Apache Knox is a REST API and application gateway for the Apache Hadoop ecosystem. It acts as a reverse proxy and gives clients a single access point to Hadoop clusters, hiding the cluster's hosts and ports. Knox supports authentication through LDAP/Active Directory, Kerberos, SAML and OAuth among others, offers single sign-on with KnoxSSO, authorisation using access lists by user, group or IP address, and audit logging. Each protected cluster is described in a topology file. Knox is installed and operated by the user; the project does not offer a SaaS service.
Knox is open source under the Apache License 2.0 and a project of the Apache Software Foundation, a US non-profit (501(c)(3)) run by volunteers. Because no central vendor hosts the software, the user decides where it runs and where data resides, for example on-premises or in a European data centre. The source code is public. European organisations thereby keep control of the access layer, but must take care of installation, updates and security configuration themselves.