apache / apache/iceberg-python

Option to specify SSE-KMS or SSE-S3 encryption when writing data with load_catalog / append

Offen
#2,329 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
1.1k
Forks
581
Ø Merge
1 T. 17 Std.
Gemergte PRs (30 T.)
77

Beschreibung

### Question

Hello team,

I am using pyiceberg to load data into an Iceberg table stored in Amazon S3.
While doing this, I am facing an explicit deny from an AWS Service Control Policy (SCP) that blocks multipart uploads without encryption. I cannot modify the SCP.

Error excerpt:
`
OSError: When initiating multiple part upload for key 'iceberg/DEV/dataset/test_4_matdoc/metadata/...'
in bucket 'pt-s3-project-bucketname':
AWS Error ACCESS_DENIED during CreateMultipartUpload operation:
User: arn:aws:sts::... is not authorized to perform: s3:PutObject
with an explicit deny in a service control policy
`
This happens during calls like:

`def load_iceberg_table(table, arrow_table):
catalog = load_catalog("glue", **{"type": "glue"})
iceberg_table: Table = catalog.load_table(f"{DATABASE}.{table}")
try:
logger.info("Appending data to Iceberg table...")
iceberg_table.append(df=arrow_table)
logger.info("Successfully appended data to Iceberg table.")
except ClientError as e:
logger.error(f"Iceberg append ClientError: {e}")
raise
except Exception as e:
logger.error(f"Unexpected Iceberg error: {e}")
raise`

From my understanding, pyiceberg uses S3 multipart upload under the hood, but I haven’t found a documented way to configure SSE-KMS or SSE-S3 parameters for these writes.

Question:
Is there currently a way to pass S3 upload parameters (like ServerSideEncryption, SSEKMSKeyId) via load_catalog, append, or FileIO configuration?
If not, could this be added as a feature so that environments with encryption-required SCPs can still use pyiceberg without policy changes?

Thanks!

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Beginne damit nachzuverfolgen, wie load_catalog und append den FileIO-S3-Multipart-Upload-Pfad erreichen, und verwende den gemeldeten ACCESS_DENIED-Fall als Reproduktion. Prüfe, ob Verschlüsselungsparameter über den Katalog, append oder die FileIO-Konfiguration verfügbar gemacht werden. Als erledigt gilt die Aufgabe, wenn die angeforderten SSE-S3- oder SSE-KMS-Einstellungen für Schreibvorgänge konfiguriert werden können und der verschlüsselte Upload-Pfad verifiziert ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws, python
Bereich
cloud, security
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
50/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.