mengna-lin opened a new pull request, #18210:
URL: https://github.com/apache/iceberg/pull/18210

   ## What
   
   Adds `AliyunKeyManagementClient`, an Alibaba Cloud KMS implementation of the 
`KeyManagementClient` SPI, so tables using Iceberg's envelope encryption can 
wrap/unwrap data keys with Aliyun KMS.
   
   ## Why
   
   The `aliyun` module previously supported only OSS; there was no way to use 
Iceberg client-side (envelope) encryption on Alibaba Cloud. 
   
   ## Changes
   
   - **`AliyunKeyManagementClient`** — `wrapKey` (Encrypt), `unwrapKey` 
(Decrypt), and server-side `generateKey` (GenerateDataKey); 
`supportsKeyGeneration()` returns true, matching `AwsKeyManagementClient`. 
Aliyun KMS returns the ciphertext blob as a Base64 string, which is carried as 
its UTF-8 bytes so `unwrapKey` can pass the same string back to Decrypt.
   - **`AliyunClientFactory#newKmsClient`** — builds the KMS client from 
`client.region` (the SDK resolves `kms.<region>.aliyuncs.com`, the same 
region-based model AWS uses) and resolves credentials from the access key / 
secret / security token, falling back to the credentials default chain (env 
vars, RRSA/OIDC, ECS RAM role) when no access key is set.
   - **`AliyunProperties`** — adds `client.region` (same key AWS uses) and 
`kms.data-key-spec` (default `AES_256`).
   - **Build** — adds `com.aliyun:kms20160120` as `compileOnly` and 
`mockito-core` to the aliyun test scope.
   - **Tests** — `TestAliyunKeyManagementClient` covers generate/wrap/unwrap 
mapping and key-generation support; `TestAliyunClientFactories` covers 
region-based endpoint resolution and the missing-region error.
   
   ## Configuration
   
   ```
   encryption.kms-impl = org.apache.iceberg.aliyun.AliyunKeyManagementClient
   client.region              = cn-hangzhou
   # credentials (optional): omit to use the default chain (env vars / 
RRSA-OIDC / ECS RAM role)
   client.access-key-id       = <access-key-id>
   client.access-key-secret   = <access-key-secret>
   client.security-token      = <sts-token>          # optional
   # optional tuning:
   kms.data-key-spec          = AES_256              # default (or AES_128)
   ```
   
   
   ## Testing
   
   `./gradlew :iceberg-aliyun:test --tests 
"org.apache.iceberg.aliyun.TestAliyunKeyManagementClient" --tests 
"org.apache.iceberg.aliyun.TestAliyunClientFactories"` — all pass (JDK 21).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to