dwsmith1983 commented on code in PR #5872:
URL: https://github.com/apache/datafusion-comet/pull/5872#discussion_r4171582544
##########
native/core/src/parquet/objectstore/s3.rs:
##########
@@ -943,11 +1103,35 @@ impl CredentialProviderMetadata {
.build();
Ok(Arc::new(credential_provider))
}
- CredentialProviderMetadata::Profile => {
- let credential_provider =
ProfileFileCredentialsProvider::builder()
- .configure(&ProviderConfig::with_default_region().await)
- .build();
- Ok(Arc::new(credential_provider))
+ CredentialProviderMetadata::Profile {
+ name,
+ file,
+ credentials_only,
+ } => {
+ let mut builder = ProfileFileCredentialsProvider::builder()
+ .configure(&ProviderConfig::with_default_region().await);
Review Comment:
The Hadoop profile provider now resolves its STS region from the selected
profile first, using the same profile name and file the credentials come from,
then the default region chain, then us-east-1, the order
`StsProfileCredentialsProviderFactory.configureEndpoint` uses. The default
chain is only consulted when the profile has no `region`, so it doesn't probe
IMDS when the profile already answers. The SDK alias spellings keep their
current behaviour.
The test uses your assume-role shape with a synthetic file and an in-memory
HTTP client and checks which STS host each case reaches: profile `region`
alone, profile `region` over a default-chain region and over
`fs.s3a.endpoint.region`, no profile `region`, and no region anywhere.
Two differences from Java remain. When nothing supplies a region, native
reaches `sts.us-east-1.amazonaws.com` rather than the global
`sts.amazonaws.com`, since aws-config has no supported way to pin that host;
AssumeRole behaves the same at either. And when the role profile has no
`region`, aws-config also checks its `source_profile` before the default chain,
where Java goes straight to the chain. A test pins that case.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]