":630},{\"_13\":621,\"_21\":38,\"_15\":622,\"_27\":623,\"_24\":-7,\"_9\":624,\"_32\":625},{\"_13\":619,\"_21\":176,\"_24\":-7,\"_15\":620},{\"_13\":614,\"_21\":38,\"_15\":615,\"_27\":616,\"_24\":-7,\"_9\":617,\"_32\":618},{\"_13\":609,\"_21\":38,\"_15\":610,\"_27\":611,\"_24\":-7,\"_9\":612,\"_32\":613},{\"_13\":604,\"_21\":38,\"_15\":605,\"_27\":606,\"_24\":-7,\"_9\":607,\"_32\":608},{\"_13\":599,\"_21\":38,\"_15\":600,\"_27\":601,\"_24\":-7,\"_9\":602,\"_32\":603},{\"_21\":22,\"_15\":549,\"_24\":-7,\"_14\":-7,\"_26\":-7,\"_27\":-7,\"_29\":550,\"_17\":551,\"_13\":552,\"_32\":553},{\"_21\":22,\"_15\":468,\"_24\":-7,\"_14\":-7,\"_26\":-7,\"_27\":-7,\"_29\":469,\"_17\":470,\"_13\":471,\"_32\":472},{\"_13\":466,\"_21\":176,\"_24\":-7,\"_15\":467},{\"_13\":461,\"_21\":38,\"_15\":462,\"_27\":463,\"_24\":-7,\"_9\":464,\"_32\":465},{\"_13\":456,\"_21\":38,\"_15\":457,\"_27\":458,\"_24\":-7,\"_9\":459,\"_32\":460},{\"_21\":22,\"_15\":422,\"_24\":-7,\"_14\":-7,\"_26\":-7,\"_27\":-7,\"_29\":423,\"_17\":424,\"_13\":425,\"_32\":426},{\"_13\":417,\"_21\":38,\"_15\":418,\"_27\":419,\"_24\":-7,\"_9\":420,\"_32\":421},{\"_13\":415,\"_21\":176,\"_24\":-7,\"_15\":416},{\"_13\":410,\"_21\":38,\"_15\":411,\"_27\":412,\"_24\":-7,\"_9\":413,\"_32\":414},{\"_13\":405,\"_21\":38,\"_15\":406,\"_27\":407,\"_24\":-7,\"_9\":408,\"_32\":409},{\"_13\":400,\"_21\":38,\"_15\":401,\"_27\":402,\"_24\":-7,\"_9\":403,\"_32\":404},{\"_13\":395,\"_21\":38,\"_15\":396,\"_27\":397,\"_24\":-7,\"_9\":398,\"_32\":399},{\"_13\":390,\"_21\":38,\"_15\":391,\"_27\":392,\"_24\":-7,\"_9\":393,\"_32\":394},{\"_13\":388,\"_21\":176,\"_24\":-7,\"_15\":389},{\"_13\":383,\"_21\":38,\"_15\":384,\"_27\":385,\"_24\":-7,\"_9\":386,\"_32\":387},{\"_13\":378,\"_21\":38,\"_15\":379,\"_27\":380,\"_24\":-7,\"_9\":381,\"_32\":382},{\"_13\":373,\"_21\":38,\"_15\":374,\"_27\":375,\"_24\":-7,\"_9\":376,\"_32\":377},{\"_13\":368,\"_21\":38,\"_15\":369,\"_27\":370,\"_24\":-7,\"_9\":371,\"_32\":372},{\"_13\":366,\"_21\":176,\"_24\":-7,\"_15\":367},{\"_21\":22,\"_15\":308,\"_24\":-7,\"_14\":-7,\"_26\":-7,\"_27\":-7,\"_29\":309,\"_17\":310,\"_13\":311,\"_32\":312},{\"_21\":22,\"_15\":232,\"_24\":-7,\"_14\":-7,\"_26\":-7,\"_27\":-7,\"_29\":233,\"_17\":234,\"_13\":235,\"_32\":236},{\"_13\":227,\"_21\":38,\"_15\":228,\"_27\":229,\"_24\":-7,\"_9\":230,\"_32\":231},{\"_13\":225,\"_21\":176,\"_24\":-7,\"_15\":226},{\"_13\":220,\"_21\":38,\"_15\":221,\"_27\":222,\"_24\":-7,\"_9\":223,\"_32\":224},{\"_13\":215,\"_21\":38,\"_15\":216,\"_27\":217,\"_24\":-7,\"_9\":218,\"_32\":219},{\"_13\":210,\"_21\":38,\"_15\":211,\"_27\":212,\"_24\":-7,\"_9\":213,\"_32\":214},{\"_13\":208,\"_21\":176,\"_24\":-7,\"_15\":209},{\"_13\":203,\"_21\":38,\"_15\":204,\"_27\":205,\"_24\":-7,\"_9\":206,\"_32\":207},{\"_13\":198,\"_21\":38,\"_15\":199,\"_27\":200,\"_24\":-7,\"_9\":201,\"_32\":202},{\"_13\":193,\"_21\":38,\"_15\":194,\"_27\":195,\"_24\":-7,\"_9\":196,\"_32\":197},{\"_13\":188,\"_21\":38,\"_15\":189,\"_27\":190,\"_24\":-7,\"_9\":191,\"_32\":192},{\"_13\":183,\"_21\":38,\"_15\":184,\"_27\":185,\"_24\":-7,\"_9\":186,\"_32\":187},{\"_13\":178,\"_21\":38,\"_15\":179,\"_27\":180,\"_24\":-7,\"_9\":181,\"_32\":182},{\"_13\":175,\"_21\":176,\"_24\":-7,\"_15\":177},{\"_13\":170,\"_21\":38,\"_15\":171,\"_27\":172,\"_24\":-7,\"_9\":173,\"_32\":174},{\"_13\":165,\"_21\":38,\"_15\":166,\"_27\":167,\"_24\":-7,\"_9\":168,\"_32\":169},{\"_13\":160,\"_21\":38,\"_15\":161,\"_27\":162,\"_24\":-7,\"_9\":163,\"_32\":164},{\"_13\":155,\"_21\":38,\"_15\":156,\"_27\":157,\"_24\":-7,\"_9\":158,\"_32\":159},{\"_13\":150,\"_21\":38,\"_15\":151,\"_27\":152,\"_24\":-7,\"_9\":153,\"_32\":154},{\"_13\":145,\"_21\":38,\"_15\":146,\"_27\":147,\"_24\":-7,\"_9\":148,\"_32\":149},{\"_13\":140,\"_21\":38,\"_15\":141,\"_27\":142,\"_24\":-7,\"_9\":143,\"_32\":144},{\"_13\":135,\"_21\":38,\"_15\":136,\"_27\":137,\"_24\":-7,\"_9\":138,\"_32\":139},{\"_13\":130,\"_21\":38,\"_15\":131,\"_27\":132,\"_24\":-7,\"_9\":133,\"_32\":134},{\"_13\":125,\"_21\":38,\"_15\":126,\"_27\":127,\"_24\":-7,\"_9\":128,\"_32\":129},{\"_13\":120,\"_21\":38,\"_15\":121,\"_27\":122,\"_24\":-7,\"_9\":123,\"_32\":124},{\"_13\":115,\"_21\":38,\"_15\":116,\"_27\":117,\"_24\":-7,\"_9\":118,\"_32\":119},{\"_13\":110,\"_21\":38,\"_15\":111,\"_27\":112,\"_24\":-7,\"_9\":113,\"_32\":114},\"(multi-page)/hbase-incompatibilities.mdx\",\"Known Incompatibilities Among HBase Versions\",\"Comprehensive list of breaking changes and incompatibilities between HBase versions, particularly for HBase 2.0.