Skip to content

ARROW-15906: [C++][Python][R] By default, don't create or delete S3 buckets - #13206

Merged
pitrou merged 18 commits into
apache:masterfrom
wjones127:ARROW-15906-no-new-bucket
Jun 15, 2022
Merged

ARROW-15906: [C++][Python][R] By default, don't create or delete S3 buckets#13206
pitrou merged 18 commits into
apache:masterfrom
wjones127:ARROW-15906-no-new-bucket

Conversation

@wjones127

@wjones127wjones127 commented May 20, 2022

Copy link
Copy Markdown
Member

BREAKING CHANGE: modifies S3FileSystem to not allow creating or deleting buckets by default. Two new options are added: allow_bucket_creation, which enables creating buckets, and allow_bucket_deletion, which enables deleting buckets.

Outside of tests, most use cases will not want to create or delete buckets, and doing so accidentally is not desirable either. Buckets have governance controls like permissions and cost-tracking tags.

To make it easy for users to transition, the FromUri method also supports these arguments:

frompyarrow.fsimportFileSystemuri="s3://minioadmin:minioadmin@?scheme=http&endpoint_override=localhost%3A9000"fs, path=FileSystem.from_uri(uri)
fs.create_dir("test")
# Traceback (most recent call last):# File "<stdin>", line 1, in <module># File "pyarrow/_fs.pyx", line 463, in pyarrow._fs.FileSystem.create_dir# check_status(self.fs.CreateDir(directory, recursive=recursive))# File "pyarrow/error.pxi", line 115, in pyarrow.lib.check_status# raise IOError(message)# OSError: Bucket 'test' not found. To create buckets, enable the allow_bucket_creation option.uri=uri+"&allow_bucket_creation=True&allow_bucket_deletion=True"fs, path=FileSystem.from_uri(uri)
fs.create_dir("test")
fs.delete_dir("test")
fs<-FileSystem$from_uri("s3://minioadmin:minioadmin@?scheme=http&endpoint_override=localhost%3A9000")$fsfs$CreateDir("test")
#> Error: IOError: Bucket 'test' not found. To create buckets, enable the allow_bucket_creation option.fs<-FileSystem$from_uri(
paste0("s3://minioadmin:minioadmin@?scheme=http&endpoint_override=localhost%3A9000",
"&allow_bucket_creation=TRUE&allow_bucket_deletion=TRUE")
)$fsfs$CreateDir("test")
fs$DeleteDir("test")

@github-actions

Copy link
Copy Markdown

@wjones127wjones127 changed the title ARROW-15906: [C++][Python][R] By default, don't create or delete bucketsARROW-15906: [C++][Python][R] By default, don't create or delete S3 bucketsMay 20, 2022
@wjones127
wjones127 marked this pull request as ready for review May 20, 2022 22:12
Comment threadcpp/src/arrow/filesystem/s3fs.h Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you also update S3Options::FromUri() to support this?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good idea. I've added that.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's make it two options for flexibility (creation and deletion).

Also wrt. naming, should this be allow_bucket_creation? @lidavidm

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perhaps create_buckets and delete_buckets? That reads more consistently with background_writes to me. Or allow_creating_buckets

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I liked create_buckets but since there is a setter method and I want it named the same thing as the property (for clear error hints), I felt like allow_bucket_creation was the better choice.

@wjones127
wjones127force-pushed the ARROW-15906-no-new-bucket branch from 4409d3d to 06b10bfCompareMay 23, 2022 16:55
@wjones127
wjones127 requested a review from kouMay 24, 2022 17:06

@koukou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you send an e-mail to dev@ to confirm whether this default behavior change is acceptable? I can't decide this because I haven't used Apache Arrow to access S3 yet.

Comment threadcpp/src/arrow/filesystem/s3fs.h Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems that "deletion" depends on allow_create_buckets confuses users. How about renaming allow_create_buckets or create one more option?

BTW, why should we disable "deletion" by default?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We probably don't have to. Buckets can only be deleted if already empty, so hard to accidentally delete an important one I suppose.

@wjones127

Copy link
Copy Markdown
MemberAuthor

Could you send an e-mail to dev@ to confirm whether this default behavior change is acceptable? I can't decide this because I haven't used Apache Arrow to access S3 yet.

