Handling of sensitive data in Cloudera

Cloudera encrypts sensitive data (such as tokens, passwords, certificates, and encryption keys) by using Vault.

Classic cluster credentials

During HDP, CDH, or Cloudera Private Cloud "classic cluster" registration in the Cloudera Management Console, Cloudera asks you to enter cluster credentials. This is required for authenticating requests on the cluster side. Cloudera uses these credentials to access cluster APIs during and after cluster registration. During registration Cloudera stores these credentials securely in the vault and later whenever Cloudera makes an API call to the cluster, Cloudera reads these credentials from the vault and inject them inside the request.