abhishekmauryaKsolves opened a new pull request, #18337:
URL: https://github.com/apache/iceberg/pull/18337
Part of #18300
Adds a table property `encryption.kek-generation-enabled` (default `false`).
When enabled and the configured KeyManagementClient reports
`supportsKeyGeneration()`, the key encryption key is generated by the KMS via
`generateKey()` instead of being created locally and wrapped via `wrapKey()`.
The default keeps the current behavior.
Changes:
- TableProperties: new property and default
- EncryptionUtil: read the property, and treat it as an encryption property
that is invalid before format v3
- StandardEncryptionManager: choose generateKey() vs wrapKey() when creating
a KEK;
the existing public constructor is kept and defaults to wrap
- docs: document the new property in configuration.md
Tests: new TestStandardEncryptionManager covering default, enabled, enabled
with an unsupported client, the table property path, and the v2 check.
Open question: local keys use `encryption.data-key-length`, while a KMS
generated key uses the KMS client's own key spec (e.g. AWS `dataKeySpec`).
These could differ; happy to add validation if reviewers want it.
AI disclosure: I used an AI assistant for drafting parts of the code and
tests.
I reviewed the changes and ran the related tests locally.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]