diqiu50 opened a new issue, #13357:
URL: https://github.com/apache/gravitino/issues/13357

   ### Version
   
   main branch
   
   ### Describe what's wrong
   
   When a `lakehouse-iceberg` catalog is routed through the Gravitino Iceberg 
REST server (IRC), the
   Trino connector only propagates authentication to the internal Iceberg REST 
client when
   `gravitino.client.authType=oauth2`. For `simple`, `basic`, and `kerberos`, no
   `iceberg.rest-catalog.security` is ever set.
   
   The catalog registers successfully, but every query fails once the IRC 
requires authentication.
   This happens at the first REST call (`GET /v1/config`), before any table 
access, so it also blocks
   vended credentials (`s3-token`, etc.) from ever being exercised.
   
   ### Error message and/or stacktrace
   
   ```
   Query failed: Cannot obtain metadata
   caused by: org.apache.iceberg.exceptions.NotAuthorizedException: Not 
authorized
        at org.apache.iceberg.rest.RESTSessionCatalog.fetchConfig
        at 
io.trino.plugin.iceberg.catalog.rest.TrinoIcebergRestCatalogFactory.create
   ```
   
   ### How to reproduce
   
   1. Run a Gravitino server with an authenticator that requires credentials 
(`simple` is enough) and
      the Iceberg REST server enabled.
   2. Configure the Trino connector with `gravitino.client.authType=simple` (or 
`basic`/`kerberos`).
   3. Register a `lakehouse-iceberg` catalog routed through the IRC.
   4. Run `SHOW SCHEMAS FROM <catalog>` — fails with `NotAuthorizedException`.
   
   ### Additional context
   
   Trino's Iceberg REST client only supports `iceberg.rest-catalog.security = 
NONE | OAUTH2`
   (pre-481), so `simple`/`basic`/`kerberos` have no automatic equivalent.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to