\",\"/docs/hbase-incompatibilities\",{\"_43\":110},\"(multi-page)/rpc.mdx\",\"0.95 RPC Specification\",\"HBase RPC wire format and client/server protocol specification for version 0.95+.\",\"/docs/rpc\",{\"_43\":115},\"(multi-page)/orca.mdx\",\"Apache HBase Orca\",\"Apache HBase Orca, HBase Colors, \u0026 Font\",\"/docs/orca\",{\"_43\":120},\"(multi-page)/asf.mdx\",\"HBase and the Apache Software Foundation\",\"HBase is a project in the Apache Software Foundation and as such there are responsibilities to the ASF to ensure a healthy project.\",\"/docs/asf\",{\"_43\":125},\"(multi-page)/hbase-history.mdx\",\"HBase History\",\"Timeline of Apache HBase development from its origins in Google's BigTable paper to becoming an Apache top-level project.\",\"/docs/hbase-history\",{\"_43\":130},\"(multi-page)/other-info.mdx\",\"Other Information About HBase\",\"Collection of HBase videos, presentations, papers, books, and useful external resources for learning and understanding HBase.\",\"/docs/other-info\",{\"_43\":135},\"(multi-page)/hfile-format.mdx\",\"HFile Format\",\"This appendix describes the evolution of the HFile format.\",\"/docs/hfile-format\",{\"_43\":140},\"(multi-page)/ycsb.mdx\",\"YCSB\",\"Documentation for YCSB (The Yahoo! Cloud Serving Benchmark)\",\"/docs/ycsb\",{\"_43\":145},\"(multi-page)/sql.mdx\",\"SQL over HBase\",\"The following projects offer some support for SQL over HBase.\",\"/docs/sql\",{\"_43\":150},\"(multi-page)/compression.mdx\",\"Compression and Data Block Encoding In HBase\",\"Comprehensive guide to compression algorithms and data block encoding options in HBase for optimizing storage and performance.\",\"/docs/compression\",{\"_43\":155},\"(multi-page)/acl-matrix.mdx\",\"Access Control Matrix\",\"The following matrix shows the permission set required to perform operations in HBase. Before using the table, read through the information about how to interpret it.\",\"/docs/acl-matrix\",{\"_43\":160},\"(multi-page)/faq.mdx\",\"FAQ\",\"Frequently asked questions about Apache HBase.\",\"/docs/faq\",{\"_43\":165},\"(multi-page)/contributing-to-documentation.mdx\",\"Appendix: Contributing to Documentation\",\"Guide for contributing to Apache HBase documentation, including patch submission procedures, website editing, style guidelines, and best practices.\",\"/docs/contributing-to-documentation\",{\"_43\":170},\"(multi-page)#46\",\"separator\",\"Appendices\",\"(multi-page)/bulk-data-generator-tool.mdx\",\"Bulk Data Generator Tool\",\"This is a random data generator tool for HBase tables leveraging Hbase bulk load. It can create pre-splited HBase table and the generated data is uniformly distributed to all the regions of the table.\",\"/docs/bulk-data-generator-tool\",{\"_43\":178},\"(multi-page)/store-file-tracking.mdx\",\"Store File Tracking\",\"This feature introduces an abstraction layer to track store files still used/needed by store engines, allowing for plugging different approaches of identifying store files required by the given store.\",\"/docs/store-file-tracking\",{\"_43\":183},\"(multi-page)/tracing.mdx\",\"Tracing\",\"HBase used to depend on the HTrace project for tracing. After the Apache HTrace project moved to the Attic/retired, we decided to move to OpenTelemetry in HBASE-22120.\",\"/docs/tracing\",{\"_43\":188},\"(multi-page)/hbtop.mdx\",\"hbtop\",\"hbtop is a real-time monitoring tool for HBase like Unix's top command. It can display summary information as well as metrics per Region/Namespace/Table/RegionServer. In this tool, you can see the metrics sorted by a selected field and filter the metrics to see only metrics you really want to see.\",\"/docs/hbtop\",{\"_43\":193},\"(multi-page)/community.mdx\",\"Community\",\"HBase community decisions, release managers, JIRA policies, commit message format, and guidelines for feature branches.\",\"/docs/community\",{\"_43\":198},\"(multi-page)/zookeeper.mdx\",\"ZooKeeper\",\"A distributed Apache HBase installation depends on a running ZooKeeper cluster. All participating nodes and clients need to be able to access the running ZooKeeper ensemble.\",\"/docs/zookeeper\",{\"_43\":203},\"(multi-page)#39\",\"Infrastructure \u0026 Tools\",\"(multi-page)/amv2.mdx\",\"AMv2 Description for Devs\",\"The AssignmentManager (AM) in HBase Master manages assignment of Regions over a cluster of RegionServers.