thswlsqls opened a new issue, #10227:
URL: https://github.com/apache/paimon/issues/10227

   # [Feature] Support s3.session-token for temporary credentials in the S3 
filesystem plugin
   
   **Search before asking**
   - [x] I searched in the [issues](https://github.com/apache/paimon/issues) 
and found nothing similar.
   
   **Motivation**
   `S3FileIO` rewrites `s3.*` catalog options to `fs.s3a.*` and then mirrors 
the hyphenated `access-key` / `secret-key` options to the dotted keys S3A 
reads. The session token is not mirrored, so `s3.session-token` ends up as 
`fs.s3a.session-token`, which S3A (hadoop-aws 3.4.2) never reads. With 
temporary STS credentials passed as hyphenated catalog options in Flink, Spark 
or Hive, S3A signs without the token and requests fail with 403. The dotted 
form `s3.session.token` works today and is unaffected.
   
   PyPaimon already accepts `s3.session-token` (#7712) and documents it in 
`docs/docs/pypaimon/catalogs.mdx`; the same options do not work for Java 
engines.
   
   **Solution**
   Add `{"fs.s3a.session-token", "fs.s3a.session.token"}` to 
`MIRRORED_CONFIG_KEYS` in `S3FileIO`, next to the access-key and secret-key 
entries, and mention `s3.session-token` in the S3 section of 
`docs/docs/maintenance/filesystems.mdx`. Precedence follows the existing 
mirrors: if both forms are set, the hyphenated one wins.
   
   **Anything else?**
   N/A
   
   **Are you willing to submit a PR?**
   - [x] I'm willing to submit a PR!
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to