cassandra-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Sam Tunnicliffe (JIRA)" <>
Subject [jira] [Updated] (CASSANDRA-14497) Add Role login cache
Date Thu, 14 Jun 2018 11:52:00 GMT


Sam Tunnicliffe updated CASSANDRA-14497:
    Fix Version/s: 4.0
           Status: Patch Available  (was: Open)

Sorry it's a bit late, but I found some time to get my patch tidied up. It goes a bit beyond
the scope of the original description to ensure that all Role info can be served from the
cache: login privilege, superuser status, custom role options as well as the member-of list.

> Add Role login cache
> --------------------
>                 Key: CASSANDRA-14497
>                 URL:
>             Project: Cassandra
>          Issue Type: Improvement
>          Components: Auth
>            Reporter: Jay Zhuang
>            Assignee: Sam Tunnicliffe
>            Priority: Major
>              Labels: security
>             Fix For: 4.0
> The [{{ClientState.login()}}|]
function is used for all auth message: [{{}}|].
But the [{{role.canLogin}}|]
information is not cached. So it hits the database every time: [{{}}|].
For a cluster with lots of new connections, it's causing performance issue. The mitigation
for us is to increase the {{system_auth}} replication factor to match the number of nodes,
so [{{local_one}}|]
would be very cheap. The P99 dropped immediately, but I don't think it is not a good solution.
> I would purpose to add {{Role.canLogin}} to the RolesCache to improve the auth performance.

This message was sent by Atlassian JIRA

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message