Repository navigation
feat(io): refresh vended storage credentials before they expire - #892
Open
plusplusjiajia wants to merge 3 commits into
Open
plusplusjiajia wants to merge 3 commits into
plusplusjiajia wants to merge 3 commits into
Conversation
plusplusjiajia
force-pushed
the
feat-vended-credential-refresh
branch
4 times, most recently
from
August 21, 2026 15:56
d92ef4d to
7088aed
Compare
Member
|
Thanks for adding this feature! I think it is too large to review which may incur a long delay. Perhaps let's split it into smaller ones so we can review it one by one? |
Member
Author
@wgtmac Thanks — split into a stack, smallest first:
Each builds and passes the full suite standalone; the diff here narrows as each one merges. |
plusplusjiajia
marked this pull request as draft
August 24, 2026 09:56
plusplusjiajia
force-pushed
the
feat-vended-credential-refresh
branch
from
August 24, 2026 10:49
7088aed to
b06186d
Compare
plusplusjiajia
force-pushed
the
feat-vended-credential-refresh
branch
2 times, most recently
from
September 15, 2026 06:37
afe009b to
c15c6e3
Compare
Member
|
Is this ready for review? |
plusplusjiajia
force-pushed
the
feat-vended-credential-refresh
branch
from
September 26, 2026 05:53
c15c6e3 to
27d9bab
Compare
plusplusjiajia
force-pushed
the
feat-vended-credential-refresh
branch
from
September 29, 2026 04:19
27d9bab to
bf50711
Compare
Member
Author
Adapt the refresh policy to the provider API merged in apache#899. Install initial credentials and the provider together, and keep the provider across later credential updates. Migrate the refresh tests and cover failed initialization and the REST-to-S3 refresh path with real object storage. AI-Model: gpt-6 AI-Contributed/Feature: 40/40 AI-Contributed/UT: 248/248
plusplusjiajia
force-pushed
the
feat-vended-credential-refresh
branch
from
October 9, 2026 05:29
f0f0f83 to
a1cf5ef
Compare
plusplusjiajia
marked this pull request as ready for review
October 9, 2026 05:29
Member
Author
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Vended storage credentials expire, so new file operations on a reused table can eventually fail.
ArrowS3FileIOnow refreshes them on demand, starting five minutes before the earliest applicables3.session-token-expires-at-ms.Builds on the
StorageCredentialProviderAPI merged in #899:InitializeStorageCredentials()installs the initial credentials and provider before first use. LaterSetStorageCredentials()calls retain the provider.StorageCredentialProvider::Load()when refresh is due. REST fetching stays in the REST provider; no background thread is added.Tests cover refresh timing, concurrency, failed replacements, and provider initialization, including a real S3 read/write round trip through REST FileIO and ResolvingFileIO.