sollhui opened a new pull request, #68540:
URL: https://github.com/apache/doris/pull/68540

   ### What problem does this PR solve?
   
   Problem Summary:
   
   GCS access currently depends on HMAC credentials or unsigned requests. A 
deployment using Application Default Credentials or a Compute Engine service 
account cannot consistently use the same identity for object reads and writes, 
Iceberg metadata operations, storage vaults, and backend error-log downloads.
   
   Add native GCP OAuth authentication across FE, BE, and Cloud using 
`gs.credential_provider_type=DEFAULT` or `COMPUTE_ENGINE`, with optional 
`gs.impersonation_service_account`. GCP storage without explicit authentication 
defaults to Application Default Credentials. Public-bucket access requires 
explicit `ANONYMOUS`; existing HMAC configuration remains supported. Reject 
conflicting native, HMAC, and AWS-only authentication properties before 
creating clients.
   
   The implementation follows the current master architecture:
   
   - Keep credential resolution in the filesystem API, OAuth client 
construction in the GCS plugin, and Iceberg client integration in the Iceberg 
connector. Use the native Hadoop GCS connector for namespace operations and 
bearer-authenticated S3 XML clients for object operations.
   - Carry typed credentials through additive Thrift and Protobuf fields, Cloud 
object information, and the shared C++ S3 client factory. Preserve AWS 
authentication, client caching, and rate limiting.
   - Normalize GCS aliases for resources, serialize resource ALTER operations, 
and validate effective properties before publication. Preserve omitted vault 
credential fields during partial ALTER, support clearing impersonation 
explicitly, and reject anonymous storage vaults. Apply vault changes to 
candidate metadata so a failed update does not persist a partial rename.
   - Support `gs://` in EXPORT and OUTFILE while preserving HTTP paths. 
Generate backend GCS V4 error-log URLs through IAM `signBlob`, falling back to 
the local error-log path if signing fails.
   - Add unit coverage and IAM regression suites for catalogs, TVFs, load, 
export, outfile, backup/restore, resources, vaults, property validation, and 
anonymous access. Export tests read back the written data and isolate cleanup 
by run directory.
   
   Example native authentication properties:
   
   ```properties
   provider=GCP
   gs.credential_provider_type=DEFAULT
   gs.impersonation_service_account=tar...@project.iam.gserviceaccount.com
   ```
   
   The impersonation property is optional. Use `COMPUTE_ENGINE` to select the 
attached VM identity explicitly, or `ANONYMOUS` for public object access.
   
   Compatibility and deployment:
   
   - Existing AWS/HMAC protocol fields and authentication paths remain 
available. Native GCP credentials require updated consumers; upgrade 
MetaService and the relevant FE/BE processes before enabling the feature during 
a rolling upgrade.
   - Package google-cloud-cpp OAuth libraries for BE/Cloud and the shaded 
Hadoop GCS connector for FE/Iceberg.
   - FE presigned uploads with native OAuth remain unsupported and fail 
explicitly. Backend error-log downloads use the dedicated GCS V4 signing path.
   - Native OAuth uses the existing configurable object-store endpoint, so this 
remains an outbound-request/SSRF surface. Catalog creation requires catalog 
CREATE privilege; vault creation requires global ADMIN privilege. Google token 
and signing operations use the credential library and Google IAM APIs. No 
remote code-loading path is introduced.
   
   ### Release note
   
   Add native GCP IAM authentication with Application Default Credentials, 
Compute Engine identities, and optional service-account impersonation for 
GCS-backed storage. GCP configurations without HMAC or an explicit 
authentication mode now use ADC; public access must select `ANONYMOUS`. Improve 
resource/vault credential updates and support GCS error-log signing.
   
   ### Validation
   
   Passed locally:
   
   - GCS filesystem reactor unit tests, including 88 filesystem API tests, 152 
S3-base tests, and 36 GCS tests; zero failures, errors, or skips in these 
modules.
   - FE Core and Iceberg Checkstyle, plus the GCS reactor's style checks.
   - clang-format 16 checks for all 33 changed C++ files, BE build hygiene, 
connector import boundaries, and FE metadata-funnel checks.
   - Parsing of all 41 changed Java files; Protobuf descriptor generation and 
Thrift C++ generation for the changed definitions.
   - `git diff --check`.
   
   Not completed locally:
   
   - Full FE unit tests: the standard runner requires JDK 17; the available 
test runtime is JDK 20.
   - Iceberg reactor tests: generation stops because the installed Thrift 
compiler is 0.16.0 while master requires 0.24.0. The standalone Thrift syntax 
check above does not replace this build.
   - BE/Cloud compilation, unit tests, and clang-tidy: the installed thirdparty 
bundle lacks the required google-cloud-cpp libraries.
   - Live IAM regression suites: no configured Doris cluster or GCP test 
environment was available.
   
   ### Check List (For Author)
   
   - Test:
     - [x] Unit tests added; filesystem API/S3/GCS tests executed successfully.
     - [x] Regression tests added.
     - [ ] Full FE, Iceberg, BE/Cloud, and live IAM tests completed.
   - Behavior changed:
     - [x] Yes: native GCP authentication, ADC default, explicit anonymous 
mode, and validated partial credential updates as described above.
   - Does this need documentation?
     - [x] Yes: document credential properties, ADC deployment, impersonation 
permissions, explicit anonymous access, and upgrade requirements.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to