Sure, I've done that here: https://lists.apache.org/thread/2wnmq72trrtcxyvxzw261gq0t6grq18g

Comment threadpython/pyarrow/tests/test_dataset.py Outdated
Comment threadcpp/src/arrow/filesystem/s3fs.h Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's make it two options for flexibility (creation and deletion).

Also wrt. naming, should this be allow_bucket_creation? @lidavidm

Comment threadcpp/src/arrow/filesystem/s3fs.cc Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmm, I think we should be a bit stricter and not blindly interpret any other value as "false".
How about allowing the following values:

  • "0", "false" (case-insensitive) -> boolean false
  • "1", "true" (case-insensitive) -> boolean true
  • any other value -> raise Status::Invalid

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good. I didn't see any existing utility function to do this, so maybe I will create one.

Comment threadcpp/src/arrow/filesystem/s3fs.h Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These trivial setters are not needed as people can access the attributes directly.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

options() returns a const reference; they could access but I don't think they could mutate right?

Being able to change this setting later felt important when I didn't support in FromURI, but maybe it's not as important now.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These trivial setters are not needed as people can access the attributes directly.

I'm not so sure that's true. This fails:

auto options = fs_->options();
options.allow_bucket_creation = true;
options.allow_bucket_deletion = true;
ASSERT_EQ(fs_->options().allow_bucket_creation, true);
ASSERT_EQ(fs_->options().allow_bucket_deletion, true);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmm, this is not really supported, though. You should set options before creating the filesystem.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, I think I'm fine at this point with only allowing setting them during construction, since we've added them to the URI parsing.

Comment threadcpp/src/arrow/filesystem/s3fs.h Outdated
Comment threadpython/pyarrow/_s3fs.pyx Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should probably use the same docstring for constructor parameters and the associated properties.
Personally, I like "Whether to allow CreateDir at the bucket-level."

Comment threadpython/pyarrow/includes/libarrow_fs.pxd Outdated
Comment threadr/R/filesystem.R Outdated
@wjones127
wjones127force-pushed the ARROW-15906-no-new-bucket branch from 3703808 to b25cedfCompareJune 2, 2022 17:44
@wjones127
wjones127force-pushed the ARROW-15906-no-new-bucket branch from b25cedf to 02a1db0CompareJune 3, 2022 14:44
@wjones127
wjones127 requested a review from pitrouJune 3, 2022 19:46

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks a lot @wjones127 . Here are some more comments needing addressing.

Comment threadcpp/src/arrow/filesystem/s3fs.cc
Comment threadpython/pyarrow/_s3fs.pyx
allow_bucket_creation=True,
allow_bucket_deletion=True
)
fs.create_dir(bucket)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add tests in test_s3_options?

Comment threadpython/pyarrow/tests/test_fs.py Outdated
@pitrou

Copy link
Copy Markdown
Member

@thisisnic@dragosmg Can one of you perhaps review the R changes?

@dragosmg

Copy link
Copy Markdown
Contributor

LGTM, but I'd like the opinion of someone more experienced.

@thisisnicthisisnic left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Generally LGTM, just one small comment/suggestions on the R tests.

Comment on lines +193 to +205
test_that("CreateDir fails on bucket if allow_bucket_creation=False", {
now_tmp <- paste0(now, "-test-fail-delete")
fs$CreateDir(now_tmp)

expect_error(
limited_fs$CreateDir("should-fail"),
regexp = "Bucket does not exist"
)
expect_error(
limited_fs$DeleteDir(now_tmp),
regexp = "Would delete bucket"
)
})

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wonder if these tests might be better without the regexp parameter, given that the specific phrasing of them comes from the C++ layer, and we tend to avoid testing that component of the error message?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sure, I'll rewrite it so these messages are tested in C++ instead.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @wjones127 !

@pitrou
pitrou merged commit c72f84a into apache:masterJun 15, 2022
@wjones127
wjones127 deleted the ARROW-15906-no-new-bucket branch June 15, 2022 10:10
kou pushed a commit that referenced this pull request Feb 20, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@wjones127@pitrou@dragosmg@kou@lidavidm@jorisvandenbossche@thisisnic