Go to file
Andrés de la Peña 2e2a49fcdc CEP-20: Dynamic Data Masking
Allows to attach the native masking functions and UDFs to the definitions of
table columns in the schema, as defined by CEP-20.

The functions masking a column can be specified on CREATE TABLE queries, right
at the end of the column definition. The mask of a column can also be changed
or dropped with an ALTER TABLE query. Once a column is masked, SELECT queries
will always return the masked value of the column. That masking is done on the
coordinator, at the end of the query execution. Thus, masking won't affect any
filters or ordering, which would be based on the clear values of the masked
columns. Column masks are stored on the table system_schema.column_masks.

A new UNMASK permission allows to see the clear data of columns with an
attached mask. Also, a new SELECT_MASKED permission allows to run SELECT
queries restricting the clear values of masked columns. Superusers have both
permissions by default, whereas regular users don't have them.

Dynamic data masking can be enabled/disabled with the config property
dynamic_data_masking_enabled in cassandra.yaml. It is disabled by default.

This is the combination of multiple tickets:

 * Add masking functions to column metadata (CASSANDRA-18068)
 * Add UNMASK permission (CASSANDRA-18069)
 * Add SELECT_MASKED permission (CASSANDRA-18070)
 * Add support for using UDFs as masking functions (CASSANDRA-18071)
 * Add feature flag for dynamic data masking (CASSANDRA-18316)

patch by Andrés de la Peña; reviewed by Benjamin Lerer and Berenguer Blasi for CASSANDRA-17940
2023-03-24 13:57:18 +00:00
.build Update OpenHFT dependencies (chronicle-queue, chronicle-core, chronicle-bytes, chronicle-wire, chronicle-threads) 2023-03-22 09:03:33 +01:00
.circleci CircleCI config J17 + J11 2023-03-20 13:05:18 -04:00
.github Add pull request template and modify README to include Jira and mailing list link 2022-09-21 09:10:28 +02:00
.jenkins Merge branch 'cassandra-3.11' into cassandra-4.0 2022-06-19 16:40:36 +02:00
bin Add JDK17 startup scripts 2023-02-27 12:06:44 -05:00
conf CEP-20: Dynamic Data Masking 2023-03-24 13:57:18 +00:00
debian Prepare debian changelog for 4.1.1 2023-03-15 09:09:07 +01:00
doc CEP-20: Dynamic Data Masking 2023-03-24 13:57:18 +00:00
examples Merge branch 'cassandra-4.1' into trunk 2023-02-17 16:40:15 +01:00
ide Change trunk from 4.2 to 5.0 2023-03-07 11:03:38 +01:00
lib remove pure_sasl from the repository 2022-09-02 15:21:52 +02:00
pylib CEP-20: Dynamic Data Masking 2023-03-24 13:57:18 +00:00
redhat Change shebangs of Python scripts to resolve Python 3 from env command 2022-11-18 14:38:03 +01:00
src CEP-20: Dynamic Data Masking 2023-03-24 13:57:18 +00:00
test CEP-20: Dynamic Data Masking 2023-03-24 13:57:18 +00:00
tools SSTable format API 2023-03-06 09:17:18 +01:00
.asf.yaml Limit GH pull requests to rebases 2022-03-20 23:22:39 +01:00
.gitignore Fix copying of JAR of a trigger to temporary file 2023-02-17 16:36:42 +01:00
CASSANDRA-14092.txt Merge branch 'cassandra-2.2' into cassandra-3.0 2018-02-10 14:57:53 -02:00
CHANGES.txt CEP-20: Dynamic Data Masking 2023-03-24 13:57:18 +00:00
CONTRIBUTING.md Merge branch 'cassandra-3.11' into trunk 2021-04-22 08:32:58 -05:00
LICENSE.txt ninja-fix: typo Update in LICENSE.txt 2021-03-31 23:29:26 +02:00
NEWS.txt CEP-20: Dynamic Data Masking 2023-03-24 13:57:18 +00:00
NOTICE.txt Merge branch 'cassandra-3.11' into cassandra-4.0 2023-02-22 10:25:08 -06:00
README.asc Remove deprecated CQL functions dateOf and unixTimestampOf 2023-03-16 15:43:45 +00:00
TESTING.md Improve and clean up documentation and fix typos 2023-01-26 14:42:47 +01:00
build-shaded-dtest-jar.sh Merge branch 'cassandra-3.11' into trunk 2021-04-19 17:39:10 +02:00
build.properties.default Switch http to https URLs in build.xml 2019-05-21 17:54:11 -04:00
build.xml Increment version to 4.1.2 2023-03-21 07:00:29 -05:00
checkstyle.xml Incompatible file system thrown while running Simulator 2023-03-15 16:19:04 -07:00
checkstyle_suppressions.xml Forbid other Future implementations with checkstyle 2021-11-04 17:46:23 -07:00
checkstyle_test.xml add checkstyle modules for checking redundant and unused imports in Java code 2022-09-26 21:41:15 +02:00
eclipse_compiler.properties Add Static Analysis to warn on unsafe use of Autocloseable instances 2015-05-27 17:53:26 -04:00
relocate-dependencies.pom Upgrade maven-shade-plugin to 3.4.1 to fix shaded dtest JAR build 2023-03-14 15:57:14 -05:00