\",\"/docs/amv2\",{\"_43\":210},\"(multi-page)/pv2.mdx\",\"Procedure Framework (PV2)\",\"Procedure v2 ...aims to provide a unified way to build...multi-step procedures with a rollback/roll-forward ability in case of failure (e.g. create/delete table) — Matteo Bertozzi, the author of Pv2.\",\"/docs/pv2\",{\"_43\":215},\"(multi-page)/protobuf.mdx\",\"Protobuf in HBase\",\"Detailed guide on how HBase uses Protocol Buffers for serialization, RPC interfaces, and coprocessor endpoints, including shading and versioning considerations.\",\"/docs/protobuf\",{\"_43\":220},\"(multi-page)#35\",\"Internals\",\"(multi-page)/unit-testing.mdx\",\"Unit Testing HBase Applications\",\"This chapter discusses unit testing your HBase application using JUnit, Mockito, MRUnit, and HBaseTestingUtility.\",\"/docs/unit-testing\",{\"_43\":227},\"Building and Developing Apache HBase\",{\"_13\":304,\"_21\":38,\"_15\":232,\"_27\":305,\"_24\":-7,\"_9\":306,\"_32\":307},[238,239,240,241,242,243,244,245,246,247,248],\"(multi-page)/building-and-developing\",{\"_34\":237},\"(multi-page)/building-and-developing/meta.json\",{\"_13\":299,\"_21\":38,\"_15\":300,\"_27\":301,\"_24\":-7,\"_9\":302,\"_32\":303},{\"_13\":294,\"_21\":38,\"_15\":295,\"_27\":296,\"_24\":-7,\"_9\":297,\"_32\":298},{\"_13\":289,\"_21\":38,\"_15\":290,\"_27\":291,\"_24\":-7,\"_9\":292,\"_32\":293},{\"_13\":284,\"_21\":38,\"_15\":285,\"_27\":286,\"_24\":-7,\"_9\":287,\"_32\":288},{\"_13\":279,\"_21\":38,\"_15\":280,\"_27\":281,\"_24\":-7,\"_9\":282,\"_32\":283},{\"_13\":274,\"_21\":38,\"_15\":275,\"_27\":276,\"_24\":-7,\"_9\":277,\"_32\":278},{\"_13\":269,\"_21\":38,\"_15\":270,\"_27\":271,\"_24\":-7,\"_9\":272,\"_32\":273},{\"_13\":264,\"_21\":38,\"_15\":265,\"_27\":266,\"_24\":-7,\"_9\":267,\"_32\":268},{\"_13\":259,\"_21\":38,\"_15\":260,\"_27\":261,\"_24\":-7,\"_9\":262,\"_32\":263},{\"_13\":254,\"_21\":38,\"_15\":255,\"_27\":256,\"_24\":-7,\"_9\":257,\"_32\":258},{\"_13\":249,\"_21\":38,\"_15\":250,\"_27\":251,\"_24\":-7,\"_9\":252,\"_32\":253},\"(multi-page)/building-and-developing/developer-guidelines.mdx\",\"Developer Guidelines\",\"Code standards, interface classifications, formatting conventions, Git best practices, and patch submission guidelines for HBase contributors.\",\"/docs/building-and-developing/developer-guidelines\",{\"_43\":249},\"(multi-page)/building-and-developing/tests.mdx\",\"Tests\",\"Writing and running HBase unit tests, integration tests, and ChaosMonkey destructive tests for comprehensive test coverage.\",\"/docs/building-and-developing/tests\",{\"_43\":254},\"(multi-page)/building-and-developing/updating-landing.mdx\",\"Updating hbase.apache.org\",\"Contributing to and publishing the HBase website and documentation using gitpubsub mechanism.\",\"/docs/building-and-developing/updating-landing\",{\"_43\":259},\"(multi-page)/building-and-developing/generating-documentation.mdx\",\"Generating the HBase Reference Guide\",\"Building HBase documentation from MDX markup.\",\"/docs/building-and-developing/generating-documentation\",{\"_43\":264},\"(multi-page)/building-and-developing/announcing.mdx\",\"Announcing Releases\",\"Email template and guidelines for announcing new HBase releases to the community and mailing lists.\",\"/docs/building-and-developing/announcing\",{\"_43\":269},\"(multi-page)/building-and-developing/voting.mdx\",\"Voting on Release Candidates\",\"Baseline and additional verification procedures for voting on HBase release candidates including checksums, signatures, and testing.\",\"/docs/building-and-developing/voting\",{\"_43\":274},\"(multi-page)/building-and-developing/releasing.mdx\",\"Releasing Apache HBase\",\"Complete guide to creating HBase release candidates including building, signing, staging artifacts, and publishing releases.\",\"/docs/building-and-developing/releasing\",{\"_43\":279},\"(multi-page)/building-and-developing/building.mdx\",\"Building Apache HBase\",\"Maven build commands, JDK requirements, Hadoop version selection, and building HBase from source including protobuf and thrift generation.\",\"/docs/building-and-developing/building\",{\"_43\":284},\"(multi-page)/building-and-developing/ides.mdx\",\"IDEs\",\"Setting up Eclipse and IntelliJ IDEA for HBase development including formatters, plugins, and Maven integration.\",\"/docs/building-and-developing/ides\",{\"_43\":289},\"(multi-page)/building-and-developing/repositories.mdx\",\"Apache HBase Repositories\",\"List of Apache HBase Git repositories including main HBase, connectors, operator tools, website, and third-party libraries.