Skip to content

SS-453 Azdls custom creds - #9

Merged
patrickwwbutler merged 8 commits into
mz_v0.10.xfrom
azdls-custom-creds
Sep 16, 2026
Merged

patrickwwbutler merged 8 commits into
mz_v0.10.xfrom
azdls-custom-creds

Conversation

@patrickwwbutler

Copy link
Copy Markdown

Closes SS-453 by adding support for a custom credential loader to OpenDalStorage::Azdls, which attaches a custom credential loader to the credential chain in the storage operator.

Also bumps opendal crate version to 0.59 to get the recently added support for a credential chain in the AzdlsBuilder.

This will then be followed up in materialize by implementing VendedCredential for AzdlsCredential and building a VendedCredentialLoader<AzdlsCredential> and plugging it into the OpenDalStorageBuilder.

patrickwwbutler and others added 3 commits September 10, 2026 16:38
Needed so that the ADLS backend can accept a custom credential provider:
`AzdlsBuilder::credential_provider_chain` landed in opendal-service-azdls
0.59.1, and 0.57 offers no way to reach the signer.

Note that ADLS *replaces* the provider chain, the way S3 does, rather than
prepending to it the way GCS does, so an ADLS loader needs no equivalent of
`suppress_default_credential_sources`.

Two breaking changes come with the bump:

  * `Operator::new`/`from_config` return the operator directly, so the
    trailing `.finish()` is gone from all seven construction sites.

  * The HTTP transport is opt-in as of 0.59 (opendal RFC 7749). Without one,
    every request to an HTTP-backed service fails at call time with
    `ConfigInvalid` rather than failing to build, which showed up as the Glue
    schema-update tests failing to write table metadata. The workspace now
    enables `http-transport-reqwest` and `create_operator` installs the
    default transport behind a `Once`, rather than relying on opendal's
    pre-`main` constructor, which its own documentation warns linkers may drop
    when opendal is linked as a `staticlib` for the Python bindings.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@linear-code

linear-code Bot commented Sep 10, 2026

Copy link
Copy Markdown

SS-453

@martykulma martykulma left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's a doc string that could use an update, and may want to updated DEPENDENCIES.rust.tsv, but otherwise lgtm. Thanks @patrickwwbutler!

Comment thread crates/storage/opendal/src/lib.rs
smaheshwar-pltr and others added 2 commits September 16, 2026 14:06
Docker Hub no longer serves the MinIO server and client repositories, preventing integration test containers from starting. Use the corresponding Quay images with the existing release tags.

Generated-by: Codex

Co-authored-by: Kevin Liu <kevinjqliu@users.noreply.github.com>
@patrickwwbutler
patrickwwbutler merged commit 9e252ad into mz_v0.10.x Sep 16, 2026
20 checks passed
patrickwwbutler added a commit to MaterializeInc/materialize that referenced this pull request Sep 16, 2026
…rg catalogs backed by Azure Data Lake Storage (V2) (#38893)

Implements the `VendedCredential` trait for the newly created
`CustomAzdlsCredentialLoader` added to the MZ iceberg-rust fork in
MaterializeInc/iceberg-rust#9

Then plugs in a `CustomAzdlsCredentialLoader` with the previously
created `VendedCredentialLoader` using this trait implementation into
the `OpenDalStorageFactory::Azdls` constructor, allowing opendal to call
it for fresh vended credentials from the catalog.

Tested manually in our Azure Databricks workspace, with optimistic plans
to add CI testing later on.

Also closes [SS-173](https://linear.app/materializeinc/issue/SS-173)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants