apache / apache/iceberg-python
Allow disabling remote signing in REST Catalog
- 主要言語
- Python
- スター
- 1.1k
- フォーク
- 581
- 平均マージ
- 1日 17時間
- マージ済み PR(30日)
- 78
説明
### Feature Request / Improvement
When using a REST Catalog (e.g. Lakekeeper), pyiceberg gets remote signing details from the catalog.
However, sometimes it would be useful to _not_ use remote signing, in the case where the process performing the operations has access to the S3 endpoint through secret access keys. This is because remote signing requires a network round trip (plus any authorisation on server side).
It would be great if we could disable remote signing by respecting the `s3.signer` catalog property if it is empty.
The FileIO object gets created in `pyiceberg/catalog/rest/__init__.py`:
```python
return Table(
identifier=identifier_tuple,
metadata_location=table_response.metadata_location, # type: ignore
metadata=table_response.metadata,
io=self._load_file_io(
{**table_response.metadata.properties, **table_response.config}, table_response.metadata_location
),
catalog=self,
config=table_response.config,
)
```
This doesn't use the catalog properties that have been passed to the REST catalog init as far as I can tell.
I might be wrong, but I don't think [Support storage-credentials in REST catalog LoadTableResult- #3042
](https://github.com/apache/iceberg-python/pull/3042) fixes this, because it still uses the response from the catalog.
Thanks!
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
調査の方向性
pyiceberg/catalog/rest/__init__.py の Table の構築箇所から始め、REST カタログのプロパティがどのように FileIO の設定に渡されるかを確認します。s3.signer の処理を追跡し、そのうえで、空のカタログプロパティによってリモート署名が無効化され、既存のレスポンス設定の動作が壊れないことを検証します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- python
- 領域
- api, backend
- issue の種類
- 機能追加
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 68/100