\",\"/docs/building-and-developing/repositories\",{\"_43\":294},\"(multi-page)/building-and-developing/getting-involved.mdx\",\"Getting Involved\",\"How to contribute to Apache HBase including mailing lists, Slack, IRC, JIRA, and guidelines for reporting effective issues.\",\"/docs/building-and-developing/getting-involved\",{\"_43\":299},\"(multi-page)/building-and-developing/index.mdx\",\"Comprehensive guide for building, testing, releasing, and contributing to Apache HBase.\",\"/docs/building-and-developing\",{\"_43\":304},\"Apache HBase Operational Management\",{\"_13\":362,\"_21\":38,\"_15\":308,\"_27\":363,\"_24\":-7,\"_9\":364,\"_32\":365},[314,315,316,317,318,319,320,321],\"(multi-page)/operational-management\",{\"_34\":313},\"(multi-page)/operational-management/meta.json\",{\"_13\":357,\"_21\":38,\"_15\":358,\"_27\":359,\"_24\":-7,\"_9\":360,\"_32\":361},{\"_13\":352,\"_21\":38,\"_15\":353,\"_27\":354,\"_24\":-7,\"_9\":355,\"_32\":356},{\"_13\":347,\"_21\":38,\"_15\":348,\"_27\":349,\"_24\":-7,\"_9\":350,\"_32\":351},{\"_13\":342,\"_21\":38,\"_15\":343,\"_27\":344,\"_24\":-7,\"_9\":345,\"_32\":346},{\"_13\":337,\"_21\":38,\"_15\":338,\"_27\":339,\"_24\":-7,\"_9\":340,\"_32\":341},{\"_13\":332,\"_21\":38,\"_15\":333,\"_27\":334,\"_24\":-7,\"_9\":335,\"_32\":336},{\"_13\":327,\"_21\":38,\"_15\":328,\"_27\":329,\"_24\":-7,\"_9\":330,\"_32\":331},{\"_13\":322,\"_21\":38,\"_15\":323,\"_27\":324,\"_24\":-7,\"_9\":325,\"_32\":326},\"(multi-page)/operational-management/region-and-capacity.mdx\",\"Region \u0026 Capacity Management\",\"Managing HBase regions including compaction, splits, merges, capacity planning, RegionServer grouping, and region normalization.\",\"/docs/operational-management/region-and-capacity\",{\"_43\":322},\"(multi-page)/operational-management/table-rename.mdx\",\"Table Rename\",\"How to rename HBase tables using snapshots without downtime or data loss.\",\"/docs/operational-management/table-rename\",{\"_43\":327},\"(multi-page)/operational-management/backup-and-snapshots.mdx\",\"Backup \u0026 Snapshots\",\"HBase backup strategies and snapshot operations for data protection, including full cluster backups and live cluster snapshots.\",\"/docs/operational-management/backup-and-snapshots\",{\"_43\":332},\"(multi-page)/operational-management/running-multiple-workloads-on-a-single-cluster.mdx\",\"Running Multiple Workloads On a Single Cluster\",\"Managing multiple workloads on HBase clusters using quotas, request queues, and priority mechanisms for resource allocation.\",\"/docs/operational-management/running-multiple-workloads-on-a-single-cluster\",{\"_43\":337},\"(multi-page)/operational-management/cluster-replication.mdx\",\"Cluster Replication\",\"Setting up and managing HBase cluster replication for disaster recovery, data aggregation, and geographic distribution of data.\",\"/docs/operational-management/cluster-replication\",{\"_43\":342},\"(multi-page)/operational-management/metrics-and-monitoring.mdx\",\"Metrics \u0026 Monitoring\",\"HBase metrics system configuration, JMX monitoring, master and RegionServer metrics, and integration with monitoring tools.\",\"/docs/operational-management/metrics-and-monitoring\",{\"_43\":347},\"(multi-page)/operational-management/node.mdx\",\"Node Management\",\"Managing HBase cluster nodes including decommissioning RegionServers, rolling restarts, and draining regions for maintenance.\",\"/docs/operational-management/node\",{\"_43\":352},\"(multi-page)/operational-management/tools.mdx\",\"HBase Tools and Utilities\",\"Command-line tools for HBase administration, analysis, and debugging including canary, HBCK2, WAL tools, and MapReduce utilities.\",\"/docs/operational-management/tools\",{\"_43\":357},\"(multi-page)/operational-management/index.mdx\",\"This chapter will cover operational tools and practices required of a running Apache HBase cluster.\",\"/docs/operational-management\",{\"_43\":362},\"(multi-page)#31\",\"Operations \u0026 Development\",\"(multi-page)/case-studies.mdx\",\"Apache HBase Case Studies\",\"Performance and troubleshooting case studies for diagnosing Apache HBase cluster issues.\",\"/docs/case-studies\",{\"_43\":368},\"(multi-page)/troubleshooting.mdx\",\"Troubleshooting and Debugging Apache HBase\",\"Comprehensive guide to troubleshooting and debugging HBase issues including logs, tools, common problems, and solutions.