This is an automated email from the ASF dual-hosted git repository.

RussellSpitzer pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/iceberg.git


The following commit(s) were added to refs/heads/main by this push:
     new 9479711b58 OpenAPI: Formalize remote signing configuration (#16822)
9479711b58 is described below

commit 9479711b5806d2771b9d1f5abc650e7d6f047266
Author: Alexandre Dutra <[email protected]>
AuthorDate: Thu Jul 30 16:52:17 2026 +0200

    OpenAPI: Formalize remote signing configuration (#16822)
---
 open-api/rest-catalog-open-api.py   | 30 +++++++++++++++++++++++++++---
 open-api/rest-catalog-open-api.yaml | 33 ++++++++++++++++++++++++++++++---
 2 files changed, 57 insertions(+), 6 deletions(-)

diff --git a/open-api/rest-catalog-open-api.py 
b/open-api/rest-catalog-open-api.py
index de95134766..412c8322a3 100644
--- a/open-api/rest-catalog-open-api.py
+++ b/open-api/rest-catalog-open-api.py
@@ -1171,6 +1171,21 @@ class RemoteSignResult(BaseModel):
     headers: MultiValuedMap
 
 
+class RemoteSigningConfig(BaseModel):
+    """
+    Configuration for the remote signer client.
+    """
+
+    properties: dict[str, str] | None = Field(
+        None,
+        description='Static key-value pairs the signer client MUST pass 
through unchanged in the `properties` field of every `RemoteSignRequest` sent 
to the signing endpoint.\n',
+    )
+    headers: MultiValuedMap | None = Field(
+        None,
+        description='Static headers the signer client MUST include unchanged 
in every request to the signing endpoint.\n',
+    )
+
+
 class CreateNamespaceRequest(BaseModel):
     namespace: Namespace
     properties: dict[str, str] | None = Field(
@@ -1722,9 +1737,15 @@ class LoadTableResult(BaseModel):
 
     ## Remote Signing
 
-    If remote signing for a specific storage provider is enabled, clients must 
respect the following configurations when creating a remote signer client:
-     - `signer.endpoint`: the remote signer endpoint. Required. Can either be 
a relative path (to be resolved against `signer.uri`) or an absolute URI.
-     - `signer.uri`: the base URI to resolve `signer.endpoint` against. 
Optional. Only meaningful if `signer.endpoint` is a relative path. Defaults to 
the catalog's base URI if not set.
+    If remote signing for a specific storage provider is enabled, the server 
SHOULD use the `remote-signing-config`
+    field to communicate all signer client settings. When the 
`remote-signing-config` field is present, clients
+    SHOULD respect the provided configuration.
+
+    For backward compatibility, the following `config` properties are still 
supported but **DEPRECATED** and SHOULD NOT be used by clients able to consume 
the remote signing configuration:
+     - `signer.endpoint` **DEPRECATED**.: the remote signer endpoint. Can 
either be a relative path (to be resolved against `signer.uri`) or an absolute 
URI.
+     - `signer.uri` **DEPRECATED**.: the base URI to resolve `signer.endpoint` 
against. Only meaningful if `signer.endpoint` is a relative path. Defaults to 
the catalog's base URI if not set.
+    If any of these properties is present, clients SHOULD use them to compute 
the actual remote signing endpoint URI to contact.
+    If none of these properties is present, clients SHOULD contact the default 
remote signing endpoint using the catalog's base URI.
 
     """
 
@@ -1738,6 +1759,9 @@ class LoadTableResult(BaseModel):
     storage_credentials: list[StorageCredential] | None = Field(
         None, alias='storage-credentials'
     )
+    remote_signing_config: RemoteSigningConfig | None = Field(
+        None, alias='remote-signing-config'
+    )
 
 
 class ScanTasks(BaseModel):
diff --git a/open-api/rest-catalog-open-api.yaml 
b/open-api/rest-catalog-open-api.yaml
index dfa97292d0..11e70da547 100644
--- a/open-api/rest-catalog-open-api.yaml
+++ b/open-api/rest-catalog-open-api.yaml
@@ -3881,9 +3881,16 @@ components:
 
         ## Remote Signing
 
-        If remote signing for a specific storage provider is enabled, clients 
must respect the following configurations when creating a remote signer client:
-         - `signer.endpoint`: the remote signer endpoint. Required. Can either 
be a relative path (to be resolved against `signer.uri`) or an absolute URI.
-         - `signer.uri`: the base URI to resolve `signer.endpoint` against. 
Optional. Only meaningful if `signer.endpoint` is a relative path. Defaults to 
the catalog's base URI if not set.
+        If remote signing for a specific storage provider is enabled, the 
server SHOULD use the `remote-signing-config`
+        field to communicate all signer client settings. When the 
`remote-signing-config` field is present, clients
+        SHOULD respect the provided configuration.
+
+        For backward compatibility, the following `config` properties are 
still supported but **DEPRECATED** and SHOULD NOT be used by clients able to 
consume the remote signing configuration:
+         - `signer.endpoint` **DEPRECATED**.: the remote signer endpoint. Can 
either be a relative path (to be resolved against `signer.uri`) or an absolute 
URI.
+         - `signer.uri` **DEPRECATED**.: the base URI to resolve 
`signer.endpoint` against. Only meaningful if `signer.endpoint` is a relative 
path. Defaults to the catalog's base URI if not set.
+        If any of these properties is present, clients SHOULD use them to 
compute the actual remote signing endpoint URI to contact.
+        If none of these properties is present, clients SHOULD contact the 
default remote signing endpoint using the catalog's base URI.
+
       type: object
       required:
         - metadata
@@ -3902,6 +3909,8 @@ components:
           type: array
           items:
             $ref: '#/components/schemas/StorageCredential'
+        remote-signing-config:
+          $ref: '#/components/schemas/RemoteSigningConfig'
 
     ScanTasks:
       type: object
@@ -5448,6 +5457,24 @@ components:
         headers:
           $ref: '#/components/schemas/MultiValuedMap'
 
+    RemoteSigningConfig:
+      description: Configuration for the remote signer client.
+      type: object
+      properties:
+        properties:
+          type: object
+          additionalProperties:
+            type: string
+          description: >
+            Static key-value pairs the signer client MUST pass through 
unchanged in the `properties`
+            field of every `RemoteSignRequest` sent to the signing endpoint.
+        headers:
+          allOf:
+            - $ref: '#/components/schemas/MultiValuedMap'
+          description: >
+            Static headers the signer client MUST include unchanged in every 
request to the signing
+            endpoint.
+
   #############################
   # Reusable Response Objects #
   #############################

Reply via email to