Nandor Kollar has posted comments on this change. ( http://gerrit.cloudera.org:8080/24840 )
Change subject: IMPALA-15147: Handle token expiration and credential lifetime extension for vended credentials ...................................................................... Patch Set 5: (1 comment) http://gerrit.cloudera.org:8080/#/c/24840/5/fe/src/main/java/org/apache/impala/catalog/local/IcebergMetaProvider.java File fe/src/main/java/org/apache/impala/catalog/local/IcebergMetaProvider.java: http://gerrit.cloudera.org:8080/#/c/24840/5/fe/src/main/java/org/apache/impala/catalog/local/IcebergMetaProvider.java@231 PS5, Line 231: Pair<Table, TableMetaRef> loaded = loadTable(dbName, tableName); I think we do a full load table here, which sounds like an overkill to fetch storage credential. I think IRC spec has a dedicated endpoint to solve this scenario: /v1/{prefix}/namespaces/{namespace}/tables/{table}/credentials, however the Java SDK which we use doesn't seem to expose this endpoint. We should either improve Iceberg SDK, or regenerate the client from the latest IRC spec. Can this be a potential bottleneck in the future: With Polaris, the default token TTL is 1 hour, thus this is probably not a critical for now, though catalog admins can lower it to 15 minute (minimum value of AWS STS), and actually Lakekeeper's default TTL value seems to be 15 minute too. I think we should open a followup improvement ticket to avoid full table load in this case. -- To view, visit http://gerrit.cloudera.org:8080/24840 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I7fafc33bd78c2cdb19724a7f89536fdd7ad3c6d6 Gerrit-Change-Number: 24840 Gerrit-PatchSet: 5 Gerrit-Owner: Peter Rozsa <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Nandor Kollar <[email protected]> Gerrit-Comment-Date: Wed, 30 Sep 2026 14:07:34 +0000 Gerrit-HasComments: Yes
