feat: [branch-1.1] built-in S3 credential provider adapters for the native Parquet scan (#6023) - #6318
Merged
Conversation
… scan (apache#6023) * feat: built-in S3 credential provider adapters for the native Parquet scan * more comments addressed * address review comments * format (cherry picked from commit ce455f3)
comphead
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #6023 to
branch-1.1.Cherry-picked from
ce455f32d948355e073638e81009ecc3e5dea349without conflicts, and the diff is byte-identical to upstream. Every file it modifies is identical onbranch-1.1and onmainjust before #6023, with two exceptions. The two poms differ only by the 1.1.0 version. The S3 credential provider design doc onmainalso has #6106'sFileIOcache section, whichbranch-1.1does not; the two new sections land after the Iceberg property-bag section and do not refer to it.Which issue does this PR close?
Closes #6022 on
branch-1.1. #6023 already closed it onmain.Rationale for this change
#6023 merged after
branch-1.1was cut at 36ab57c, so without this 1.1.0 ships the failure in #6022. The native Parquet reader accepts only a fixed list of credential provider classes, so anfs.s3a.aws.credentials.providerthat plain Spark accepts, such ascom.amazonaws.auth.DefaultAWSCredentialsProviderChain, fails under Comet withUnsupported credential provider.The adapters are opt-in: nothing changes unless a user names one in
fs.s3a.comet.credential.provider.class. One part applies to any SPI provider named on the Parquet path, not only the adapters. Itsinitialize()now receives thefs.s3a.*config subset, static keys included, where 1.0 passed an empty map. The S3 credential providers guide documents this, and with this backport 1.1.0 is the first release that behaves this way.What changes are included in this PR?
The original change, so see #6023 for the details. No adaptations were needed. In short:
HadoopS3ACredentialProviderAdapterandAwsSdkCredentialProviderAdapterinorg.apache.comet.cloud.s3, each with an AWS SDK v1 body for Spark 3.4/3.5 and a v2 body for Spark 4.x.s3.rsforwards thefs.s3a.*subset to the SPI'sinitialize()on the Parquet path.hadoop-awsand the matching AWS SDK atprovidedscope, versioned per Spark profile, so nothing new is bundled. Spotless now also checks the Java files under thespark-*shim directories, which reformats three existing test files.How are these changes tested?
The original PR's tests, run locally on
branch-1.1with JDK 17:parquet::objectstore::s3tests pass, including the two new ones.cargo fmt --checkand workspace clippy with-D warningsare clean.org.apache.comet.cloud.s3: 40 pass on Spark 3.5 (SDK v1) and 47 on Spark 4.1 (SDK v2).CometPublicApiSuitepasses.HadoopS3ACredentialProviderAdapterBridgeSuite,CometS3CredentialBridgeSuiteandParquetReadFromS3Suitepass, 15 tests. On Spark 3.5, 14 of the 15 pass. The failure isCometS3CredentialBridgeSuite's REST catalog test, whose Iceberg write S3Proxy rejects with anx-amz-content-sha256mismatch, and it fails the same way onbranch-1.1without this PR.prettier --checkpasses on the three changed docs.Against
branch-1.1, the changed paths route this pull request to every suite except Spark 3.4's SQL job and the benchmark check.