Skip to content

Antalya 26.8: Cache vended credentials for REST catalogs - #2382

Open
zvonand wants to merge 3 commits into
antalya-26.8from
feature/antalya-26.8/ClickHouse-ClickHouse-pr-107960
Open

zvonand wants to merge 3 commits into
antalya-26.8from
feature/antalya-26.8/ClickHouse-ClickHouse-pr-107960

Conversation

@zvonand

@zvonand zvonand commented Sep 15, 2026

Copy link
Copy Markdown
Member

Changelog category (leave one):

  • Improvement

Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):

Add option to cache vended credentials for REST catalogs; add a setting vended_credentials_cache_ttl (seconds). 300 by default. 0 means no caching.


Workflow [PR]
Sync PR [sync-upstream/pr/107960] (ClickHouse#107960 by @zvonand).

Cherry-picked from ClickHouse#107960.


Now, new vended credentials are requested on each metadata request. This PR adds an (optional) cache for creds with configurable TTL.

@zvonand zvonand added releasy Created/managed by RelEasy antalya-26.8 Session label (releasy session config) ai-resolved Port conflict auto-resolved by Claude labels Sep 15, 2026
@zvonand zvonand mentioned this pull request Sep 15, 2026
20 of 33 tasks
@github-actions

github-actions Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Workflow [PR], commit [bc73262]

Cherry-pick of ClickHouse#107960

Add an optional cache for vended credentials of REST data lake catalogs,
controlled by the new `DataLakeCatalog` database setting
`vended_credentials_cache_ttl` (seconds, default `300`, `0` disables caching).
Azure read/write buffers, listing, delete paths and metadata probes refresh
credentials through the catalog callback once on an authentication error.

Adapted to antalya-26.8:
* `ICatalog::getCredentialsConfigurationCallback` has no `table_metadata`
  parameter here: `RestCatalog` checks the table identity against
  `storage_id.uuid`, and `UnityCatalog` picks Azure or S3 credentials by the
  content of the credentials response.
* `UnityV2Catalog` does not exist here, so its hunk is skipped.
* `ReadBufferFromAzureBlobStorage` keeps the existing `blob_client` member
  instead of the upstream lazy `getBlobClient` accessor; `checkReturnedRange`
  does not exist here.
* `AzureObjectStorage` keeps plain `connection_params` and `auth_method`; there
  is no `cloneImpl` or `successful_objects` out-parameter here.
@zvonand
zvonand force-pushed the feature/antalya-26.8/ClickHouse-ClickHouse-pr-107960 branch from f04e570 to 6c6ec46 Compare September 28, 2026 09:42
`getDecimalScale` was only reachable through `Functions/identity.h` ->
`DataTypes/Native.h`, which is included under `USE_EMBEDDED_COMPILER`.
The embedded compiler is disabled in MSan builds, so the build failed with
"use of undeclared identifier 'getDecimalScale'".

CI report: https://altinity-build-artifacts.s3.amazonaws.com/PRs/2382/6c6ec46d270461947cbba184d9d96e154004f97f/build_amd_msan/build_clickhouse/build_clickhouse.log
PR: #2382

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-resolved Port conflict auto-resolved by Claude antalya antalya-26.8 Session label (releasy session config) releasy Created/managed by RelEasy

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants