Peter Rozsa has uploaded this change for review. ( http://gerrit.cloudera.org:8080/24840
Change subject: IMPALA-15147: Handle token expiration and credential lifetime extension for vended credentials ...................................................................... IMPALA-15147: Handle token expiration and credential lifetime extension for vended credentials Vended STS credentials are short-lived, so a long-running query can outlive the token it started with. Executors run libhdfs and have no Iceberg FileIO or AWS SDK to self-refresh, so refresh is routed through the coordinator, which owns the frontend and the REST catalog session. Backend: - CredentialEntry gains IsNearExpiry() / IsFullyExpired(), driven by the new --credential_refresh_threshold_s flag (default 300s). - QueryCredentials refreshes a table's credentials with one FetchCredentials RPC. The refresh happens inline in FindCredential(), i.e. when HdfsFsCache resolves a connection for a file open and the covering credential is near expiry, so the connection built for that open already carries the fresh token (its cache key includes a digest of the material, IMPALA-15145). Reads in progress keep the connection they opened with. Per table at most one refresh is in flight (other lookups wait on it, bounded by the RPC timeout) and refreshes are rate limited by --credential_refresh_min_interval_s (default 60s), so a token with a lifetime below the threshold does not cause a refresh per lookup. If a refresh fails, entries that are fully expired are skipped by lookups, which fall back to the process-global credential, but stay registered (fragments only register credentials at init) so a later refresh can restore them. - New ControlService::FetchCredentials RPC. The coordinator validates that the query id belongs to a live query that references the table (pinning the query for the duration of the call), then runs the frontend round trip on a dedicated thread pool (--credential_fetch_threads) so a slow catalog cannot stall the service threads shared with ReportExecStatus; when that pool's queue is full the request is rejected (the backend retries at its next interval) rather than blocking a service thread. The credentials are returned as a Thrift sidecar. QueryState exposes coord_proxy() so executors reuse the existing coordinator link. Frontend: - TFetchCredentialsRequest/Response and JniFrontend.fetchCredentials() wrap Frontend.fetchCredentials(), which goes FeCatalog -> MetaProvider -> IcebergMetaProvider and issues a fresh REST loadTable to obtain the table's current credentials. MultiMetaProvider routes to the provider that owns the table, moving on to the next one whatever kind of exception a provider that does not own it throws. Failures propagate to the backend with their cause instead of being reported as an empty list. Tests: - test_iceberg_credential_vending adds two cases that set the refresh threshold above the token TTL so lookups take the refresh path: a scan of ice_s3.nation that checks a refresh was logged, and a scan of the 100-file ice_s3.many_files table that checks the refreshes are rate limited to a handful rather than one per file. Change-Id: I7fafc33bd78c2cdb19724a7f89536fdd7ad3c6d6 Assisted-by: Claude Fable 5.1 <[email protected]> --- M be/src/runtime/query-credentials.cc M be/src/runtime/query-credentials.h M be/src/runtime/query-state.h M be/src/service/control-service.cc M be/src/service/control-service.h M be/src/service/frontend.cc M be/src/service/frontend.h M common/protobuf/control_service.proto M common/thrift/Frontend.thrift M fe/src/main/java/org/apache/impala/catalog/FeCatalog.java M fe/src/main/java/org/apache/impala/catalog/local/IcebergMetaProvider.java M fe/src/main/java/org/apache/impala/catalog/local/LocalCatalog.java M fe/src/main/java/org/apache/impala/catalog/local/MetaProvider.java M fe/src/main/java/org/apache/impala/catalog/local/MetaProviderDecorator.java M fe/src/main/java/org/apache/impala/catalog/local/MultiMetaProvider.java M fe/src/main/java/org/apache/impala/service/Frontend.java M fe/src/main/java/org/apache/impala/service/JniFrontend.java M tests/custom_cluster/test_iceberg_credential_vending.py 18 files changed, 610 insertions(+), 25 deletions(-) git pull ssh://gerrit.cloudera.org:29418/Impala-ASF refs/changes/40/24840/5 -- To view, visit http://gerrit.cloudera.org:8080/24840 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: newchange Gerrit-Change-Id: I7fafc33bd78c2cdb19724a7f89536fdd7ad3c6d6 Gerrit-Change-Number: 24840 Gerrit-PatchSet: 5 Gerrit-Owner: Peter Rozsa <[email protected]>
