pyarrow.parquet.encryption.DecryptionConfiguration#

class pyarrow.parquet.encryption.DecryptionConfiguration(cache_lifetime=None, *, read_kms_url=None)#

Bases: _Weakrefable

Configuration of the decryption, such as cache timeout.

__init__(*args, **kwargs)#

Methods

__init__(*args, **kwargs)

Attributes

cache_lifetime

Lifetime of cached entities (key encryption keys, local wrapping keys, KMS client objects).

read_kms_url

Whether the KMS instance URL may be read from Parquet key material when it is not configured in the KmsConnectionConfig.

cache_lifetime#

Lifetime of cached entities (key encryption keys, local wrapping keys, KMS client objects).

read_kms_url#

Whether the KMS instance URL may be read from Parquet key material when it is not configured in the KmsConnectionConfig.

This should only be enabled when the KMS implementation validates the URL it receives, to ensure a KMS access token isn’t sent to a malicious URL.