Aleksandr Savonin created FLINK-40855:
-----------------------------------------
Summary: Shut down AWS SDK v1 STS clients after S3
delegation-token acquisition
Key: FLINK-40855
URL: https://issues.apache.org/jira/browse/FLINK-40855
Project: Flink
Issue Type: Bug
Components: FileSystems
Reporter: Aleksandr Savonin
AbstractS3DelegationTokenProvider.obtainDelegationTokens() creates an AWS SDK
v1 STS client on each invocation but never explicitly shuts it down.
Both the Hadoop and Presto S3 delegation-token providers inherit this behavior.
Consequently, client resources can remain allocated beyond the acquisition
operation, including after failures.
The SDK has a finalizer-based cleanup path, but relying on its timing causes
unnecessary resource retention.
I discovered this independently while working on the DPAT delegation-token
[https://cwiki.apache.org/confluence/spaces/FLINK/pages/430408507/FLIP-588+Support+per-job+delegation+tokens].
PR #27026 also addresses STS cleanup as part of a broader Hadoop/AWS SDK
migration. This issue isolates the cleanup fix for the existing SDK v1
implementation so it can be reviewed and considered for backporting
independently of that migration.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)