Skip to content

Add a "securing DataFusion" documentation #26061

Description

@alamb

I added an initial security policy in this PR

@samueleresca noted (❤️ ) in #25917 (comment) that it would be helpful to add additional documentation on how to harden DataFusion from threats by explicitly state the configurations that contribute to security hardening and their default.

For example, DuckDB does something similar in their operations manual.

Some corresponding examples in the DataFusion domain from @samueleresca:

He suggested

The stuff above might go in a dedicated section on the already existing Config page.

I would personally suggest adding a new page in our library user guide here:

Activity

  1. alamb commented on Oct 5, 2026

    @alamb
    ContributorAuthor

    To anyone who wants to do this, please don't just dump an AI generated doc on us

    You should put yourself in the role of someone using DataFusion and give a high level explanation about configuring it for security and then give doc links and a BRIEF description (a sentence or less) of the various settings and WHY they contribute to the security posture / hardening

  2. efegokdemir commented on Oct 5, 2026

    @efegokdemir
    Contributor

    take

  3. samueleresca commented on Oct 6, 2026

    @samueleresca
    Member

    Thanks @alamb for opening this 🥇

  4. added a commit that references this issue on Oct 9, 2026
    5218379
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions