diqiu50 opened a new issue, #13369:
URL: https://github.com/apache/gravitino/issues/13369

   ### Version\n\nmain branch\n\n### Describe the bug\n\nThe Glue static 
credentials provider accepts any non-empty access key and secret key during 
local configuration validation because resolving static credentials does not 
authenticate them with AWS.\n\nThis is required for offline catalog creation, 
but later connection and metadata operations may expose a raw AWS SDK 
authentication error. The error does not identify the relevant Gravitino 
catalog properties, so users cannot easily determine how to correct the 
configuration.\n\nCredential-provider resolution failures are also reported as 
argument validation errors even though they are connection failures.\n\nCatalog 
creation should remain offline-capable. Glue connection checks and runtime 
metadata operations should instead report actionable errors that identify  and 
.\n\n### Error message and/or stacktrace\n\nFor example, invalid static 
credentials may surface an AWS error such as  without identifying which 
Gravitino catalog prop
 erties must be corrected.\n\n### How to reproduce\n\n1. Configure a Glue 
catalog with the static credentials provider and syntactically valid but 
rejected values for  and .\n2. Call , or execute a Glue metadata operation.\n3. 
Observe that the failure is reported as a raw or generic AWS SDK error rather 
than an actionable catalog-credential error.\n\n### Additional 
context\n\nRelated to #13012, which improved errors for missing credentials. 
This issue covers credentials that resolve locally but are rejected by AWS, 
while preserving offline catalog creation.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to