ggershinsky opened a new issue, #18240: URL: https://github.com/apache/iceberg/issues/18240
### Feature Request / Improvement All encryption keys in a table, except for the master key, are wrapped (encrypted) by a parent key. Some security protocols require periodic re-wrapping with a fresh version of the parent keys. The period is typically long, one year or above. We need a procedure that generates new manifest file keys, and re-encrypts all active manifests with the new keys (so the data file keys are re-wrapped) - basically creating new manifest files. Then it generates new manifest list file keys, and re-encrypts all active manifest lists with the new keys - basically creating new manifest list files. Then it generates a fresh Key Encryption Key and uses it to encrypt the new manifest list file keys. The new Key Encryption Key is wrapped with a rotated master table key. For safety / fault-tolerance, the procedure can run only on the latest snapshot, so the older snapshots are available for recovery. However, it should be documented with clear instructions on when and how the old snapshots are retired, so no re-wrapped keys exist anymore. ### Query engine None ### Willingness to contribute - [ ] I can contribute this improvement/feature independently - [ ] I would be willing to contribute this improvement/feature with guidance from the Iceberg community - [ ] I cannot contribute this improvement/feature at this time -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
