OSSEVA FOR APACHE HADOOP
Your Hadoop cluster outlived its support contract.
CDH 6.3 support ended in March 2022 and HDP 3.1 support in December 2021. Upstream, Hadoop 3.2 was declared end of life in December 2023 and 2.10 has had no release since May 2022. OSSeva ships patched builds for all of them today.
Trusted globally by enterprises




Why now
Most production Hadoop lines are past community support
The Hadoop community declared 2.8 end of life in March 2020, 2.9 in September 2020, 3.1 in June 2021 and 3.2 on 22 December 2023. The 2.10 line was never formally retired, but its last release, 2.10.2, shipped on 31 May 2022, and 3.3 has had nothing since 3.3.6 on 23 June 2023. Only 3.4 and 3.5 are moving, and Hadoop 3.5 servers require JDK 17.
CDH and HDP left vendor support years ago
Cloudera's lifecycle policy ended support for CDH 5.14 to 5.16 in December 2020, CDH 6.2 and 6.3 in March 2022, HDP 2.6 in December 2020 and HDP 3.1 in December 2021. The vendor path forward is CDP, which is a platform migration rather than an upgrade. Many clusters stayed where they were, running HDFS, YARN, HBase and Hive with no one shipping fixes for them.
The hidden ZooKeeper time bomb
HDFS automatic failover and YARN ResourceManager HA both run through ZooKeeper. CDH 5 and 6 ship ZooKeeper 3.4.5, HDP ships 3.4.6, and upstream Hadoop 3.3.6 bundles 3.6.3, all from lines past community end of life. Write access to that ensemble is worth more than it looks: CVE-2021-25642 showed YARN's ZKConfigurationStore deserialising ZooKeeper data without checks, so anyone who could write to ZooKeeper could run commands as the YARN user.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 2.8.x(Community EOL 9 Mar 2020 — OSSeva patched) | EOL | Clean |
| 2.9.x(Community EOL 7 Sep 2020 — OSSeva patched) | EOL | Clean |
| 2.10.x(No release since 31 May 2022 — OSSeva patched) | Extended | Clean |
| 3.1.x(Community EOL Jun 2021 — OSSeva patched) | EOL | Clean |
| 3.2.x(Community EOL 22 Dec 2023 — OSSeva patched) | EOL | Clean |
| 3.3.x(No release since 23 Jun 2023 — OSSeva patched) | Extended | Clean |
| 3.4.x(Upstream maintained, latest 3.4.3) | Extended | Clean |
| 3.5.x(Released 2 Apr 2026) | Current | Clean |
| CDH 5.14 to 5.16(Cloudera EoS Dec 2020 — OSSeva patched) | EOL | Clean |
| CDH 6.2 and 6.3(Cloudera EoS Mar 2022 — OSSeva patched) | EOL | Clean |
| HDP 2.6(Cloudera EoS Dec 2020 — OSSeva patched) | EOL | Clean |
| HDP 3.1(Cloudera EoS Dec 2021 — OSSeva patched) | EOL | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Patched, signed builds for Hadoop 2.8 to 3.3, CDH 5 and 6, and HDP 2.6 and 3.1.
- Security backports for HDFS, YARN and MapReduce on end-of-life lines
- CDH and HDP component builds, including HBase, Hive and ZooKeeper
- Transitive dependency patching (Jetty, Netty, Jackson, log4j)
- Tarball, RPM and parcel delivery
- Signed artifacts (GPG) and VEX statements for scanner findings
- Cluster security audit
- 24/7 managed operations
OSSeva Assure
Patch plus a full cluster audit and a costed platform plan.
- Everything in Patch
- NameNode, ResourceManager and ZooKeeper HA review
- Kerberos, Ranger or Sentry policy and exposure audit
- Component version map across every service on the cluster
- SOC 2 / HIPAA attestation package with VEX for auditors
- Migration plan to Hadoop 3.4 or 3.5, CDP, or a cloud platform
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 cluster monitoring, 15-min SLA, named engineers.
- Everything in Assure
- 24/7 HDFS capacity, NameNode and YARN queue monitoring
- 15-minute P1 incident response SLA
- Named senior Hadoop engineer
- Failover testing and ZooKeeper quorum management
- Rolling upgrade and migration execution
- Quarterly capacity and cost reviews
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
# The build string names the distribution (cdh, or an HDP stack number)
hadoop version | head -1
# HDP: installed stack versions
hdp-select versions
# CDH: parcels on this host
ls /opt/cloudera/parcels/
# The quorum NameNode failover and ResourceManager HA depend on
hdfs getconf -confKey ha.zookeeper.quorum
hdfs haadmin -getAllServiceState
yarn rmadmin -getAllServiceState
# Version the ensemble is actually running
echo srvr | nc zk1.internal 2181 | head -1<dependency>
<groupId>io.osseva.hadoop</groupId>
<artifactId>hadoop-client</artifactId>
<version>3.3.6-osseva-1</version>
</dependency>Migrate from Cloudera CDH and HDP past end of support
OSSeva ships patched builds for the CDH and HDP releases still in production, and for the upstream Hadoop lines the community has stopped releasing. HDFS, YARN, HBase, Hive and the shared ZooKeeper are patched together, so the cluster keeps running while the move to Hadoop 3.4 or 3.5, CDP, or a cloud platform is planned and carried out.
Pricing model
OSSeva for Apache Hadoop is priced per cluster, not per node or per terabyte stored.
Frequently asked questions
Which Apache Hadoop versions are end of life?
The Hadoop community has declared 1.x, 2.0 to 2.9, and 3.0 to 3.2 end of life. The most recent were 2.9 in September 2020, 3.1 in June 2021 and 3.2 on 22 December 2023. Hadoop 3.4 and 3.5 are the lines still getting releases: 3.4.3 on 24 February 2026 and 3.5.0 on 2 April 2026.
Is Hadoop 2.10 end of life?
Not formally, but in practice there are no fixes. The last 2.10 release, 2.10.2, shipped on 31 May 2022, and the HBase reference guide notes that the Hadoop community has not officially retired 2.x even though no 2.x release has followed. OSSeva ships patched 2.10 builds today.
When did Cloudera support for CDH and HDP end?
Under Cloudera's lifecycle policy, CDH 5.14 to 5.16 reached end of support in December 2020, CDH 6.2 and 6.3 in March 2022, HDP 2.6 in December 2020 and HDP 3.1 in December 2021. A limited support period for eligible customers ended in September 2022 for CDH 6.2 and 6.3, and in June 2022 for HDP 3.1.
Can OSSeva support a CDH or HDP cluster that Cloudera no longer supports?
Yes. OSSeva is independent of Cloudera and ships patched builds for CDH 5 and 6 and HDP 2.6 and 3.1 components, including HDFS, YARN, HBase, Hive and ZooKeeper. The cluster keeps its layout and its data. Book a discovery call to map the components you run.
Why does Hadoop depend on ZooKeeper?
For high availability. HDFS automatic failover adds a ZooKeeper quorum and the ZKFailoverController, which uses a ZooKeeper lock to decide the active NameNode. YARN ResourceManager HA uses a ZooKeeper-based elector and, by recommendation, the ZooKeeper state store. Almost every production cluster runs both, so the ensemble is as critical as the NameNode.
Ready to get Apache Hadoop patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.