diqiu50 opened a new issue, #13357:
URL: https://github.com/apache/gravitino/issues/13357
### Version
main branch
### Describe what's wrong
When a `lakehouse-iceberg` catalog is routed through the Gravitino Iceberg
REST server (IRC), the
Trino connector only propagates authentication to the internal Iceberg REST
client when
`gravitino.client.authType=oauth2`. For `simple`, `basic`, and `kerberos`, no
`iceberg.rest-catalog.security` is ever set.
The catalog registers successfully, but every query fails once the IRC
requires authentication.
This happens at the first REST call (`GET /v1/config`), before any table
access, so it also blocks
vended credentials (`s3-token`, etc.) from ever being exercised.
### Error message and/or stacktrace
```
Query failed: Cannot obtain metadata
caused by: org.apache.iceberg.exceptions.NotAuthorizedException: Not
authorized
at org.apache.iceberg.rest.RESTSessionCatalog.fetchConfig
at
io.trino.plugin.iceberg.catalog.rest.TrinoIcebergRestCatalogFactory.create
```
### How to reproduce
1. Run a Gravitino server with an authenticator that requires credentials
(`simple` is enough) and
the Iceberg REST server enabled.
2. Configure the Trino connector with `gravitino.client.authType=simple` (or
`basic`/`kerberos`).
3. Register a `lakehouse-iceberg` catalog routed through the IRC.
4. Run `SHOW SCHEMAS FROM <catalog>` — fails with `NotAuthorizedException`.
### Additional context
Trino's Iceberg REST client only supports `iceberg.rest-catalog.security =
NONE | OAUTH2`
(pre-481), so `simple`/`basic`/`kerberos` have no automatic equivalent.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]