apache / apache/iceberg-python
Option to specify SSE-KMS or SSE-S3 encryption when writing data with load_catalog / append
- 主要言語
- Python
- スター
- 1.1k
- フォーク
- 581
- 平均マージ
- 1日 17時間
- マージ済み PR(30日)
- 78
説明
### Question
Hello team,
I am using pyiceberg to load data into an Iceberg table stored in Amazon S3.
While doing this, I am facing an explicit deny from an AWS Service Control Policy (SCP) that blocks multipart uploads without encryption. I cannot modify the SCP.
Error excerpt:
`
OSError: When initiating multiple part upload for key 'iceberg/DEV/dataset/test_4_matdoc/metadata/...'
in bucket 'pt-s3-project-bucketname':
AWS Error ACCESS_DENIED during CreateMultipartUpload operation:
User: arn:aws:sts::... is not authorized to perform: s3:PutObject
with an explicit deny in a service control policy
`
This happens during calls like:
`def load_iceberg_table(table, arrow_table):
catalog = load_catalog("glue", **{"type": "glue"})
iceberg_table: Table = catalog.load_table(f"{DATABASE}.{table}")
try:
logger.info("Appending data to Iceberg table...")
iceberg_table.append(df=arrow_table)
logger.info("Successfully appended data to Iceberg table.")
except ClientError as e:
logger.error(f"Iceberg append ClientError: {e}")
raise
except Exception as e:
logger.error(f"Unexpected Iceberg error: {e}")
raise`
From my understanding, pyiceberg uses S3 multipart upload under the hood, but I haven’t found a documented way to configure SSE-KMS or SSE-S3 parameters for these writes.
Question:
Is there currently a way to pass S3 upload parameters (like ServerSideEncryption, SSEKMSKeyId) via load_catalog, append, or FileIO configuration?
If not, could this be added as a feature so that environments with encryption-required SCPs can still use pyiceberg without policy changes?
Thanks!
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
調査の方向性
まず、報告された ACCESS_DENIED のケースを再現として使用し、load_catalog と append が FileIO S3 マルチパートアップロードのパスにどのように到達するかを追跡します。暗号化パラメーターがカタログ、append、または FileIO 設定を通じて公開されているか確認します。書き込みに対して要求された SSE-S3 または SSE-KMS 設定を構成でき、暗号化されたアップロードパスが検証されれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- aws, python
- 領域
- cloud, security
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 50/100