smaheshwar-pltr commented on PR #13225:
URL: https://github.com/apache/iceberg/pull/13225#issuecomment-5564942054

   @singhpk234 @szlta @ggershinsky, thanks a lot for the discussion here. I was 
wondering if you could folks could clarify what you had in mind here for this 
PR (or happy if implementing is easier)?
   
   Are we requiring complete storage and KMS credential sets when the client 
advertises both `vended-credentials` and `kms-vended-credentials`? Or do we 
want to prohibit a client that advertises only storage vending, from using a 
locally configured KMS?
   
   The latter feels quite intrusive to me, we may have to modify existing 
implementations to impose that. I also wonder about customer-managed Vault or 
cross-cloud KMS/storage use cases where a catalog vending KMS is not necessary 
/ feasible, but I'm not too opinionated. (Also, storage delegation already 
permits clients to use client-configured credentials when no vended credentials 
are returned)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to