hbase-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Andrew Purtell (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HBASE-8369) MapReduce over snapshot files
Date Fri, 01 Nov 2013 22:11:19 GMT

    [ https://issues.apache.org/jira/browse/HBASE-8369?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13811706#comment-13811706
] 

Andrew Purtell commented on HBASE-8369:
---------------------------------------

This is a fine feature for performance but needs a fat release note indicating it is incompatible
with security features we have now and planned. 

ACLs: Since the AccessController is bypassed, only file level permissions can provide protection.
Perhaps someday if HDFS has file ACLs we can push CF ACLs down, that would be a useful improvement
and maybe the best we can do here. 

Cell ACLs and visibility labels: The code that does access or visibility checking lives in
the regionserver and cannot be trusted to filter cell if running in a mapreduce task with
untrustable user code. 

Encryption: Unless the reader has access to the cluster master key the files won't be readable.
That's the desired outcome. :-) Shipping the master key to a MR job where untrustable user
code can steal it would not be advisable. 

> MapReduce over snapshot files
> -----------------------------
>
>                 Key: HBASE-8369
>                 URL: https://issues.apache.org/jira/browse/HBASE-8369
>             Project: HBase
>          Issue Type: New Feature
>          Components: mapreduce, snapshots
>            Reporter: Enis Soztutar
>            Assignee: Enis Soztutar
>             Fix For: 0.98.0
>
>         Attachments: HBASE-8369-0.94.patch, HBASE-8369-0.94_v2.patch, HBASE-8369-0.94_v3.patch,
HBASE-8369-0.94_v4.patch, HBASE-8369-0.94_v5.patch, HBASE-8369-trunk_v1.patch, HBASE-8369-trunk_v2.patch,
HBASE-8369-trunk_v3.patch, hbase-8369_v0.patch, hbase-8369_v5.patch, hbase-8369_v6.patch
>
>
> The idea is to add an InputFormat, which can run the mapreduce job over snapshot files
directly bypassing hbase server layer. The IF is similar in usage to TableInputFormat, taking
a Scan object from the user, but instead of running from an online table, it runs from a table
snapshot. We do one split per region in the snapshot, and open an HRegion inside the RecordReader.
A RegionScanner is used internally for doing the scan without any HRegionServer bits. 
> Users have been asking and searching for ways to run MR jobs by reading directly from
hfiles, so this allows new use cases if reading from stale data is ok:
>  - Take snapshots periodically, and run MR jobs only on snapshots.
>  - Export snapshots to remote hdfs cluster, run the MR jobs at that cluster without HBase
cluster.
>  - (Future use case) Combine snapshot data with online hbase data: Scan from yesterday's
snapshot, but read today's data from online hbase cluster. 



--
This message was sent by Atlassian JIRA
(v6.1#6144)

Mime
View raw message