LiJie20190102 opened a new pull request, #13500:
URL: https://github.com/apache/gravitino/pull/13500

   
   
   ### What changes were proposed in this pull request?
   
   Add support for encrypted password values in `gravitino.conf` using 
AES-256-GCM (JDK built-in `javax.crypto`, zero external dependencies). 
Encrypted values use `ENC(base64(...))` format and are transparently decrypted 
at server startup.
   
   **New files:**
   - `common/.../utils/PasswordEncryptor.java` — encrypt/decrypt utility, 
`isEncrypted()`, `decryptIfNeeded()`, `shouldWarnDefaultKey(configValue)`, 
default key `"gravitino"` fallback
   - `common/.../utils/PasswordEncryptorCLI.java` — Java CLI tool (`encrypt` / 
`decrypt` subcommands, interactive mode, zero external deps)
   - `common/.../utils/TestPasswordEncryptor.java` — unit tests
   - `scripts/encrypt_password.py` — Python encryption script, fully 
interoperable with Java (same AES-256-GCM + PBKDF2WithHmacSHA256)
   
   **Modified files:**
   - `core/.../database/H2Database.java` — wrap password read with 
`decryptIfNeeded()` + default key warning
   - `core/.../session/SqlSessionFactoryHelper.java` — same
   - `core/.../stats/StatisticManager.java` — same + partition options override 
decrypt via `computeIfPresent`
   - `core/.../session/TestSqlSession.java` — add ENC scenario test
   - `core/.../stats/TestStatisticManager.java` — add partition ENC password 
override decrypt test
   - `conf/gravitino.conf.template` — default value changed to `ENC(...)`, add 
usage instructions
   - `core/Configs.java` — default password changed to `ENC(...)`
   - `dev/docker/gravitino/rewrite_gravitino_server_config.py` — align 
container default with `ENC(...)` value
   - `docs/gravitino-server-config.md` — update defaults, add 
`GRAVITINO_PASSWORD_ENCRYPTION_KEY` note
   - `docs/how-to-use-relational-backend-storage.md` — add encryption 
instructions
   
   ### Why are the changes needed?
   
   `gravitino.conf` currently stores the JDBC password in plaintext 
(`gravitino.entity.store.relational.jdbcPassword = gravitino`), which is a 
security risk in production: anyone with read access to the config file can see 
the database password. Compliance requirements (SOC2, GDPR) typically mandate 
that credentials at rest be encrypted.
   
   Fix: #13314 
   
   ### Does this PR introduce _any_ user-facing change?
   
   Yes.
   
   1. The default value of `gravitino.entity.store.relational.jdbcPassword` 
changes from plaintext `gravitino` to `ENC(...)` (encrypted form of `gravitino` 
using the default master key `gravitino`). Existing plaintext values continue 
to work unchanged (`decryptIfNeeded()` passes through non-`ENC(...)` values).
   2. New environment variable `GRAVITINO_PASSWORD_ENCRYPTION_KEY` (and system 
property `gravitino.password.encryption.key`) for the master encryption key. 
Defaults to `gravitino` for out-of-box experience; **a custom key must be set 
for production** (one-time `LOG.warn` emitted when default key is used with an 
encrypted value).
   3. New CLI tool and Python script for encrypting/decrypting passwords.
   
   ### How was this patch tested?
   
   1. `TestPasswordEncryptor` — 15 unit tests covering encrypt/decrypt 
roundtrip, wrong key, tampered ciphertext (GCM integrity), default key 
fallback, Unicode, special characters, blank/null inputs.
   2. `TestSqlSession.testInitWithEncryptedPassword` — mock config returns 
`ENC(...)` value, verify decrypted password reaches the data source.
   3. 
`TestStatisticManager.testBuildStorageOptionsPartitionEncryptedPasswordOverrides`
 — verify partition-specific `ENC(...)` password is decrypted after overriding 
entity store password.
   4. Cross-language interoperability verified: Java encrypt → Python decrypt, 
Python encrypt → Java decrypt.
   5. CLI standalone execution verified: `java -cp gravitino-common-*.jar 
org.apache.gravitino.utils.PasswordEncryptorCLI encrypt "test" --key "key"` 
runs without additional classpath dependencies.
   6. Wrong key produces clear error: "the master encryption key is incorrect 
or the encrypted data has been tampered with."
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to