This is an automated email from the ASF dual-hosted git repository.
RussellSpitzer pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/iceberg.git
The following commit(s) were added to refs/heads/main by this push:
new 9479711b58 OpenAPI: Formalize remote signing configuration (#16822)
9479711b58 is described below
commit 9479711b5806d2771b9d1f5abc650e7d6f047266
Author: Alexandre Dutra <[email protected]>
AuthorDate: Thu Jul 30 16:52:17 2026 +0200
OpenAPI: Formalize remote signing configuration (#16822)
---
open-api/rest-catalog-open-api.py | 30 +++++++++++++++++++++++++++---
open-api/rest-catalog-open-api.yaml | 33 ++++++++++++++++++++++++++++++---
2 files changed, 57 insertions(+), 6 deletions(-)
diff --git a/open-api/rest-catalog-open-api.py
b/open-api/rest-catalog-open-api.py
index de95134766..412c8322a3 100644
--- a/open-api/rest-catalog-open-api.py
+++ b/open-api/rest-catalog-open-api.py
@@ -1171,6 +1171,21 @@ class RemoteSignResult(BaseModel):
headers: MultiValuedMap
+class RemoteSigningConfig(BaseModel):
+ """
+ Configuration for the remote signer client.
+ """
+
+ properties: dict[str, str] | None = Field(
+ None,
+ description='Static key-value pairs the signer client MUST pass
through unchanged in the `properties` field of every `RemoteSignRequest` sent
to the signing endpoint.\n',
+ )
+ headers: MultiValuedMap | None = Field(
+ None,
+ description='Static headers the signer client MUST include unchanged
in every request to the signing endpoint.\n',
+ )
+
+
class CreateNamespaceRequest(BaseModel):
namespace: Namespace
properties: dict[str, str] | None = Field(
@@ -1722,9 +1737,15 @@ class LoadTableResult(BaseModel):
## Remote Signing
- If remote signing for a specific storage provider is enabled, clients must
respect the following configurations when creating a remote signer client:
- - `signer.endpoint`: the remote signer endpoint. Required. Can either be
a relative path (to be resolved against `signer.uri`) or an absolute URI.
- - `signer.uri`: the base URI to resolve `signer.endpoint` against.
Optional. Only meaningful if `signer.endpoint` is a relative path. Defaults to
the catalog's base URI if not set.
+ If remote signing for a specific storage provider is enabled, the server
SHOULD use the `remote-signing-config`
+ field to communicate all signer client settings. When the
`remote-signing-config` field is present, clients
+ SHOULD respect the provided configuration.
+
+ For backward compatibility, the following `config` properties are still
supported but **DEPRECATED** and SHOULD NOT be used by clients able to consume
the remote signing configuration:
+ - `signer.endpoint` **DEPRECATED**.: the remote signer endpoint. Can
either be a relative path (to be resolved against `signer.uri`) or an absolute
URI.
+ - `signer.uri` **DEPRECATED**.: the base URI to resolve `signer.endpoint`
against. Only meaningful if `signer.endpoint` is a relative path. Defaults to
the catalog's base URI if not set.
+ If any of these properties is present, clients SHOULD use them to compute
the actual remote signing endpoint URI to contact.
+ If none of these properties is present, clients SHOULD contact the default
remote signing endpoint using the catalog's base URI.
"""
@@ -1738,6 +1759,9 @@ class LoadTableResult(BaseModel):
storage_credentials: list[StorageCredential] | None = Field(
None, alias='storage-credentials'
)
+ remote_signing_config: RemoteSigningConfig | None = Field(
+ None, alias='remote-signing-config'
+ )
class ScanTasks(BaseModel):
diff --git a/open-api/rest-catalog-open-api.yaml
b/open-api/rest-catalog-open-api.yaml
index dfa97292d0..11e70da547 100644
--- a/open-api/rest-catalog-open-api.yaml
+++ b/open-api/rest-catalog-open-api.yaml
@@ -3881,9 +3881,16 @@ components:
## Remote Signing
- If remote signing for a specific storage provider is enabled, clients
must respect the following configurations when creating a remote signer client:
- - `signer.endpoint`: the remote signer endpoint. Required. Can either
be a relative path (to be resolved against `signer.uri`) or an absolute URI.
- - `signer.uri`: the base URI to resolve `signer.endpoint` against.
Optional. Only meaningful if `signer.endpoint` is a relative path. Defaults to
the catalog's base URI if not set.
+ If remote signing for a specific storage provider is enabled, the
server SHOULD use the `remote-signing-config`
+ field to communicate all signer client settings. When the
`remote-signing-config` field is present, clients
+ SHOULD respect the provided configuration.
+
+ For backward compatibility, the following `config` properties are
still supported but **DEPRECATED** and SHOULD NOT be used by clients able to
consume the remote signing configuration:
+ - `signer.endpoint` **DEPRECATED**.: the remote signer endpoint. Can
either be a relative path (to be resolved against `signer.uri`) or an absolute
URI.
+ - `signer.uri` **DEPRECATED**.: the base URI to resolve
`signer.endpoint` against. Only meaningful if `signer.endpoint` is a relative
path. Defaults to the catalog's base URI if not set.
+ If any of these properties is present, clients SHOULD use them to
compute the actual remote signing endpoint URI to contact.
+ If none of these properties is present, clients SHOULD contact the
default remote signing endpoint using the catalog's base URI.
+
type: object
required:
- metadata
@@ -3902,6 +3909,8 @@ components:
type: array
items:
$ref: '#/components/schemas/StorageCredential'
+ remote-signing-config:
+ $ref: '#/components/schemas/RemoteSigningConfig'
ScanTasks:
type: object
@@ -5448,6 +5457,24 @@ components:
headers:
$ref: '#/components/schemas/MultiValuedMap'
+ RemoteSigningConfig:
+ description: Configuration for the remote signer client.
+ type: object
+ properties:
+ properties:
+ type: object
+ additionalProperties:
+ type: string
+ description: >
+ Static key-value pairs the signer client MUST pass through
unchanged in the `properties`
+ field of every `RemoteSignRequest` sent to the signing endpoint.
+ headers:
+ allOf:
+ - $ref: '#/components/schemas/MultiValuedMap'
+ description: >
+ Static headers the signer client MUST include unchanged in every
request to the signing
+ endpoint.
+
#############################
# Reusable Response Objects #
#############################