Vend credentials for a bucket
Resolve the endpoint and credentials for a bucket.
A registered bucket returns its own endpoint and credentials; an unregistered bucket transparently falls back to the tenant default. Intended for infrastructure consumers (the S3A credential provider, Gravitino) authenticating with the platform PSK.
Authorizations
The access token received from the authorization server in the OAuth 2.0 flow.
Path Parameters
The bucket to vend credentials for; unregistered buckets fall back to the tenant default.
Response
Resolved endpoint and credentials for the bucket.
Resolved S3 connection details for one bucket, for runtime credential vending.
A registered bucket returns its own endpoint + credentials (source="bucket"); an
unregistered bucket falls back to the tenant default (source="default"). Region and
path-style are tenant-wide and come from the service S3 configuration in both cases.
Distinct from S3CredentialResponse (the per-user access-key CRUD model) — this is the
infra-facing endpoint+creds vend for the S3A credential provider / Gravitino.
The bucket the credentials apply to.
S3 endpoint URL for this bucket.
Whether path-style access is required for this endpoint.
S3 access key.
S3 secret key.
Where the credentials were resolved from: 'bucket' (override) or 'default'.
S3 region, if configured.
S3 session token for temporary credentials; null for static keys.

