roryqi opened a new pull request, #13546: URL: https://github.com/apache/gravitino/pull/13546
### What changes were proposed in this pull request? Add a design for tag-based row-filter and column-mask policies enforced through Iceberg REST read restrictions. The design defines: - Typed `system_row_filter` and `system_column_mask` policy content. - Policy selection through effective tags. - The `gravitino-filter-v1` expression profile. - Subject and Iceberg schema binding. - Deterministic resolution, canonicalization, deduplication, and conflict handling. - Iceberg REST response, caching, and fail-closed requirements. - An experimental module and reader path before official Iceberg runtime support is available. ### Why are the changes needed? Gravitino can resolve governance policies from tags, but currently has no standard way to restrict visible rows or column values after table access is granted. Iceberg REST read restrictions provide a standard enforcement boundary while keeping engine-specific expressions out of Gravitino policy content. Fix: #13545 ### Does this PR introduce _any_ user-facing change? No. This pull request adds design documentation only. ### How was this patch tested? - `./gradlew spotlessApply` - `python3 .claude/skills/gravitino-docs-refine/scripts/check_links.py design-docs/tag-based-read-restrictions-for-iceberg-rest.md` - `git diff --check` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
