roryqi opened a new issue, #13545:
URL: https://github.com/apache/gravitino/issues/13545

   ### Describe the feature
   
   Add tag-based row-filter and column-mask policies that Gravitino resolves 
into
   Iceberg REST `read-restrictions`.
   
   Existing authorization continues to decide whether a subject may read a 
table.
   Read-restriction policies only reduce the visible rows or column values and
   never grant access.
   
   ### Motivation
   
   Gravitino can associate governance policies with tags, but it currently has 
no
   standard way to enforce fine-grained restrictions after table access is
   granted.
   
   The Iceberg REST read-restriction contract provides a standard enforcement
   boundary using field-ID-based predicates and column-mask actions.
   
   ### Describe the solution
   
   Define a design that:
   
   - Adds typed `system_row_filter` and `system_column_mask` policy content.
   - Selects policies through effective tags.
   - Defines a restricted expression profile for row predicates and rule
     conditions.
   - Binds the authenticated subject, group membership, and table schema before
     producing a response.
   - Returns standard Iceberg row-filter expressions and column-mask actions.
   - Detects conflicting effective policies and fails closed on resolution or
     enforcement errors.
   - Handles subject-dependent caching and ETags safely.
   - Initially delivers the integration through an opt-in experimental module 
and
     reader package.
   
   The design document will be submitted first. Implementation will be split 
into
   follow-up tasks.
   
   ### Additional context
   
   Related work:
   
   - Policy-on-tag design: #12177
   - Apache Iceberg read-restrictions specification:
     https://github.com/apache/iceberg/pull/13879


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to