SS-471 Add support for vending (and refreshing) credentials for Iceberg catalogs backed by Azure Data Lake Storage (V2) - #38893
Conversation
QA LLM Review1. MEDIUM -- ADLS
|
martykulma
left a comment
There was a problem hiding this comment.
aside from the comment, the rest looks good! thanks @patrickwwbutler
…m loader when building Azdls OpenDalStorageFactory
56eab53 to
8e32108
Compare
…ot (#38700) ### Motivation The `:rust: cargo-fuzz` job has failed on every release-qualification run since 2026-08-28 (v26.40.0-rc.1) with `build FAILED for src/transform/fuzz`: `mz-storage-types` fails to compile with unresolved imports of `TokenProvider`, `OAuth2TokenProvider`, `RequestAuthenticator` and `BearerTokenAuthenticator` from `iceberg_catalog_rest`. Every release from v26.40 to v26.44 shipped without fuzz coverage. The fuzz crates build in their own workspace, `test/cargo-fuzz`, which carries a copy of the root's `[patch.crates-io]` table. Its three iceberg-rust entries were still pinned to the fork revision for 0.9.0 after #38471 moved the root to the 0.10.1 revision, and the root has moved the revision twice more since (#38733, #38893). A patch that no longer satisfies the version requirement is not an error to Cargo: it lands in `[[patch.unused]]` with a warning and the crate resolves from crates.io, which lacks the fork API that #38475 started using two seconds later. The `launchdarkly-server-sdk` patch in the same table had drifted the same way after the root dropped it in #37026. ### Description - `test/cargo-fuzz/Cargo.toml`: repin the three iceberg entries to the root's current revision, add the missing `chrono-tz` fork entry, and drop the stale LaunchDarkly patch. - `bin/lint-cargo` (run by CI's lint step): a new check that fails when the fuzz workspace's patch table carries an entry the root does not have, one that differs from the root's, or lacks a root entry. It fails on the pre-fix manifest naming all five drifted or missing entries, and passes after. It also caught the two later root bumps: rebased onto current main before the repin, it failed naming exactly the three iceberg entries. A missing entry gets no Cargo warning at all: the root's `chrono-tz` fork (#38735) was absent, so the fuzz targets reaching `mz-pgtz` built against crates.io's older tzdata, and the check now fails naming it on the previous manifest. Root entries outside the fuzz dependency graph (`duckdb`, `postgres_array`) are listed in the check as omitted. Alternatives considered: per-crate fuzz workspaces (more duplication), symlinking or generating the manifest (Cargo has no include mechanism; a generated file for a table that changes a few times a year is not worth the tooling), repinning without the lint (guarantees the same outage on the next root patch bump). ### Verification `cargo check` passes for `src/transform/fuzz` and for the whole `test/cargo-fuzz` workspace (17 crates), resolving iceberg and `chrono-tz` from the forks; `cargo metadata` shows zero `[[patch.unused]]` entries. `bin/lint-cargo` exits 1 on the old manifest and 0 on the new one; black, ruff and pyright are clean. Not run locally: the release build with sanitizer-coverage flags and `cargo fuzz build` itself. The errors were unresolved imports, which `cargo check` exercises fully; the release-qualification `cargo-fuzz` step is the end-to-end check. Closes: [QAR-200](https://linear.app/materializeinc/issue/QAR-200) 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Implements the
VendedCredentialtrait for the newly createdCustomAzdlsCredentialLoaderadded to the MZ iceberg-rust fork in MaterializeInc/iceberg-rust#9Then plugs in a
CustomAzdlsCredentialLoaderwith the previously createdVendedCredentialLoaderusing this trait implementation into theOpenDalStorageFactory::Azdlsconstructor, allowing opendal to call it for fresh vended credentials from the catalog.Tested manually in our Azure Databricks workspace, with optimistic plans to add CI testing later on.
Also closes SS-173