Chapter 26 · Security: Authentication, Authorization, Roles, TLS, and Secrets

Protect JMX / Management Interfaces, Credentials, Network Paths, Backups, and Configuration Secrets

Secure JMX, listener exposure, credentials, configuration secrets and backup paths.

Advanced110–160 minutesJMX/secrets/backup boundary labApache Cassandra 5.0.9 · Java 17 · cqlsh/nodetool · RF=3 · LOCAL_QUORUM · UCSLast reviewed: September 2026

Learning outcomes

AtlasMart secures native CQL, but a scanner discovers remotely reachable JMX and a CI identity can read every backup. Those paths can bypass application authorization entirely. Protect management and recovery surfaces as part of the same threat model.

01

Keep JMX local by default and define controls required for remote JMX.

02

Inventory actual listener/port exposure instead of trusting a “private” network label.

03

Keep credentials, private keys and config secrets out of Git/process arguments/history.

04

Apply equal-or-stronger access/encryption/audit to backups.

05

Run secret-rotation and negative backup-access checks.

Chapter 26 lab baseline

The mandatory work uses a separate disposable security cluster so hardening experiments cannot lock the shared course cluster. Pin Apache Cassandra 5.0.9 with the official cassandra:5.0.9 image, Java 17 from that image, Docker network atlasmart-cassandra-security, cluster atlasmart-security, nodes atlasmart-sec-1..3, datacenter dc1, racks rack1..rack3, 16 virtual nodes (vnodes) per node, NetworkTopologyStrategy, replication factor (RF) 3, and LOCAL_QUORUM for application-style verification. Tables use UnifiedCompactionStrategy (UCS), default_time_to_live=0, and gc_grace_seconds=864000.

The lab intentionally starts with Cassandra's compatible security defaults so the migration is observable: AllowAllAuthenticator, AllowAllAuthorizer, client TLS disabled, internode encryption none, and JMX local-only. No Cassandra/JMX/storage ports are published to the host. This is a local learning boundary, not a production posture. Never place a real password, token, private key, keystore password, backup key, or break-glass credential into Git, lesson HTML, screenshots, chat, shell history, or process arguments.

Execution and safety note

Run commands only against the disposable Apache Cassandra course lab or another explicitly approved non-production environment. Confirm node, keyspace, table, container, volume, path, and datacenter targets before destructive, failure-injection, cleanup, repair, restore, security, or topology operations. Capture current state and expected rollback/recovery evidence first; output and timings can differ by host, operating system, Java runtime, Docker/runtime, driver, and Cassandra configuration.

Terms before the security mechanisms

CQL is Cassandra Query Language. A coordinator is the node accepting a client request; replicas store copies of the target partition. A partition is the row group located by a partition key; its hash maps to a token. vnodes are multiple token ranges assigned per node. A keyspace defines replication. RF is replication factor and CL is consistency level. An SSTable is Cassandra's immutable on-disk table file set; compaction merges SSTables; repair compares replica ranges and streams differences. SAI is Storage-Attached Indexing. A driver is the client library speaking Cassandra's native protocol.

Authentication proves an identity; Cassandra's authenticator implements that decision. Authorization decides what an authenticated identity may do; the authorizer checks permissions on Cassandra resources. A role is Cassandra's principal/inheritance object; LOGIN=true makes it directly authenticatable. A superuser bypasses normal authorization and therefore belongs only in tightly controlled administration or break-glass recovery. Least privilege grants only the permissions needed.

TLS (Transport Layer Security) protects network traffic and authenticates endpoints with certificates. Client TLS protects application/cqlsh ↔ Cassandra native protocol; internode TLS protects Cassandra node ↔ node gossip/replication/streaming. mTLS (mutual TLS) means both sides present certificates. A keystore holds private key/certificate material and a truststore holds trust anchors. JMX (Java Management Extensions) is Cassandra's management interface used by nodetool. Defense in depth layers identity, permissions, encryption, network isolation, secrets, backups, audit, patching and recovery instead of trusting one control.

1. JMX is a separate privileged management interface

nodetool communicates through JMX, not CQL. Cassandra ships with local JMX by default. If remote JMX is enabled, protect it independently with authentication, TLS, fixed/bounded Remote Method Invocation (RMI) ports as required, firewall/management-network policy, dedicated management identity and audit. CQL client TLS and Cassandra roles do not secure JMX.

bash · prove local JMX and inventory listeners
docker port atlasmart-sec-1docker inspect atlasmart-sec-1 --format '{{json .HostConfig.PortBindings}}'docker exec atlasmart-sec-1 nodetool statusdocker exec atlasmart-sec-1 sh -lc 'ss -lntp || true'docker exec atlasmart-sec-1 sh -lc \ 'grep -n -E "LOCAL_JMX|jmxremote.authenticate|jmxremote.ssl" /etc/cassandra/cassandra-env.sh | head -40' 

No host-published 7199 is evidence only for this Docker deployment. A Kubernetes Service, host network, cloud security group, firewall or sidecar can change the real reachability boundary; test negative reachability from an unauthorized network location.

