apache / apache/iceberg-python

feat: Automatic Vended Credential Refresh

未关闭
#3,506 0 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
1.1k
派生
581
平均合并
1 天 17 小时
30 天内合并 PR
78

描述

### Feature Request / Improvement

Today, long-running writes to PyIceberg risk failing when credentials expire mid-transaction. The Java implementation addressed this by adding a vended-credential refresh mechanism that calls a REST catalog endpoint to obtain new credentials whenever the current ones are within five minutes of expiring.

I propose a similar approach for PyIceberg, delivered in three separate PRs:

1. **VendedCredential class implementation** (largest diff) -> [PR](https://github.com/apache/iceberg-python/pull/3507) ready for review
2. **Credential refresh support in `PyArrowFileIO`** -> PR pending review and merge of 1
3. **Credential refresh support in `FsspecFileIO`** -> PR pending review and merge of 1

PRs 2 and 3 depend on PR 1, which provides the core vended-credential implementation.

贡献指南

这个仓库没有索引到贡献指南

调研方向

首先查看 PR 3507,其中包含 VendedCredential 的实现,也是剩余工作的依赖项。然后检查计划中的 PyArrowFileIO 和 FsspecFileIO 刷新支持;当两个集成都能在从 REST catalog 获取的凭据过期前刷新这些凭据时,该功能就完成了。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
data-engineering
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
需要澄清
新手友好度
20/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。