Skip to content

Add tests for PBE and Hadoop JCEKS global S3 credentials - #30798

Open
niteshy wants to merge 1 commit into
trinodb:masterfrom
niteshy:feature/s3-keystore-global-credentials
Open

Add tests for PBE and Hadoop JCEKS global S3 credentials#30798
niteshy wants to merge 1 commit into
trinodb:masterfrom
niteshy:feature/s3-keystore-global-credentials

Conversation

@niteshy

@niteshy niteshy commented Aug 19, 2026

Copy link
Copy Markdown

Description

Test-only change covering both JCEKS entry layouts for global fs.s3a.access.key and fs.s3a.secret.key aliases:

  • PBE JCEKS (SecretKeyEntry via PBEKeySpec): unit tests for KeystoreSecretProvider and SecretsResolver, plus Hive DML product tests against MinIO with keystore-backed catalog credentials. Compatible with Trino's bundled Airlift 444.

  • Hadoop-format JCEKS (SecretKeySpec via CredentialProviderFactory setKeyEntry): unit test via KeyStoreTestFixture.createHadoopKeyStore, validated with secrets-keystore-plugin 445-SNAPSHOT (test scope only).

Production Hadoop-format keystores require enhanced reader support in airlift/airlift#2100 and a subsequent Trino Airlift version bump — not a merge blocker for this test-only PR.

Additional context and related issues

Thanks for feedback by @dain @electrum in #30638 (comment). Added this airlift/airlift#2100 in Airlift. This PR is the follow-up to the discussion on #30638

Release notes

(x) This is not user-visible or is docs only, and no release notes are required.
( ) Release notes are required. Please propose a release note for me.
( ) Release notes are required, with the following suggested text:

Test-only change covering both JCEKS entry layouts for global
fs.s3a.access.key and fs.s3a.secret.key aliases:

- PBE JCEKS (SecretKeyEntry via PBEKeySpec): unit tests for
  KeystoreSecretProvider and SecretsResolver, plus Hive DML product
  tests against MinIO with keystore-backed catalog credentials.
  Compatible with Trino's bundled Airlift 444.

- Hadoop-format JCEKS (SecretKeySpec via CredentialProviderFactory
  setKeyEntry): unit test via KeyStoreTestFixture.createHadoopKeyStore,
  validated with secrets-keystore-plugin 445-SNAPSHOT (test scope only).

Production Hadoop-format keystores require enhanced reader support in
airlift/airlift#2100 and a subsequent Trino Airlift version bump — not
a merge blocker for this test-only PR.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

1 participant