README.asc

Apache Cassandra
-----------------

Apache Cassandra is a highly-scalable partitioned row store. Rows are organized into tables with a required primary key.

https://cwiki.apache.org/confluence/display/CASSANDRA2/Partitioners[Partitioning] means that Cassandra can distribute your data across multiple machines in an application-transparent matter. Cassandra will automatically repartition as machines are added and removed from the cluster.

https://cwiki.apache.org/confluence/display/CASSANDRA2/DataModel[Row store] means that like relational databases, Cassandra organizes data by rows and columns. The Cassandra Query Language (CQL) is a close relative of SQL.

For more information, see http://cassandra.apache.org/[the Apache Cassandra web site].

Issues should be reported on https://issues.apache.org/jira/projects/CASSANDRA/issues/[The Cassandra Jira].

Requirements
------------
. Java >= 1.8 (OpenJDK and Oracle JVMS have been tested)
. Python 3.6+ (for cqlsh)

Getting started
---------------

This short guide will walk you through getting a basic one node cluster up
and running, and demonstrate some simple reads and writes. For a more-complete guide, please see the Apache Cassandra website's http://cassandra.apache.org/doc/latest/getting_started/[Getting Started Guide].

First, we'll unpack our archive:

  $ tar -zxvf apache-cassandra-$VERSION.tar.gz
  $ cd apache-cassandra-$VERSION

After that we start the server. Running the startup script with the -f argument will cause
Cassandra to remain in the foreground and log to standard out; it can be stopped with ctrl-C.

  $ bin/cassandra -f

Now let's try to read and write some data using the Cassandra Query Language:

  $ bin/cqlsh

The command line client is interactive so if everything worked you should
be sitting in front of a prompt:

----
Connected to Test Cluster at localhost:9160.
[cqlsh 6.2.0 | Cassandra 5.0-SNAPSHOT | CQL spec 3.4.7 | Native protocol v5]
Use HELP for help.
cqlsh>
----

As the banner says, you can use 'help;' or '?' to see what CQL has to
offer, and 'quit;' or 'exit;' when you've had enough fun. But lets try
something slightly more interesting:

----
cqlsh> CREATE KEYSPACE schema1
       WITH replication = { 'class' : 'SimpleStrategy', 'replication_factor' : 1 };
cqlsh> USE schema1;
cqlsh:Schema1> CREATE TABLE users (
                 user_id varchar PRIMARY KEY,
                 first varchar,
                 last varchar,
                 age int
               );
cqlsh:Schema1> INSERT INTO users (user_id, first, last, age)
               VALUES ('jsmith', 'John', 'Smith', 42);
cqlsh:Schema1> SELECT * FROM users;
 user_id | age | first | last
---------+-----+-------+-------
  jsmith |  42 |  john | smith
cqlsh:Schema1>
----

If your session looks similar to what's above, congrats, your single node
cluster is operational!

For more on what commands are supported by CQL, see
http://cassandra.apache.org/doc/latest/cql/[the CQL reference]. A
reasonable way to think of it is as, "SQL minus joins and subqueries, plus collections."

Wondering where to go from here?

  * Join us in #cassandra on the https://s.apache.org/slack-invite[ASF Slack] and ask questions.
  * Subscribe to the Users mailing list by sending a mail to
    user-subscribe@cassandra.apache.org.
  * Subscribe to the Developer mailing list by sending a mail to
    dev-subscribe@cassandra.apache.org.
  * Visit the http://cassandra.apache.org/community/[community section] of the Cassandra website for more information on getting involved.
  * Visit the http://cassandra.apache.org/doc/latest/development/index.html[development section] of the Cassandra website for more information on how to contribute.