[Feature] Access table data with the temporary credentials issued by the REST catalog

Abierto
#369 0 comentarios 0 reacciones 1 asignado Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
30/100
Tipo de issue
Nueva funcionalidad
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
cpp
Área
api, database

Línea de trabajo

Start by tracing Catalog::GetTableFileSystem, ReadContextBuilder, ScanContextBuilder, WriteContextBuilder, and CredentialProviderFactory::Get to understand the existing catalog and file-system extension points. Done means data-token.enabled remains backward-compatible, table credentials refresh independently before expiry, the builder and provider APIs work, and static built-in file-system credentials remain unchanged.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

enhancement

Search before asking

  • I searched in the issues and found nothing similar.

Motivation

The C++ REST catalog can only read and write table data with the static credentials configured in the catalog options (fs.oss.accessKeyId and friends). A REST catalog that issues per-table temporary credentials (data tokens, e.g. DLF) has no way to have those credentials used for that table's data IO, and no way to keep them fresh before they expire. Callers that bring their own FileSystem also have no supported abstraction for sourcing credentials that expire.

Solution

Add data-token support to the REST catalog: when data-token.enabled=true, the catalog loads a table's temporary credentials and serves a refreshing FileSystem for that table through Catalog::GetTableFileSystem(identifier). ReadContextBuilder, ScanContextBuilder and WriteContextBuilder gain WithCatalog(catalog, identifier) so the table's schema and file system are resolved from the catalog in one call. The credentials are cached and reloaded before expiry by rebuilding the delegate file system keyed by the issued token, so a rotation of one table's credentials does not disturb the others.

Also add a generic CredentialProvider + CredentialProviderFactory extension point: a caller that brings its own FileSystem builds a provider with CredentialProviderFactory::Get and consults GetCredentials() at each access, then passes that file system in through Catalog::Create or a builder's WithFileSystem. The built-in file systems (oss, s3, local, jindo) keep signing with the static credentials of their own options.

Anything else?

data-token.enabled defaults to false, and the new API is additive, so the change is backward compatible.

Are you willing to submit a PR?

  • I'm willing to submit a PR!
Lenguaje dominante
C++
Estrellas
65
Forks
29
Merge medio
2 d 30 min
PR fusionados (30 d)
77

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de apache/paimon-cpp

Todos los issues de apache/paimon-cpp

Issues similares

Más issues de C++

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.