Skip to content

feat(encryption/kms): Add AWS KMS client - #3173

Open
zakariya-s wants to merge 12 commits into
apache:mainfrom
zakariya-s:zstasa/aws-kms-cse
Open

zakariya-s wants to merge 12 commits into
apache:mainfrom
zakariya-s:zstasa/aws-kms-cse

Conversation

@zakariya-s

@zakariya-s zakariya-s commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Which issue does this PR close?

What changes are included in this PR?

Adds a new iceberg-kms crate for Iceberg client-side encryption key management. Providers are behind feature flags, following the OpenDAL storage pattern. This PR adds AWS KMS behind the aws feature.

The KMS client is created once from the application-supplied catalog properties and shared across the catalog, matching the existing KmsClientFactory lifecycle.

Are these changes tested?

Yes.

The AWS SDK mock framework was also used to test AWS calls.

AI Disclosure

LLMs were used to assist, but the code has been validated by hand.

Comment thread crates/kms/aws/src/config.rs Outdated
Comment thread crates/kms/src/aws/client.rs
@mbutrovich

mbutrovich commented Sep 8, 2026 •

Copy link
Copy Markdown
Collaborator

How does this compare to #2466?

cc @hsiang-c

@zakariya-s

Copy link
Copy Markdown
Contributor Author

How does this compare to #2466?

cc @hsiang-c

It implements the same but the previous PR has been inactive for a few months now. This also addresses some of @xanderbailey's comments.

Comment thread crates/kms/Cargo.toml
@hsiang-c

hsiang-c commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

@zakariya-s Thanks for working on it, I'll review your PR.

@mbutrovich Thanks for the reminder!

@zakariya-s

Copy link
Copy Markdown
Contributor Author

Hey @hsiang-c @mbutrovich @CTTY could I get a review here when you have time please? Thanks

@xanderbailey

Copy link
Copy Markdown
Contributor

I’ll take a look here this evening!

@zakariya-s

Copy link
Copy Markdown
Contributor Author

CI fails because we're creating a new iceberg-kms crate

- Follow Iceberg Java for configuration: honour `client.region` (with
  `region_name` as a lower-precedence alias) and parse all catalog
  properties through `iceberg_property_macro::Properties`. Glue-style
  property constants are now crate-private.
- Reject `client.assume-role.arn` until assume-role support lands in a
  follow-up, instead of silently using different credentials than the
  catalog's S3 file IO.
- Report AWS service errors by their modeled error, and transport errors
  by their full cause chain with the Encrypt plaintext redacted. Never
  attach the raw HTTP response, which can contain plaintext keys.
- Validate `kms.endpoint` as an http(s) URI with a host when the client is
  created, and reject GenerateDataKey keys that do not match
  `kms.data-key-spec` and empty ciphertext blobs.
- Skip SDK catalog properties entirely when an `SdkConfig` is injected.
- Raise aws-sdk-kms to 1.123, which no longer pulls in h2 0.3 through
  test-util, and drop the RUSTSEC-2026-0258 audit exception. Set the
  aws-config floor to 1.9, the minimum compatible with aws-sdk-kms 1.123.
- Move the AWS dev-dependencies to the workspace, drop the unused
  iceberg-catalog-rest dev-dependency, and use the memory catalog in the
  module example.
- Isolate tests from the host AWS environment, cover the factory wiring
  of every property, and remove redundant and SDK-wording-dependent
  assertions.
Test the assume-role and incomplete static-credential rejections through
the factory, rename a test that no longer overrides anything, and
clarify how catalog properties interact with an injected SdkConfig.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants