laserninja opened a new issue, #13577:
URL: https://github.com/apache/gravitino/issues/13577

   ### What would you like to be improved?
   
   Make connecting Polaris and Unity Catalog deployments through Gravitino's 
existing Iceberg REST backend a tested, documented workflow with clear 
operation capabilities and authorization boundaries.
   
   Federation already exists, including the merged wrapper and 
credential-handling work in [PR 
#11367](https://github.com/apache/gravitino/pull/11367). An earlier Polaris/HMS 
integration attempt, [PR 
#11789](https://github.com/apache/gravitino/pull/11789), closed without 
merging. This proposal builds on those efforts rather than introducing another 
federation abstraction.
   
   Operators need to know which remote operations, identity models, and 
credential flows are supported before enabling a connection.
   
   ### How should we improve?
   
   - Provide versioned, tested connection profiles for Polaris and supported 
Unity Catalog endpoints. Distinguish open-source Unity Catalog from Databricks 
Unity Catalog.
   - Publish a compatibility matrix for namespace/table operations, views, 
reads/writes, and credential delegation. Mark unsupported and unverified 
capabilities explicitly.
   - Validate service-identity versus caller-identity behavior, token refresh, 
credential scope, and which system authorizes each operation.
   - Add connection and authorization diagnostics that avoid exposing 
credentials. Document policy limitations rather than implying unsupported 
policy translation or enforcement.
   - Provide reproducible Spark or Trino examples and integration tests for 
supported operations, expired credentials, and denied access.
   
   Acceptance should demonstrate one end-to-end engine path per supported 
service profile, preserve remote access restrictions, and provide a 
reproducible compatibility report. Keep live-service checks opt-in where 
external infrastructure is required.
   
   Reuse the [existing REST 
backend](https://github.com/apache/gravitino/blob/main/docs/iceberg-rest-service.md#rest-backend-configuration).
 Cross-organization sharing and redesigning external asset identity are 
separate workstreams; the latter is discussed in 
[#13476](https://github.com/apache/gravitino/discussions/13476).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to