LiJie20190102 opened a new pull request, #13500: URL: https://github.com/apache/gravitino/pull/13500
### What changes were proposed in this pull request? Add support for encrypted password values in `gravitino.conf` using AES-256-GCM (JDK built-in `javax.crypto`, zero external dependencies). Encrypted values use `ENC(base64(...))` format and are transparently decrypted at server startup. **New files:** - `common/.../utils/PasswordEncryptor.java` — encrypt/decrypt utility, `isEncrypted()`, `decryptIfNeeded()`, `shouldWarnDefaultKey(configValue)`, default key `"gravitino"` fallback - `common/.../utils/PasswordEncryptorCLI.java` — Java CLI tool (`encrypt` / `decrypt` subcommands, interactive mode, zero external deps) - `common/.../utils/TestPasswordEncryptor.java` — unit tests - `scripts/encrypt_password.py` — Python encryption script, fully interoperable with Java (same AES-256-GCM + PBKDF2WithHmacSHA256) **Modified files:** - `core/.../database/H2Database.java` — wrap password read with `decryptIfNeeded()` + default key warning - `core/.../session/SqlSessionFactoryHelper.java` — same - `core/.../stats/StatisticManager.java` — same + partition options override decrypt via `computeIfPresent` - `core/.../session/TestSqlSession.java` — add ENC scenario test - `core/.../stats/TestStatisticManager.java` — add partition ENC password override decrypt test - `conf/gravitino.conf.template` — default value changed to `ENC(...)`, add usage instructions - `core/Configs.java` — default password changed to `ENC(...)` - `dev/docker/gravitino/rewrite_gravitino_server_config.py` — align container default with `ENC(...)` value - `docs/gravitino-server-config.md` — update defaults, add `GRAVITINO_PASSWORD_ENCRYPTION_KEY` note - `docs/how-to-use-relational-backend-storage.md` — add encryption instructions ### Why are the changes needed? `gravitino.conf` currently stores the JDBC password in plaintext (`gravitino.entity.store.relational.jdbcPassword = gravitino`), which is a security risk in production: anyone with read access to the config file can see the database password. Compliance requirements (SOC2, GDPR) typically mandate that credentials at rest be encrypted. Fix: #13314 ### Does this PR introduce _any_ user-facing change? Yes. 1. The default value of `gravitino.entity.store.relational.jdbcPassword` changes from plaintext `gravitino` to `ENC(...)` (encrypted form of `gravitino` using the default master key `gravitino`). Existing plaintext values continue to work unchanged (`decryptIfNeeded()` passes through non-`ENC(...)` values). 2. New environment variable `GRAVITINO_PASSWORD_ENCRYPTION_KEY` (and system property `gravitino.password.encryption.key`) for the master encryption key. Defaults to `gravitino` for out-of-box experience; **a custom key must be set for production** (one-time `LOG.warn` emitted when default key is used with an encrypted value). 3. New CLI tool and Python script for encrypting/decrypting passwords. ### How was this patch tested? 1. `TestPasswordEncryptor` — 15 unit tests covering encrypt/decrypt roundtrip, wrong key, tampered ciphertext (GCM integrity), default key fallback, Unicode, special characters, blank/null inputs. 2. `TestSqlSession.testInitWithEncryptedPassword` — mock config returns `ENC(...)` value, verify decrypted password reaches the data source. 3. `TestStatisticManager.testBuildStorageOptionsPartitionEncryptedPasswordOverrides` — verify partition-specific `ENC(...)` password is decrypted after overriding entity store password. 4. Cross-language interoperability verified: Java encrypt → Python decrypt, Python encrypt → Java decrypt. 5. CLI standalone execution verified: `java -cp gravitino-common-*.jar org.apache.gravitino.utils.PasswordEncryptorCLI encrypt "test" --key "key"` runs without additional classpath dependencies. 6. Wrong key produces clear error: "the master encryption key is incorrect or the encrypted data has been tampered with." -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
