Repository navigation
feat(encryption/kms): Add AWS KMS client - #3173
Open
zakariya-s wants to merge 12 commits into
Open
zakariya-s wants to merge 12 commits into
zakariya-s wants to merge 12 commits into
Conversation
xanderbailey
reviewed
Sep 8, 2026
xanderbailey
reviewed
Sep 8, 2026
Collaborator
Contributor
Author
It implements the same but the previous PR has been inactive for a few months now. This also addresses some of @xanderbailey's comments. |
zakariya-s
commented
Sep 9, 2026
Contributor
|
@zakariya-s Thanks for working on it, I'll review your PR. @mbutrovich Thanks for the reminder! |
Contributor
Author
|
Hey @hsiang-c @mbutrovich @CTTY could I get a review here when you have time please? Thanks |
Contributor
|
I’ll take a look here this evening! |
# Conflicts: # Cargo.lock # Cargo.toml # README.md
Contributor
Author
|
CI fails because we're creating a new |
- Follow Iceberg Java for configuration: honour `client.region` (with `region_name` as a lower-precedence alias) and parse all catalog properties through `iceberg_property_macro::Properties`. Glue-style property constants are now crate-private. - Reject `client.assume-role.arn` until assume-role support lands in a follow-up, instead of silently using different credentials than the catalog's S3 file IO. - Report AWS service errors by their modeled error, and transport errors by their full cause chain with the Encrypt plaintext redacted. Never attach the raw HTTP response, which can contain plaintext keys. - Validate `kms.endpoint` as an http(s) URI with a host when the client is created, and reject GenerateDataKey keys that do not match `kms.data-key-spec` and empty ciphertext blobs. - Skip SDK catalog properties entirely when an `SdkConfig` is injected. - Raise aws-sdk-kms to 1.123, which no longer pulls in h2 0.3 through test-util, and drop the RUSTSEC-2026-0258 audit exception. Set the aws-config floor to 1.9, the minimum compatible with aws-sdk-kms 1.123. - Move the AWS dev-dependencies to the workspace, drop the unused iceberg-catalog-rest dev-dependency, and use the memory catalog in the module example. - Isolate tests from the host AWS environment, cover the factory wiring of every property, and remove redundant and SDK-wording-dependent assertions.
zakariya-s
force-pushed
the
zstasa/aws-kms-cse
branch
from
October 7, 2026 14:57
e7806f6 to
a09c378
Compare
Test the assume-role and incomplete static-credential rejections through the factory, rename a test that no longer overrides anything, and clarify how catalog properties interact with an injected SdkConfig.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Which issue does this PR close?
KeyManagementClientfor AWS KMS #2466.What changes are included in this PR?
Adds a new
iceberg-kmscrate for Iceberg client-side encryption key management. Providers are behind feature flags, following the OpenDAL storage pattern. This PR adds AWS KMS behind theawsfeature.The KMS client is created once from the application-supplied catalog properties and shared across the catalog, matching the existing
KmsClientFactorylifecycle.Are these changes tested?
Yes.
The AWS SDK mock framework was also used to test AWS calls.
AI Disclosure
LLMs were used to assist, but the code has been validated by hand.