\",\"/docs/troubleshooting\",{\"_43\":373},\"(multi-page)/profiler.mdx\",\"Profiler Servlet\",\"Integrated, on-demand profiling via the Async Profiler project.\",\"/docs/profiler\",{\"_43\":378},\"(multi-page)/performance.mdx\",\"Apache HBase Performance Tuning\",\"Comprehensive performance tuning guide covering OS configuration, network optimization, JVM tuning, schema design, read/write patterns, and HDFS optimization for HBase clusters.\",\"/docs/performance\",{\"_43\":383},\"(multi-page)#26\",\"Performance \u0026 Troubleshooting\",\"(multi-page)/cp.mdx\",\"Apache HBase Coprocessors\",\"The coprocessor framework provides mechanisms for running your custom code directly on the RegionServers managing your data.\",\"/docs/cp\",{\"_43\":390},\"(multi-page)/spark.mdx\",\"HBase and Spark\",\"Apache Spark is a software framework that is used to process data in memory in a distributed manner, and is replacing MapReduce in many use cases.\",\"/docs/spark\",{\"_43\":395},\"(multi-page)/thrift-filter-language.mdx\",\"Thrift API and Filter Language\",\"Apache Thrift is a cross-platform, cross-language development framework. HBase includes a Thrift API and filter language. The Thrift API relies on client and server processes.\",\"/docs/thrift-filter-language\",{\"_43\":400},\"(multi-page)/external-apis.mdx\",\"Apache HBase External APIs\",\"This chapter will cover access to Apache HBase either through non-Java languages and through custom protocols.\",\"/docs/external-apis\",{\"_43\":405},\"(multi-page)/hbase-apis.mdx\",\"Apache HBase APIs\",\"This chapter provides information about performing operations using HBase native APIs.\",\"/docs/hbase-apis\",{\"_43\":410},\"(multi-page)#20\",\"APIs \u0026 Integration\",\"(multi-page)/sync-replication.mdx\",\"Synchronous Replication\",\"Setting up synchronous replication between HBase clusters for strong consistency and automatic failover capabilities.\",\"/docs/sync-replication\",{\"_43\":417},\"Backup and Restore\",{\"_13\":452,\"_21\":38,\"_15\":422,\"_27\":453,\"_24\":-7,\"_9\":454,\"_32\":455},[428,429,430,431],\"(multi-page)/backup-restore\",{\"_34\":427},\"(multi-page)/backup-restore/meta.json\",{\"_13\":447,\"_21\":38,\"_15\":448,\"_27\":449,\"_24\":-7,\"_9\":450,\"_32\":451},{\"_13\":442,\"_21\":38,\"_15\":443,\"_27\":444,\"_24\":-7,\"_9\":445,\"_32\":446},{\"_13\":437,\"_21\":38,\"_15\":438,\"_27\":439,\"_24\":-7,\"_9\":440,\"_32\":441},{\"_13\":432,\"_21\":38,\"_15\":433,\"_27\":434,\"_24\":-7,\"_9\":435,\"_32\":436},\"(multi-page)/backup-restore/additional-topics.mdx\",\"Additional Topics\",\"Configuration keys, security considerations, and best practices for HBase backup and restore operations.\",\"/docs/backup-restore/additional-topics\",{\"_43\":432},\"(multi-page)/backup-restore/administration.mdx\",\"Administration of Backup Images\",\"Managing HBase backup images including listing, describing, deleting, and merging backup sets for efficient storage.\",\"/docs/backup-restore/administration\",{\"_43\":437},\"(multi-page)/backup-restore/commands.mdx\",\"Backup and Restore commands\",\"Command-line utilities for creating, restoring, and merging HBase backups including full and incremental backup operations.\",\"/docs/backup-restore/commands\",{\"_43\":442},\"(multi-page)/backup-restore/overview.mdx\",\"Overview\",\"Introduction to HBase backup and restore feature, including full and incremental backups for disaster recovery and point-in-time recovery.\",\"/docs/backup-restore/overview\",{\"_43\":447},\"(multi-page)/backup-restore/index.mdx\",\"Comprehensive guide to HBase backup and restore capabilities for data protection, disaster recovery, and point-in-time recovery.\",\"/docs/backup-restore\",{\"_43\":452},\"(multi-page)/offheap-read-write.mdx\",\"RegionServer Off-Heap Read/Write Path\",\"Using off-heap memory for HBase read and write paths to reduce GC pressure and improve P99/P999 RPC latencies.\",\"/docs/offheap-read-write\",{\"_43\":456},\"(multi-page)/inmemory-compaction.mdx\",\"In-memory Compaction\",\"Accordion feature that applies LSM compaction to MemStore while data is in RAM, reducing write amplification and improving performance.