AWS Security ChangesHomeSearch

AWS datasync: Enhanced TDE support with Kerberos in DataSync tasks

Service: datasync · 2026-07-29 · Documentation medium

File: datasync/latest/userguide/create-hdfs-location.md · Type: encryption

Summary

Clarified Transparent Data Encryption (TDE) support for Kerberos authentication in Enhanced mode tasks.

Security assessment

The change explicitly documents expanded encryption support (TDE with Kerberos) in Enhanced mode, improving security documentation.

Evidence

DataSync reads and writes to TDE-enabled clusters when using simple authentication with Basic or Enhanced mode tasks, or Kerberos authentication with Enhanced mode tasks.

Diff

diff --git a/datasync/latest/userguide/create-hdfs-location.md b/datasync/latest/userguide/create-hdfs-location.md
index 15b7d92ca..39eef896b 100644
--- a//datasync/latest/userguide/create-hdfs-location.md
+++ b//datasync/latest/userguide/create-hdfs-location.md
@@ -11 +11 @@ Providing DataSync access to HDFS clustersUnsupported HDFS featuresCreating your
-With AWS DataSync, you can transfer data between your Hadoop Distributed File System (HDFS) cluster and one of the following AWS storage services using Basic mode tasks:
+With AWS DataSync, you can transfer data between your Hadoop Distributed File System (HDFS) cluster and the following AWS storage services. The supported storage services depend on your task mode:
@@ -13 +13,2 @@ With AWS DataSync, you can transfer data between your Hadoop Distributed File Sy
-  * [Amazon S3](./create-s3-location.html)
+Basic mode | Enhanced mode  
+---|---  
@@ -14,0 +16 @@ With AWS DataSync, you can transfer data between your Hadoop Distributed File Sy
+  * [Amazon S3](./create-s3-location.html)
@@ -24,0 +23,5 @@ With AWS DataSync, you can transfer data between your Hadoop Distributed File Sy
+| 
+
+  * [Amazon S3](./create-s3-location.html)
+  * [Amazon EFS](./create-efs-location.html)
+  * [Amazon FSx for Lustre](./create-lustre-location.html)
@@ -32 +35 @@ To set up this kind of transfer, you create a [location](./how-datasync-transfer
-To connect to your HDFS cluster, DataSync uses a Basic mode agent [agent that you deploy](./deploy-agents.html) as close as possible to your HDFS cluster. The DataSync agent acts as an HDFS client and communicates with the NameNodes and DataNodes in your cluster.
+To connect to your HDFS cluster, DataSync uses an [agent that you deploy](./deploy-agents.html) as close as possible to your HDFS cluster. Use the agent that corresponds to your task mode. The DataSync agent acts as an HDFS client and communicates with the NameNodes and DataNodes in your cluster.
@@ -73 +76 @@ When using Kerberos authentication, DataSync supports encryption of data as it's
-You can also configure HDFS clusters for encryption at rest using Transparent Data Encryption (TDE). When using simple authentication, DataSync reads and writes to TDE-enabled clusters. If you're using DataSync to copy data to a TDE-enabled cluster, first configure the encryption zones on the HDFS cluster. DataSync doesn't create encryption zones. 
+You can also configure HDFS clusters for encryption at rest using Transparent Data Encryption (TDE). DataSync reads and writes to TDE-enabled clusters when using simple authentication with Basic or Enhanced mode tasks, or Kerberos authentication with Enhanced mode tasks. If you're using DataSync to copy data to a TDE-enabled cluster, first configure the encryption zones on the HDFS cluster. DataSync doesn't create encryption zones.
@@ -75 +78,7 @@ You can also configure HDFS clusters for encryption at rest using Transparent Da
-## Unsupported HDFS features
+### High Availability
+
+DataSync supports HDFS clusters configured for High Availability (HA) with multiple NameNodes. HA support depends on your task mode:
+
+  * **Enhanced mode** – You can specify multiple NameNodes when creating or updating your HDFS location. DataSync connects to the active NameNode for your transfer.
+
+  * **Basic mode** – You can specify only one NameNode.
@@ -77 +85,0 @@ You can also configure HDFS clusters for encryption at rest using Transparent Da
-The following HDFS capabilities aren't currently supported by DataSync:
@@ -79 +86,0 @@ The following HDFS capabilities aren't currently supported by DataSync:
-  * Transparent Data Encryption (TDE) when using Kerberos authentication
@@ -81 +88,4 @@ The following HDFS capabilities aren't currently supported by DataSync:
-  * Configuring multiple NameNodes
+
+## Unsupported HDFS features
+
+The following HDFS capabilities aren't supported by DataSync with either task mode:
@@ -93,0 +104,9 @@ The following HDFS capabilities aren't currently supported by DataSync:
+The following HDFS capabilities aren't supported with Basic mode tasks but are supported with Enhanced mode tasks:
+
+  * Transparent Data Encryption (TDE) when using Kerberos authentication
+
+  * Configuring multiple NameNodes (for clusters that use NameNode High Availability)
+
+
+
+
@@ -120,0 +140,4 @@ You can choose more than one agent. For more information, see [Using multiple Da
+###### Note
+
+With Enhanced mode tasks, you can specify more than one NameNode if your cluster is configured for NameNode High Availability. Basic mode tasks support only one NameNode.
+
@@ -160,0 +184,4 @@ _Tags_ are key-value pairs that help you manage, filter, and search for your loc
+###### Note
+
+With Enhanced mode tasks, you can specify more than one NameNode if your cluster is configured for NameNode High Availability. Basic mode tasks support only one NameNode.
+