ggershinsky commented on code in PR #18210:
URL: https://github.com/apache/iceberg/pull/18210#discussion_r4090718047


##########
aliyun/src/main/java/org/apache/iceberg/aliyun/AliyunProperties.java:
##########
@@ -76,11 +76,31 @@ public class AliyunProperties implements Serializable {
    */
   public static final String OSS_STAGING_DIRECTORY = "oss.staging-dir";
 
+  /**
+   * The region id used to derive a service endpoint, for example {@code 
cn-hangzhou}. Used by the
+   * Aliyun KMS client to resolve {@code kms.<region>.aliyuncs.com}.
+   */
+  public static final String CLIENT_REGION = "client.region";
+
+  /**
+   * Overrides the KMS endpoint. Defaults to the region-derived {@code 
kms.<region>.aliyuncs.com}.
+   * Set to a KMS Instance (DKMS) endpoint for keys that live in a KMS 
Instance.
+   */
+  public static final String CLIENT_KMS_ENDPOINT = "client.kms-endpoint";
+
+  /** The data key spec used when generating data keys with Aliyun KMS: 
AES_256 or AES_128. */
+  public static final String KMS_DATA_KEY_SPEC = 
"kms.client.aliyun.generation.data_key_spec";

Review Comment:
   Even better, we can use this opportunity to introduce different parameters 
for the length of different keys. This one actually generates a "key encryption 
key", that encrypts keys for manifest list, stats and other files. 
   While the name "kms.client....generation.data_key_spec" still makes sense 
(from KMS point of view, any generated key is a "data key"), the comment above 
should probably explain the situation.
   
   The 
https://github.com/apache/iceberg/blob/main/core/src/main/java/org/apache/iceberg/TableProperties.java#L461
 is used for actual data keys that encrypt data, delete, manifest and manifest 
list files.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to