diqiu50 opened a new pull request, #13370:
URL: https://github.com/apache/gravitino/pull/13370

   ### What changes were proposed in this pull request?
   
   - Recognize AWS Glue authentication error codes separately from 
authorization and general connection failures.
   - Convert credential-provider resolution failures and AWS-rejected 
credentials into actionable connection errors that identify the relevant 
Gravitino catalog properties.
   - Apply the same actionable authentication diagnostics to Glue schema and 
table operations.
   - Keep catalog creation offline-capable; static credentials are not 
authenticated during catalog creation.
   
   ### Why are the changes needed?
   
   Static AWS credentials can resolve locally even when AWS will reject them. 
Glue connection checks and metadata operations currently expose raw or generic 
AWS SDK errors, which do not tell users which catalog properties need 
correction.
   
   Fix: #13369
   
   ### Does this PR introduce _any_ user-facing change?
   
   Yes. Glue connection tests and metadata operations now report clearer 
authentication failures and identify `aws-access-key-id` and 
`aws-secret-access-key`. Catalog creation behavior is unchanged.
   
   ### How was this patch tested?
   
   Added unit tests for:
   
   - Missing credentials in the default provider chain.
   - AWS-rejected static credentials during connection tests.
   - AWS-rejected credentials during schema operations.
   - Authentication error-code recognition and conversion.
   - Credential-provider resolution failures.
   
   Ran:
   
   `./gradlew :catalogs:catalog-glue:spotlessApply :catalogs:catalog-glue:test 
-PskipITs`
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to