《SNIA-SDC23-Fajth-Re-thinking-Security-in-a-Distributed-Storage-System_0.pdf》由会员分享,可在线阅读,更多相关《SNIA-SDC23-Fajth-Re-thinking-Security-in-a-Distributed-Storage-System_0.pdf(81页珍藏版)》请在三个皮匠报告上搜索。
1、Virtual Conference September 28-29,20211Re-thinking security in a distributed storage systemApache Ozone SecurityIstvan Fajth-Apache Ozone PMC-Cloudera Inc.A brief project overview Security in Apache Ozone Tokens Public Key Infrastructure23Apache Ozone4Papers:GFS Mapreduce20032006Sub-projects:Common
2、 HDFS Mapreduce YARN20092014HDFS-7240 Scaling HDFS2018Apache Ozone is a highly scalable,distributed storage for Analytics,Big data and Cloud Native applications.Ozone supports S3 compatible object APIs as well as a Hadoop Compatible File System implementation.It is optimized for both efficient objec
3、t store and file system operations.5/volume 1volume 2volume nS3 volumebucket 1bucket 2bucket nkey 1key 2key nObject StoreFileSystemVolumeA bucket groupTop level directoryBucketA bucketDirectory in a top level directoryKeyA keyDirectory or file in a bucket or directory6Ozone FileSystem APIOzone CLIS3
4、 GatewayHTTPFS GatewayOzone Native RPC ClientOzone Client LayerOzone ManagerOzone ManagerOzone ManagerOzone Metadata LayerStorage Container ManagerStorage Container ManagerStorage Container ManagerOzone DatanodeOzone DatanodeOzone DatanodeHDDS Storage LayerMetadata operationsData TransferData Replic
5、ationOzone ReconOzone Monitoring8Ozone ManagerOzone ManagerOzone ManagerLeaderFollowerFollowerReplicationA brief project overview Security in Apache Ozone Tokens Public Key Infrastructure910Ozone FileSystem APIOzone CLIS3 GatewayHTTPFS GatewayOzone Native RPC ClientOzone Client LayerOzone ManagerOzo
6、ne Metadata LayerStorage Container ManagerStorage Container ManagerStorage Container ManagerOzone DatanodeOzone DatanodeOzone DatanodeHDDS Storage LayerOzone ReconOzone MonitoringClientsAuthentication10Ozone FileSystem APIOzone CLIS3 GatewayHTTPFS GatewayOzone Native RPC ClientOzone Client LayerOzon