roryqi opened a new issue, #13545:
URL: https://github.com/apache/gravitino/issues/13545
### Describe the feature
Add tag-based row-filter and column-mask policies that Gravitino resolves
into
Iceberg REST `read-restrictions`.
Existing authorization continues to decide whether a subject may read a
table.
Read-restriction policies only reduce the visible rows or column values and
never grant access.
### Motivation
Gravitino can associate governance policies with tags, but it currently has
no
standard way to enforce fine-grained restrictions after table access is
granted.
The Iceberg REST read-restriction contract provides a standard enforcement
boundary using field-ID-based predicates and column-mask actions.
### Describe the solution
Define a design that:
- Adds typed `system_row_filter` and `system_column_mask` policy content.
- Selects policies through effective tags.
- Defines a restricted expression profile for row predicates and rule
conditions.
- Binds the authenticated subject, group membership, and table schema before
producing a response.
- Returns standard Iceberg row-filter expressions and column-mask actions.
- Detects conflicting effective policies and fails closed on resolution or
enforcement errors.
- Handles subject-dependent caching and ETags safely.
- Initially delivers the integration through an opt-in experimental module
and
reader package.
The design document will be submitted first. Implementation will be split
into
follow-up tasks.
### Additional context
Related work:
- Policy-on-tag design: #12177
- Apache Iceberg read-restrictions specification:
https://github.com/apache/iceberg/pull/13879
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]