This application discloses a
security design and architecture for multi-tenant Hadoop clusters. In one embodiment, in a multi-tenant Hadoop cluster comprising multiple tenants and
multiple applications, a method for identifying, naming, and creating a multi-tenant
directory structure in the multi-tenant Hadoop cluster may include: (1) identifying multiple groups of a
directory structure selected from groups consisting of a
superuser group, multiple tenant groups, and at least one application group; (2) creating a valid
directory for each of the groups; (3) adding each of the multiple users to one of the multiple tenant groups and the application group; (4) creating a tenant directory and a
home directory for the users; and (5) assigning an owner, group owner, default permissions, and
extended access control lists to the tenant directory and the
home directory.