apache / apache/iceberg

KMS credential vending

Open
#16,194 0 comments 0 reactions 0 assignees View on GitHub
improvement
Dominant language
Java
Stars
9.2k
Forks
3.5k
Avg merge
2d 16h
Merged PRs (30d)
129

Description

### Feature Request / Improvement

Lifting out the discussion in https://github.com/apache/iceberg/pull/13225#issuecomment-4362295328 to a separate issue / feature request.

https://github.com/apache/iceberg/pull/13225 supports KMS clients for REST catalogs, configured at the catalog-level and not at a finer level e.g. at the table-level where a REST catalog can vend credentials to be used in KMS clients that only support operating on the required key. This issue tracks supporting that.

### Query engine

None

### Willingness to contribute

- [ ] I can contribute this improvement/feature independently
- [ ] I would be willing to contribute this improvement/feature with guidance from the Iceberg community
- [ ] I cannot contribute this improvement/feature at this time

Contributor guide

Open the contributing guide

Research direction

Start by reading the discussion in PR 13225, especially the linked issue comment, and review how REST catalogs currently configure KMS clients at catalog level. Define the table-level credential-vending behavior and its completion criteria, including how credentials are used with KMS clients that operate only on the required key.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
backend-api-design, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.