apache / apache/beam

[Feature Request]: Add a basic doc explaining Beam's security model

Open
#30,911 8 comments 0 reactions 0 assignees View on GitHub
awaiting triage new feature P3 website
Dominant language
Java
Stars
8.7k
Forks
4.7k
Avg merge
1d 20h
Merged PRs (30d)
196

Description

### What would you like to happen?

Explain a few concepts like:
- Beam allows users to run arbitrary code. And Beam does not have different code privilege levels. (Because of that some code execution vulnerabilities will be normal within Beam's model.)
- Beam work with different runners. Runners security models will apply in the execution environment (e.g. cluster models might allow resource access across running jobs.) (Because of that runner related security issues will be best addressed with the specific runners.)
- ...

### Issue Priority

Priority: 3 (nice-to-have improvement)

### Issue Components

- [ ] Component: Python SDK
- [ ] Component: Java SDK
- [ ] Component: Go SDK
- [ ] Component: Typescript SDK
- [ ] Component: IO connector
- [ ] Component: Beam YAML
- [ ] Component: Beam examples
- [ ] Component: Beam playground
- [ ] Component: Beam katas
- [X] Component: Website
- [ ] Component: Spark Runner
- [ ] Component: Flink Runner
- [ ] Component: Samza Runner
- [ ] Component: Twister2 Runner
- [ ] Component: Hazelcast Jet Runner
- [ ] Component: Google Cloud Dataflow Runner

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.