Peter Rozsa has uploaded this change for review. ( 
http://gerrit.cloudera.org:8080/24840


Change subject: IMPALA-15147: Handle token expiration and credential lifetime 
extension for vended credentials
......................................................................

IMPALA-15147: Handle token expiration and credential lifetime extension for 
vended credentials

Vended STS credentials are short-lived, so a long-running query can
outlive the token it started with. Executors run libhdfs and have no
Iceberg FileIO or AWS SDK to self-refresh, so refresh is routed through
the coordinator, which owns the frontend and the REST catalog session.

Backend:
- CredentialEntry gains IsNearExpiry() / IsFullyExpired(), driven by the
  new --credential_refresh_threshold_s flag (default 300s).
- QueryCredentials refreshes a table's credentials with one
  FetchCredentials RPC. The refresh happens inline in FindCredential(),
  i.e. when HdfsFsCache resolves a connection for a file open and the
  covering credential is near expiry, so the connection built for that
  open already carries the fresh token (its cache key includes a digest
  of the material, IMPALA-15145). Reads in progress keep the connection
  they opened with. Per table at most one refresh is in flight (other
  lookups wait on it, bounded by the RPC timeout) and refreshes are rate
  limited by --credential_refresh_min_interval_s (default 60s), so a
  token with a lifetime below the threshold does not cause a refresh per
  lookup. If a refresh fails, entries that are fully expired are skipped
  by lookups, which fall back to the process-global credential, but stay
  registered (fragments only register credentials at init) so a later
  refresh can restore them.
- New ControlService::FetchCredentials RPC. The coordinator validates
  that the query id belongs to a live query that references the table
  (pinning the query for the duration of the call), then runs the
  frontend round trip on a dedicated thread pool
  (--credential_fetch_threads) so a slow catalog cannot stall the service
  threads shared with ReportExecStatus; when that pool's queue is full
  the request is rejected (the backend retries at its next interval)
  rather than blocking a service thread. The credentials are returned as
  a Thrift sidecar. QueryState exposes coord_proxy() so executors reuse
  the existing coordinator link.

Frontend:
- TFetchCredentialsRequest/Response and JniFrontend.fetchCredentials()
  wrap Frontend.fetchCredentials(), which goes FeCatalog -> MetaProvider
  -> IcebergMetaProvider and issues a fresh REST loadTable to obtain the
  table's current credentials. MultiMetaProvider routes to the provider
  that owns the table, moving on to the next one whatever kind of
  exception a provider that does not own it throws. Failures propagate
  to the backend with their cause instead of being reported as an empty
  list.

Tests:
- test_iceberg_credential_vending adds two cases that set the refresh
  threshold above the token TTL so lookups take the refresh path: a scan
  of ice_s3.nation that checks a refresh was logged, and a scan of the
  100-file ice_s3.many_files table that checks the refreshes are rate
  limited to a handful rather than one per file.

Change-Id: I7fafc33bd78c2cdb19724a7f89536fdd7ad3c6d6
Assisted-by: Claude Fable 5.1 <[email protected]>
---
M be/src/runtime/query-credentials.cc
M be/src/runtime/query-credentials.h
M be/src/runtime/query-state.h
M be/src/service/control-service.cc
M be/src/service/control-service.h
M be/src/service/frontend.cc
M be/src/service/frontend.h
M common/protobuf/control_service.proto
M common/thrift/Frontend.thrift
M fe/src/main/java/org/apache/impala/catalog/FeCatalog.java
M fe/src/main/java/org/apache/impala/catalog/local/IcebergMetaProvider.java
M fe/src/main/java/org/apache/impala/catalog/local/LocalCatalog.java
M fe/src/main/java/org/apache/impala/catalog/local/MetaProvider.java
M fe/src/main/java/org/apache/impala/catalog/local/MetaProviderDecorator.java
M fe/src/main/java/org/apache/impala/catalog/local/MultiMetaProvider.java
M fe/src/main/java/org/apache/impala/service/Frontend.java
M fe/src/main/java/org/apache/impala/service/JniFrontend.java
M tests/custom_cluster/test_iceberg_credential_vending.py
18 files changed, 610 insertions(+), 25 deletions(-)



  git pull ssh://gerrit.cloudera.org:29418/Impala-ASF refs/changes/40/24840/5
--
To view, visit http://gerrit.cloudera.org:8080/24840
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: newchange
Gerrit-Change-Id: I7fafc33bd78c2cdb19724a7f89536fdd7ad3c6d6
Gerrit-Change-Number: 24840
Gerrit-PatchSet: 5
Gerrit-Owner: Peter Rozsa <[email protected]>

Reply via email to