2. Secrets need a lifecycle

Material Avoid Preferred pattern
CQL password Git, screenshots, routine CLI argument interactive/protected credentials file/secret injection
TLS private key repo/world-readable volume secret mount, KMS/HSM-integrated context where appropriate
keystore password committed rendered YAML render/inject from protected source; restrict config backups
JMX credential shared app-admin password management-only identity + TLS/network policy
backup encryption key same broad principal as data separate key policy, restore authorization and recovery escrow
break-glass credential daily shared superuser vaulted, monitored, tested emergency workflow
text · secret rotation acceptance flow
1. Inventory every consumer of the old secret/certificate.2. Issue a new version without immediately revoking the old one.3. Canary authentication/TLS/authorization.4. Roll all consumers and monitor old-secret use/failures.5. Disable/revoke the old secret.6. Prove old-secret authentication now fails.7. Remove temporary files/environment values and record evidence/owner/expiry.

3. Shell, cqlsh and configuration evidence hygiene

Use --disable-history for sensitive cqlsh administration. A cqlsh credentials file can support automation but must be owner-readable only and itself treated as a secret. Avoid routine password command arguments because process listings and logs can expose them. When collecting evidence, extract/redact security posture fields instead of copying a secret-bearing cassandra.yaml wholesale.

bash · redacted posture evidence
for n in 1 2 3; do  echo "=== atlasmart-sec-$n ==="  docker exec atlasmart-sec-$n sh -lc \    "grep -E '^(authenticator|authorizer|role_manager|network_authorizer):' /etc/cassandra/cassandra.yaml"  docker exec atlasmart-sec-$n nodetool statusbinarydone# Never dump secret-bearing YAML/credentials/private keys/environment values into a ticket.

4. Backups must not be weaker than live data

Snapshots and incremental SSTables can contain the same sensitive cells as the live database. Client/internode TLS does not encrypt those files at rest. A production backup vault needs a dedicated identity model, encryption/key management, integrity, retention/immutability where appropriate, access/audit logs, deletion/legal-hold controls and tested restore-key availability. Separation from the production account/site can reduce ransomware/operator-error blast radius.

PowerShell · local ACL/inventory simulation without reading backup contents
$vault='.\atlasmart-backup-vault'if (Test-Path $vault) {  Get-Acl $vault | Format-List  Get-ChildItem $vault -File -Recurse | Select-Object -First 10 FullName,Length} else { 'Use a disposable Chapter 25 vault copy for this check.' }# Production evidence should use actual object-store/filesystem IAM, KMS and audit data.
Unsafe design: application DB roles are narrow, but CI can download all backups.

Backup files bypass Cassandra authorization. Repair with dedicated backup/restore principals, vault encryption/key policy, access review, audit and explicit denied-access tests from non-backup identities.

5. Verification and reset

Check your understanding

  1. Why can nodetool work with no host-published JMX port?
  2. Why avoid password CLI arguments?
  3. Does client TLS encrypt SSTable backups?
  4. What proves network isolation?
  5. Why separate break-glass from daily admin access?
Review the answers

1. It runs inside the container against local-only JMX.

2. Process listings/history/logs can expose them.

3. No; backup-at-rest protection is separate.

4. Actual listener/service/firewall/security-group policy plus negative reachability tests.

5. It reduces routine exposure and makes emergency access attributable, approved and auditable.

Production judgment

Security controls affect latency, availability and operator skill. Record Cassandra/JVM/driver versions, DC/racks/RF/CL, auth/TLS/JMX/network state, role inheritance, credential/certificate expiry, audit retention, backup encryption/access, patch status, repair/restore credentials and the application routing/retry/idempotency model. Re-run p50/p95/p99 latency and replica-failure tests after encryption/authorization changes. Data modeling still matters: partition/cardinality/TTL/tombstone/compaction/repair/SAI/vector choices can change sensitive-data exposure and resource-denial risk.

Do not treat a private subnet, one superuser password, client TLS or one audit stream as sufficient. Managed Cassandra may operate some server certificates, JMX, upgrades or backups, but application identities, permissions, client trust, data classification, secret use and incident response still have explicit owners. Migration/rollback must retain a tested administrative path and prevent coordinator-dependent security drift. Lesson 5 makes patching, audit evidence, incident access and tenant boundaries recurring operational controls.

Summary and next step

This lesson’s concepts, evidence path, failure boundaries, and production judgment should now be explicit enough to verify rather than assume. Re-run the check-your-understanding prompts and preserve any lab evidence you need before changing or cleaning up the environment.

Next, continue to Operational Security Review: Patch Cadence, Audit Evidence, Incident Access, and Multi-Tenant Boundaries.

Authoritative references

Security defaults, algorithms, tooling and deprecations are version-sensitive. Re-check the target Cassandra/JVM/driver distribution and organizational cryptographic policy before production rollout.

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.