\",\"/docs/inmemory-compaction\",{\"_43\":461},\"(multi-page)#15\",\"Advanced Features\",\"Architecture\",{\"_13\":545,\"_21\":38,\"_15\":468,\"_27\":546,\"_24\":-7,\"_9\":547,\"_32\":548},[474,475,476,477,478,479,480,481,482,483,484,485],\"(multi-page)/architecture\",{\"_34\":473},\"(multi-page)/architecture/meta.json\",{\"_13\":541,\"_21\":38,\"_15\":448,\"_27\":542,\"_24\":-7,\"_9\":543,\"_32\":544},{\"_13\":536,\"_21\":38,\"_15\":537,\"_27\":538,\"_24\":-7,\"_9\":539,\"_32\":540},{\"_13\":531,\"_21\":38,\"_15\":532,\"_27\":533,\"_24\":-7,\"_9\":534,\"_32\":535},{\"_13\":526,\"_21\":38,\"_15\":527,\"_27\":528,\"_24\":-7,\"_9\":529,\"_32\":530},{\"_13\":521,\"_21\":38,\"_15\":522,\"_27\":523,\"_24\":-7,\"_9\":524,\"_32\":525},{\"_13\":516,\"_21\":38,\"_15\":517,\"_27\":518,\"_24\":-7,\"_9\":519,\"_32\":520},{\"_13\":511,\"_21\":38,\"_15\":512,\"_27\":513,\"_24\":-7,\"_9\":514,\"_32\":515},{\"_13\":506,\"_21\":38,\"_15\":507,\"_27\":508,\"_24\":-7,\"_9\":509,\"_32\":510},{\"_13\":501,\"_21\":38,\"_15\":502,\"_27\":503,\"_24\":-7,\"_9\":504,\"_32\":505},{\"_13\":496,\"_21\":38,\"_15\":497,\"_27\":498,\"_24\":-7,\"_9\":499,\"_32\":500},{\"_13\":491,\"_21\":38,\"_15\":492,\"_27\":493,\"_24\":-7,\"_9\":494,\"_32\":495},{\"_13\":486,\"_21\":38,\"_15\":487,\"_27\":488,\"_24\":-7,\"_9\":489,\"_32\":490},\"(multi-page)/architecture/snapshot-scanner.mdx\",\"Scan Over Snapshot\",\"Using TableSnapshotScanner to scan HBase snapshots directly from HDFS, bypassing RegionServers for better performance.\",\"/docs/architecture/snapshot-scanner\",{\"_43\":486},\"(multi-page)/architecture/hbase-mob.mdx\",\"Storing Medium-sized Objects (MOB)\",\"Optimized storage and handling of medium-sized objects (100KB-10MB) in HBase using the MOB feature for improved performance.\",\"/docs/architecture/hbase-mob\",{\"_43\":491},\"(multi-page)/architecture/timeline-consistent-reads.mdx\",\"Timeline-consistent High Available Reads\",\"Using region replicas to achieve high availability for reads with timeline consistency, reducing read unavailability during failures.\",\"/docs/architecture/timeline-consistent-reads\",{\"_43\":496},\"(multi-page)/architecture/hdfs.mdx\",\"HDFS\",\"How HBase leverages HDFS for distributed storage, including NameNode and DataNode architecture and file replication.\",\"/docs/architecture/hdfs\",{\"_43\":501},\"(multi-page)/architecture/bulk-loading.mdx\",\"Bulk Loading\",\"Efficient methods for loading large datasets into HBase using MapReduce to generate HFiles and directly load them into the cluster.\",\"/docs/architecture/bulk-loading\",{\"_43\":506},\"(multi-page)/architecture/regions.mdx\",\"Regions\",\"Understanding HBase regions, stores, memstore, write-ahead log (WAL), compaction, splits, and region management strategies.\",\"/docs/architecture/regions\",{\"_43\":511},\"(multi-page)/architecture/regionserver.mdx\",\"RegionServer\",\"HBase RegionServer implementation, interfaces, read/write paths, block cache, memstore management, and performance tuning.\",\"/docs/architecture/regionserver\",{\"_43\":516},\"(multi-page)/architecture/master.mdx\",\"Master\",\"HBase Master server responsibilities including RegionServer monitoring, metadata operations, load balancing, and failover behavior.\",\"/docs/architecture/master\",{\"_43\":521},\"(multi-page)/architecture/client-request-filters.mdx\",\"Client Request Filters\",\"Using filters with Get and Scan operations to efficiently query HBase data, including comparison, column, row, and utility filters.\",\"/docs/architecture/client-request-filters\",{\"_43\":526},\"(multi-page)/architecture/client.mdx\",\"Client\",\"HBase client architecture, connection management, metadata caching, and client-side configuration for optimal performance.\",\"/docs/architecture/client\",{\"_43\":531},\"(multi-page)/architecture/catalog-tables.mdx\",\"Catalog Tables\",\"Understanding hbase:meta catalog table structure, location tracking, and how HBase maintains region metadata.\",\"/docs/architecture/catalog-tables\",{\"_43\":536},\"(multi-page)/architecture/overview.mdx\",\"Introduction to HBase as a NoSQL distributed database, key features, scalability characteristics, and when to use HBase.\",\"/docs/architecture/overview\",{\"_43\":541},\"(multi-page)/architecture/index.mdx\",\"Comprehensive guide to HBase architecture including client-server model, regions, WAL, compaction, and advanced features.