// Cloudera CDH extended support

Still running CDH 5 or CDH 6?
Support ended years ago. Patched components are available today.

Cloudera's support lifecycle policy ended CDH 5.14 to 5.16 in December 2020 and CDH 6.2 and 6.3 in March 2022, and limited support for eligible CDH 6 customers finished in September 2022. Every CDH release from 5.0 to 6.3 bundles ZooKeeper 3.4.5, from an upstream line that reached end of life in June 2020. OSSeva ships patched builds of the CDH components that carry the most exposure, ZooKeeper included, so the cluster stays supported while the exit is planned.

CDH 6.36.26.16.0CDH 5.165.xZooKeeper 3.4.5HDFS, YARN, HBase, Hive

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why CDH clusters are still in production

CDH clusters tend to hold years of data and jobs that nobody wants to rewrite in a hurry.

Every exit is a platform move

Leaving CDH means a new distribution or a new data platform. Data, jobs, security policies and downstream consumers all move, and that work runs for quarters.

ZooKeeper 3.4.5 sits under everything

HDFS HA, YARN HA, HBase, HiveServer2 and Cloudera Search all coordinate through the same ensemble. The upstream 3.4 line never received a fix for CVE-2023-44981 and ships log4j 1.2.17. Cloudera's builds carry their own patches, so check the fixed-CVE list for your exact build.

Scanners read the version string

Scanners match zookeeper-3.4.5 and the CDH component versions against public advisories. Without patched builds and a written assessment, each finding has to be argued by hand.

The dates that matter

  1. 2019-08

    End of support for CDH 5.8 and earlier.

  2. 2020-06-01

    ZooKeeper 3.4 end of life upstream. Every CDH release bundles 3.4.5.

  3. 2020-12

    End of support for CDH 5.14, 5.15 and 5.16.

  4. 2021-08

    End of support for CDH 6.0.

  5. 2021-12

    End of support for CDH 6.1.

  6. 2022-03

    End of support for CDH 6.2 and 6.3.

  7. 2022-09-30

    Limited support for eligible CDH 6.2 and 6.3 customers ends.

What OSSeva delivers

1

Patched CDH components

Signed builds with backported security fixes for HDFS, YARN, HBase and Hive on CDH 5 and 6, matched to the CDH release you run so the cluster keeps its version and configuration.

CDH 5 and 6HDFS, YARN, HBase, HiveSigned builds
2

Patched ZooKeeper 3.4.5

The bundled ensemble, patched and dropped in with configuration and data unchanged, plus VEX statements for the findings your scanner raises against it.

ZooKeeper 3.4.5Drop-inVEX
3

Migration off CDH

A migration plan per workload to a current distribution, upstream Apache releases or a cloud platform, carried out with your team while the patched cluster keeps running.

Upstream ApacheCloud platformsCut-over plan

Your options, compared

OptionWhat you getTrade-off
Upgrade to a current commercial distributionVendor support for current Hadoop componentsA full platform upgrade and a new subscription.
Migrate to a cloud data platformManaged storage and computeData movement and job rewrites across several quarters.
OSSeva extended supportPatched CDH components and ZooKeeper today, and help with the moveA subscription while CDH stays in production.
Stay on unsupported CDHNothingFindings accumulate on the cluster that holds the most data.

End-of-support dates from Cloudera's support lifecycle policy. Bundled ZooKeeper versions from Cloudera's CDH 5 and CDH 6 packaging documentation. ZooKeeper advisories from zookeeper.apache.org/security.

Frequently asked questions

When did CDH reach end of life?

According to Cloudera's support lifecycle policy, CDH 5.14 to 5.16 ended in December 2020, CDH 6.0 in August 2021, 6.1 in December 2021, and 6.2 and 6.3 in March 2022. Limited support for eligible CDH 6.2 and 6.3 customers ran to 30 September 2022.

Which ZooKeeper version does CDH use?

ZooKeeper 3.4.5 with Cloudera patches, in every release from CDH 5.0 to 6.3. The upstream 3.4 line reached end of life on 1 June 2020.

Can we still get Cloudera CDH support?

CDH is past every date in the vendor's lifecycle policy. OSSeva supports CDH 5 and 6 clusters as they are, with patched components and ZooKeeper builds shipping now, until you move.

Do we have to upgrade CDH to get patches?

No. Patched builds match the CDH release you run, so the cluster keeps its current version and configuration.

Which support tier fits a CDH cluster?

Patch covers signed builds with backported fixes. Assure adds an ensemble audit and an attestation package for auditors. Operate adds 24/7 monitoring and named engineers.

Keep CDH patched while the exit is planned.

Start with Patch today. Add Assure or Operate when the cluster needs them.