hpathri opened a new pull request, #11789:
URL: https://github.com/apache/gravitino/pull/11789

   …auth
   
   Three changes to support transparent multi-catalog federation (Polaris + 
HMS) through a single Gravitino-managed endpoint:
   
   1. FederatedIcebergCatalog (new built-in catalog-backend=federated): A 
read-federating Iceberg Catalog implementation that wraps a REST backend (e.g. 
Apache Polaris) and a Hive backend (HMS), resolving each table by trying REST 
first then falling back to Hive. Activated via catalog-backend=federated in 
gravitino.conf. Backend configs are passed as namespaced properties 
(federated.rest.* / federated.hive.*).
   
   2. OAuth2 client-credentials for the REST catalog backend: 
IcebergCatalogUtil.loadRestCatalog() previously hardcoded 
UserPrincipalForwardingAuthManager (which only forwards the gravitino user's 
access token). When a catalog has a 'credential' property, Iceberg's built-in 
OAuth2Manager is now used instead, enabling client-credentials auth to services 
like Apache Polaris. Backward compatible — deployments without 'credential' 
keep the existing behavior.
   
   3. redirectTable() delegation in GravitinoMetadata: The Trino connector's 
GravitinoMetadata now delegates redirectTable() to the inner ConnectorMetadata. 
This enables Trino's native hive.iceberg-catalog-name table redirect to fire 
through Gravitino-wrapped catalogs, allowing a single 'unified' Hive catalog to 
serve both Hive Parquet (natively) and Iceberg tables (via redirect to the 
federated backend).
   
   <!--
   1. Title: [#<issue>] <type>(<scope>): <subject>
      Examples:
        - "[#123] feat(operator): Support xxx"
        - "[#233] fix: Check null before access result in xxx"
        - "[MINOR] refactor: Fix typo in variable name"
        - "[MINOR] docs: Fix typo in README"
        - "[#255] test: Fix flaky test NameOfTheTest"
      Reference: https://www.conventionalcommits.org/en/v1.0.0/
   2. If the PR is unfinished, please mark this PR as draft.
   -->
   
   ### What changes were proposed in this pull request?
   
   (Please outline the changes and how this PR fixes the issue.)
   
   ### Why are the changes needed?
   
   (Please clarify why the changes are needed. For instance,
     1. If you propose a new API, clarify the use case for a new API.
     2. If you fix a bug, describe the bug.)
   
   Fix: #(issue)
   
   ### Does this PR introduce _any_ user-facing change?
   
   (Please list the user-facing changes introduced by your change, including
     1. Change in user-facing APIs.
     2. Addition or removal of property keys.)
   
   ### How was this patch tested?
   
   (Please test your changes, and provide instructions on how to test it:
     1. If you add a feature or fix a bug, add a test to cover your changes.
     2. If you fix a flaky test, repeat it for many times to prove it works.)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to