thswlsqls opened a new issue, #10227: URL: https://github.com/apache/paimon/issues/10227
# [Feature] Support s3.session-token for temporary credentials in the S3 filesystem plugin **Search before asking** - [x] I searched in the [issues](https://github.com/apache/paimon/issues) and found nothing similar. **Motivation** `S3FileIO` rewrites `s3.*` catalog options to `fs.s3a.*` and then mirrors the hyphenated `access-key` / `secret-key` options to the dotted keys S3A reads. The session token is not mirrored, so `s3.session-token` ends up as `fs.s3a.session-token`, which S3A (hadoop-aws 3.4.2) never reads. With temporary STS credentials passed as hyphenated catalog options in Flink, Spark or Hive, S3A signs without the token and requests fail with 403. The dotted form `s3.session.token` works today and is unaffected. PyPaimon already accepts `s3.session-token` (#7712) and documents it in `docs/docs/pypaimon/catalogs.mdx`; the same options do not work for Java engines. **Solution** Add `{"fs.s3a.session-token", "fs.s3a.session.token"}` to `MIRRORED_CONFIG_KEYS` in `S3FileIO`, next to the access-key and secret-key entries, and mention `s3.session-token` in the S3 section of `docs/docs/maintenance/filesystems.mdx`. Precedence follows the existing mirrors: if both forms are set, the hyphenated one wins. **Anything else?** N/A **Are you willing to submit a PR?** - [x] I'm willing to submit a PR! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
