nastra commented on code in PR #14065:
URL: https://github.com/apache/iceberg/pull/14065#discussion_r2367010137


##########
docs/docs/configuration.md:
##########
@@ -143,6 +143,23 @@ The properties can be manually constructed or passed in 
from a compute engine li
 Spark uses its session properties as catalog properties, see more details in 
the [Spark configuration](spark-configuration.md#catalog-configuration) section.
 Flink passes in catalog properties through `CREATE CATALOG` statement, see 
more details in the [Flink](flink.md#adding-catalogs) section.
 
+### Catalog REST auth properties
+
+The following catalog properties configure authentication for the REST catalog.
+They support Basic, OAuth2, SigV4, and Google authentication, in addition to 
the default none.
+
+| Property                          | Default            | Description         
                                                                                
                                              |
+| --------------------------------- | ------------------ 
|---------------------------------------------------------------------------------------------------------------------------------------------------|
+| rest.auth.type                    | none               | Authentication 
mechanism for REST catalog access. Supported values: `none`, `basic`, `oauth2`, 
`sigv4`, `google`.                                  |
+| rest.auth.basic.username          | null               | Username for Basic 
authentication. Required if `rest.auth.type` = `basic`.                         
                                               |
+| rest.auth.basic.password          | null               | Password for Basic 
authentication. Required if `rest.auth.type` is `basic`.                        
                                               |
+| rest.auth.credential              | null               | Credential string 
(client_id:client_secret) exchanged for a token in the OAuth2 
client-credentials flow. Required if `rest.auth.type` = `oauth2`. |
+| rest.auth.oauth2-server-uri       | null               | OAuth2 token 
endpoint URI. Required if the REST catalog is not the OAuth2 authentication 
server. Required if `rest.auth.type` = `oauth2`.         |
+| rest.auth.token-expires-in-ms     | 3600000 (1 hour)   | Time in 
milliseconds after which a bearer token is considered expired. Used to decide 
when to refresh or re-exchange a token.                     |

Review Comment:
   these don't have a `rest.auth` prefix. See also 
https://github.com/apache/iceberg/blob/af82d34e78d82690892127d46b7f2937b29f362f/core/src/main/java/org/apache/iceberg/rest/auth/OAuth2Properties.java#L37-L68



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to