apache / apache/iceberg-python

Allow disabling remote signing in REST Catalog

オープン
#3,888 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
1.1k
フォーク
581
平均マージ
1日 17時間
マージ済み PR(30日)
78

説明

### Feature Request / Improvement

When using a REST Catalog (e.g. Lakekeeper), pyiceberg gets remote signing details from the catalog.

However, sometimes it would be useful to _not_ use remote signing, in the case where the process performing the operations has access to the S3 endpoint through secret access keys. This is because remote signing requires a network round trip (plus any authorisation on server side).

It would be great if we could disable remote signing by respecting the `s3.signer` catalog property if it is empty.

The FileIO object gets created in `pyiceberg/catalog/rest/__init__.py`:

```python
return Table(
identifier=identifier_tuple,
metadata_location=table_response.metadata_location, # type: ignore
metadata=table_response.metadata,
io=self._load_file_io(
{**table_response.metadata.properties, **table_response.config}, table_response.metadata_location
),
catalog=self,
config=table_response.config,
)
```

This doesn't use the catalog properties that have been passed to the REST catalog init as far as I can tell.

I might be wrong, but I don't think [Support storage-credentials in REST catalog LoadTableResult- #3042
](https://github.com/apache/iceberg-python/pull/3042) fixes this, because it still uses the response from the catalog.

Thanks!

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

pyiceberg/catalog/rest/__init__.py の Table の構築箇所から始め、REST カタログのプロパティがどのように FileIO の設定に渡されるかを確認します。s3.signer の処理を追跡し、そのうえで、空のカタログプロパティによってリモート署名が無効化され、既存のレスポンス設定の動作が壊れないことを検証します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
python
領域
api, backend
issue の種類
機能追加
難易度
3/5
見積もり時間
1〜2日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
68/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。