Hi Prashant,

Currently, yes, only AWS, but we will support GCP in the next six months.  I 
think GCP has “attribute mappings”. I don’t know enough about GCP yet, but I 
will follow up with support for “attribute mappings” when I get there.

Based on our offline conversation, I also raised 
https://github.com/apache/polaris/issues/3337.  I can work on it after we are 
done with this PR.

—
Anand


From: Prashant Singh <[email protected]>
Date: Monday, December 29, 2025 at 1:02 PM
To: [email protected] <[email protected]>
Cc: Anand Kumar Sankaran <[email protected]>
Subject: Re: feat: Add AWS STS Session Tags support for credential vending #3327

This Message Is From an External Sender
This message came from outside your organization.
Report 
Suspicious<https://us-phishalarm-ewt.proofpoint.com/EWT/v1/Iz9xO38YGHZK!YhNDZAAunAmmqJ0BlYIHU-hY3gvg2U6o3_byYw0Z3YW5wPGKdViU5ab1ogVqkuZkZT_kC9yK-XK3ar7gdk73Ee8Lp8V2oUKt_3Z0zf-EH8yvdc9USCCuwj8OTiso3NX_$>

Welcome to the Polaris community, Anand !

Thank you for the change, I think it's a nice feature to have i.e to capture 
for what table access this cred was vended and for whom
which can help your compliance, I am assuming your organization is only on AWS 
then.

All in all I see value in this change, and am happy to help you with the 
reviews.

Thanks,
Prashant Singh



On Mon, Dec 29, 2025 at 8:42 AM Anand Kumar Sankaran via dev 
<[email protected]<mailto:[email protected]>> wrote:
Hello all,

This is my first PR against the Apache Polaris project.

I am working on deploying Apache Polaris to production for my employer.  We 
have strict requirements around data protection and tracking who accessed what 
data, given a lot of the personal data we deal with.


I raised this enhancement against Polaris.

Add support for AWS STS Session Tags when vending S3 credentials via 
AssumeRole. This enables deterministic correlation between Polaris catalog 
operations and downstream S3 access events in AWS CloudTrail.

https://github.com/apache/polaris/issues/3325<https://urldefense.com/v3/__https://github.com/apache/polaris/issues/3325__;!!Iz9xO38YGHZK!-L_q8c3p0kCiBXt4Mp2QEO5K2aPfsXwOqsxTWSXJSnjU9B171zfVNw7dNEYmDLkQrs2LXv7m9GmX0nr3G7qsXc-8r9WmvWy3$>

This is the PR.

https://github.com/apache/polaris/pull/3327<https://urldefense.com/v3/__https://github.com/apache/polaris/pull/3327__;!!Iz9xO38YGHZK!-L_q8c3p0kCiBXt4Mp2QEO5K2aPfsXwOqsxTWSXJSnjU9B171zfVNw7dNEYmDLkQrs2LXv7m9GmX0nr3G7qsXc-8r-Jcur0E$>

Thanks to Dmitri for the review and I will update the PR later today.

I would appreciate all feedback for this PR and feature request.  I read the 
contribution guidelines, if I missed something, please let me know.

—
Anand
Workday Data Lake

Reply via email to