Vend the default credentials
Resolve the tenant default endpoint and credentials, independent of any bucket.
Authorizations
The access token received from the authorization server in the OAuth 2.0 flow.
Response
The tenant default endpoint and credentials.
Resolved S3 connection details for one bucket, for runtime credential vending.
A registered bucket returns its own endpoint + credentials (source="bucket"); an
unregistered bucket falls back to the tenant default (source="default"). Region and
path-style are tenant-wide and come from the service S3 configuration in both cases.
Distinct from S3CredentialResponse (the per-user access-key CRUD model) — this is the
infra-facing endpoint+creds vend for the S3A credential provider / Gravitino.
The bucket the credentials apply to.
S3 endpoint URL for this bucket.
Whether path-style access is required for this endpoint.
S3 access key.
S3 secret key.
Where the credentials were resolved from: 'bucket' (override) or 'default'.
S3 region, if configured.
S3 session token for temporary credentials; null for static keys.