\",\"/docs/architecture\",{\"_43\":545},\"Security\",{\"_13\":595,\"_21\":38,\"_15\":549,\"_27\":596,\"_24\":-7,\"_9\":597,\"_32\":598},[555,556,557,558,559,560,561],\"(multi-page)/security\",{\"_34\":554},\"(multi-page)/security/meta.json\",{\"_13\":590,\"_21\":38,\"_15\":591,\"_27\":592,\"_24\":-7,\"_9\":593,\"_32\":594},{\"_13\":8,\"_21\":38,\"_15\":587,\"_27\":588,\"_24\":-7,\"_9\":10,\"_32\":589},{\"_13\":582,\"_21\":38,\"_15\":583,\"_27\":584,\"_24\":-7,\"_9\":585,\"_32\":586},{\"_13\":577,\"_21\":38,\"_15\":578,\"_27\":579,\"_24\":-7,\"_9\":580,\"_32\":581},{\"_13\":572,\"_21\":38,\"_15\":573,\"_27\":574,\"_24\":-7,\"_9\":575,\"_32\":576},{\"_13\":567,\"_21\":38,\"_15\":568,\"_27\":569,\"_24\":-7,\"_9\":570,\"_32\":571},{\"_13\":562,\"_21\":38,\"_15\":563,\"_27\":564,\"_24\":-7,\"_9\":565,\"_32\":566},\"(multi-page)/security/example.mdx\",\"Security Configuration Example\",\"This configuration example includes support for HFile v3, ACLs, Visibility Labels, and transparent encryption of data at rest and the WAL. All options have been discussed separately in the sections above.\",\"/docs/security/example\",{\"_43\":562},\"(multi-page)/security/data-access.mdx\",\"Securing Access To Your Data\",\"Role-based access control (RBAC), visibility labels, and data encryption strategies for securing HBase data at rest and in transit.\",\"/docs/security/data-access\",{\"_43\":567},\"(multi-page)/security/hdfs-and-zookeeper-access.mdx\",\"Securing Access to HDFS and ZooKeeper\",\"Secure HBase requires secure ZooKeeper and HDFS so that users cannot access and/or modify the metadata and data from under HBase. HBase uses HDFS (or configured file system) to keep its data files as well as write ahead logs (WALs) and other data. HBase uses ZooKeeper to store some metadata for operations (master address, table locks, recovery state, etc).\",\"/docs/security/hdfs-and-zookeeper-access\",{\"_43\":572},\"(multi-page)/security/tls.mdx\",\"Transport Level Security (TLS) in HBase RPC communication\",\"Configuring TLS encryption for secure HBase client-server and Master-RegionServer communication without downtime.\",\"/docs/security/tls\",{\"_43\":577},\"(multi-page)/security/user-access.mdx\",\"Simple User Access to Apache HBase\",\"Setting up simple SASL authentication for HBase clients without Kerberos, using username/password-based access control.\",\"/docs/security/user-access\",{\"_43\":582},\"Secure Client Access to Apache HBase\",\"Configuring Kerberos-based secure authentication for HBase clients, including server and client setup procedures.\",{\"_43\":8},\"(multi-page)/security/web-ui.mdx\",\"Web UI Security\",\"HBase provides mechanisms to secure various components and aspects of HBase and how it relates to the rest of the Hadoop infrastructure, as well as clients and resources outside Hadoop.\",\"/docs/security/web-ui\",{\"_43\":590},\"(multi-page)/security/index.mdx\",\"Comprehensive guide to securing Apache HBase, including authentication, authorization, encryption, and access control mechanisms.\",\"/docs/security\",{\"_43\":595},\"(multi-page)/mapreduce.mdx\",\"HBase and MapReduce\",\"Guide to using Apache HBase with MapReduce including configuration, examples, and best practices.\",\"/docs/mapreduce\",{\"_43\":599},\"(multi-page)/regionserver-sizing.mdx\",\"RegionServer Sizing Rules of Thumb\",\"Memory sizing guidelines, rowkey design patterns, schema case studies, and performance optimization tips for HBase RegionServers.\",\"/docs/regionserver-sizing\",{\"_43\":604},\"(multi-page)/schema-design.mdx\",\"HBase and Schema Design\",\"Comprehensive guide to designing HBase schemas, including table and column family design, rowkey strategies, and best practices for optimal performance.\",\"/docs/schema-design\",{\"_43\":609},\"(multi-page)/datamodel.mdx\",\"Data Model\",\"In HBase, data is stored in tables, which have rows and columns. This is a terminology overlap with relational databases (RDBMSs), but this is not a helpful analogy. Instead, it can be helpful to think of an HBase table as a multi-dimensional map.\",\"/docs/datamodel\",{\"_43\":614},\"(multi-page)#8\",\"Core Concepts\",\"(multi-page)/shell.mdx\",\"The Apache HBase Shell\",\"Guide to using the HBase Shell including scripting, tricks, and advanced features.\",\"/docs/shell\",{\"_43\":621},\"Upgrading\",{\"_13\":656,\"_21\":38,\"_15\":626,\"_27\":657,\"_24\":-7,\"_9\":658,\"_32\":659},[632,633,634,635],\"(multi-page)/upgrading\",{\"_34\":631},\"(multi-page)/upgrading/meta.json\",{\"_13\":651,\"_21\":38,\"_15\":652,\"_27\":653,\"_24\":-7,\"_9\":654,\"_32\":655},{\"_13\":646,\"_21\":38,\"_15\":647,\"_27\":648,\"_24\":-7,\"_9\":649,\"_32\":650},{\"_13\":641,\"_21\":38,\"_15\":642,\"_27\":643,\"_24\":-7,\"_9\":644,\"_32\":645},{\"_13\":636,\"_21\":38,\"_15\":637,\"_27\":638,\"_24\":-7,\"_9\":639,\"_32\":640},\"(multi-page)/upgrading/paths.mdx\",\"Upgrade Paths\",\"Detailed upgrade paths and compatibility considerations when upgrading between HBase major versions (2.x to 3.x, 1.x to 2.x, etc.).