difin opened a new pull request, #6655:
URL: https://github.com/apache/hive/pull/6655
<!--
Thanks for sending a pull request! Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
https://cwiki.apache.org/confluence/display/Hive/HowToContribute
2. Ensure that you have created an issue on the Hive project JIRA:
https://issues.apache.org/jira/projects/HIVE/summary
3. Ensure you have added or run the appropriate tests for your PR:
4. If the PR is unfinished, add '[WIP]' in your PR title, e.g.,
'[WIP]HIVE-XXXXX: Your PR title ...'.
5. Be sure to keep the PR description updated to reflect all changes.
6. Please write your PR title to summarize what this PR proposes.
7. If possible, provide a concise example to reproduce the issue for a
faster review.
-->
### What changes were proposed in this pull request?
<!--
Please clarify what changes you are proposing. The purpose of this section
is to outline the changes and how this PR fixes the issue.
If possible, please consider writing useful notes for better and faster
reviews in your PR. See the examples below.
1. If you refactor some codes with changing classes, showing the class
hierarchy will help reviewers.
2. If you fix some SQL features, you can provide some references of other
DBMSes.
3. If there is design documentation, please add the link.
4. If there is a discussion in the mailing list, please add the link.
-->
This PR extends Iceberg REST vended credential propagation beyond S3 to GCS,
ADLS, and OSS. It refactors `IcebergVendedCredentialUtil` into
provider-specific Hadoop mappers that translate Iceberg `StorageCredential`
config keys into the correct `fs.gs.*`, `fs.azure.*`, and `fs.oss.*`
properties. New GCS/ADLS/OSS secret keys are added to `hive.conf.hidden.list`
so they travel via the secure Credentials channel rather than plain job
properties. Unit tests cover the new mappings and round-trip behavior.
Integration tests are left for follow-up work.
### Why are the changes needed?
<!--
Please clarify why the changes are needed. For instance,
1. If you propose a new API, clarify the use case for a new API.
2. If you fix a bug, you can clarify why it is a bug.
-->
The original vended-credential work only propagated Hadoop mappings for S3.
Iceberg REST catalogs can vend credentials for GCS, ADLS, and OSS as well, but
without equivalent mapping those jobs cannot configure the corresponding Hadoop
FileSystem connectors on Tez/LLAP execution paths. This change closes that gap
so multi-cloud Iceberg deployments can use vended credentials consistently
across providers.
### Does this PR introduce _any_ user-facing change?
<!--
Note that it means *any* user-facing change including all aspects such as
the documentation fix.
If yes, please clarify the previous behavior and the change this PR proposes
- provide the console output, description, screenshot and/or a reproducable
example to show the behavior difference if possible.
If possible, please also clarify if this is a user-facing change compared to
the released Hive versions or within the unreleased branches such as master.
If no, write 'No'.
-->
Yes, for deployments using Iceberg REST catalogs with vended credentials on
GCS, ADLS, or OSS. Those workloads can now propagate storage credentials to
Hadoop FileSystem paths on Tez/LLAP, which was not supported before. Users on
S3-only setups or without vended credentials should see no change in behavior.
### How was this patch tested?
<!--
If tests were added, say they were added here. Please make sure to add some
test cases that check the changes thoroughly including negative and positive
cases if possible.
If it was tested in a way different from regular unit tests, please clarify
how you tested step by step, ideally copy and paste-able, so that other
reviewers can test and check, and descendants can verify in the future.
If tests were not added, please describe why they were not added and/or why
it was difficult to add.
-->
Unit tests in `TestIcebergVendedCredentialUtil` were expanded to cover GCS,
ADLS, and OSS Hadoop property mapping, secret routing into `jobSecrets`, mapper
selection by URI scheme and config-key fallback, and Credentials-channel
round-trip restore. Existing S3 coverage was kept and refactored to use the new
mapper layout. No integration coverage was added for GCS/ADLS/OSS in this PR;
that is planned as follow-up work.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]