\",\"/docs/upgrading/paths\",{\"_43\":636},\"(multi-page)/upgrading/rollback.mdx\",\"Rollback\",\"How to rollback an HBase upgrade to restore the cluster to a previous version, including backup procedures and data recovery steps.\",\"/docs/upgrading/rollback\",{\"_43\":641},\"(multi-page)/upgrading/rolling.mdx\",\"Rolling Upgrades\",\"How to perform rolling upgrades across HBase versions that are binary or wire compatible without cluster downtime.\",\"/docs/upgrading/rolling\",{\"_43\":646},\"(multi-page)/upgrading/version-number.mdx\",\"HBase version number and compatibility\",\"Understanding HBase semantic versioning scheme and compatibility guarantees across major, minor, and patch versions.\",\"/docs/upgrading/version-number\",{\"_43\":651},\"(multi-page)/upgrading/index.mdx\",\"Guide to upgrading Apache HBase between major versions, including requirements, compatibility considerations, and step-by-step procedures.\",\"/docs/upgrading\",{\"_43\":656},\"Configuration\",{\"_13\":708,\"_21\":38,\"_15\":660,\"_27\":709,\"_24\":-7,\"_9\":710,\"_32\":711},[666,667,668,669,670,671,672],\"(multi-page)/configuration\",{\"_34\":665},\"(multi-page)/configuration/meta.json\",{\"_13\":703,\"_21\":38,\"_15\":704,\"_27\":705,\"_24\":-7,\"_9\":706,\"_32\":707},{\"_13\":698,\"_21\":38,\"_15\":699,\"_27\":700,\"_24\":-7,\"_9\":701,\"_32\":702},{\"_13\":693,\"_21\":38,\"_15\":694,\"_27\":695,\"_24\":-7,\"_9\":696,\"_32\":697},{\"_13\":688,\"_21\":38,\"_15\":689,\"_27\":690,\"_24\":-7,\"_9\":691,\"_32\":692},{\"_13\":683,\"_21\":38,\"_15\":684,\"_27\":685,\"_24\":-7,\"_9\":686,\"_32\":687},{\"_13\":678,\"_21\":38,\"_15\":679,\"_27\":680,\"_24\":-7,\"_9\":681,\"_32\":682},{\"_13\":673,\"_21\":38,\"_15\":674,\"_27\":675,\"_24\":-7,\"_9\":676,\"_32\":677},\"(multi-page)/configuration/dynamic.mdx\",\"Dynamic Configuration\",\"How to change HBase configuration properties dynamically without server restart using update_config commands.\",\"/docs/configuration/dynamic\",{\"_43\":673},\"(multi-page)/configuration/important.mdx\",\"The Important Configurations\",\"Critical HBase configurations divided into required settings and recommended optimizations for production clusters.\",\"/docs/configuration/important\",{\"_43\":678},\"(multi-page)/configuration/example.mdx\",\"Example Configurations\",\"Sample configuration files and setup examples for distributed HBase clusters.\",\"/docs/configuration/example\",{\"_43\":683},\"(multi-page)/configuration/default.mdx\",\"Default Configuration\",\"HBase default configuration properties and how to customize them via hbase-site.xml for site-specific settings.\",\"/docs/configuration/default\",{\"_43\":688},\"(multi-page)/configuration/confirm.mdx\",\"Running and Confirming Your Installation\",\"Steps to start HBase services and verify your installation is working correctly.\",\"/docs/configuration/confirm\",{\"_43\":693},\"(multi-page)/configuration/hbase-run-models.mdx\",\"HBase run modes: Standalone and Distributed\",\"Understanding HBase deployment modes: standalone mode for development and distributed mode for production clusters.\",\"/docs/configuration/hbase-run-models\",{\"_43\":698},\"(multi-page)/configuration/basic-prerequisites.mdx\",\"Basic Prerequisites\",\"This section lists required services and some required system configuration.\",\"/docs/configuration/basic-prerequisites\",{\"_43\":703},\"(multi-page)/configuration/index.mdx\",\"Complete guide to HBase configuration including all settings, tuning parameters, and best practices.\",\"/docs/configuration\",{\"_43\":708},\"(multi-page)#4\",\"Configuration \u0026 Setup\",\"All docs for LLMs\",\"/llms-full.txt\",\"external\",\"(multi-page)/getting-started.mdx\",\"Getting Started\",\"Quick start to get you up and run a single-node, standalone instance of HBase.\",\"/docs/getting-started\",{\"_43\":717},\"(multi-page)/index.mdx\",\"Preface\",\"This is the official reference guide for the HBase version it ships with.\",\"/docs\",{\"_43\":722},\"(multi-page)#0\"]\n");</script><!--$--><script>window.__reactRouterContext.streamController.close();</script><!--/$--><!--/$--></body></html>