Open Source · Iceberg Catalog

Pangolin: an Apache Iceberg REST catalog in Rust

Multi-tenant, with Git-style branches over catalog state. Pre-1.0, published as 0.8.0.

Pangolin is an open-source catalog for Apache Iceberg tables, written in Rust. It implements the Iceberg REST specification, so PyIceberg, Spark and other Iceberg clients can point at it directly, and it adds multi-tenancy, branches and merges, RBAC, credential vending and a management UI around that protocol. The latest release is 0.8.0, tagged on August 11, 2026. The project calls it beta and pre-1.0.

Install

The server ships as a container image. The Python SDK, PyPangolin, is on PyPI.

docker pull alexmerced/pangolin-api:0.8.0
pip install pypangolin

To build from source you need Rust 1.94 or later:

git clone https://github.com/AlexMercedCoder/Pangolin.git
cd Pangolin/pangolin
cargo run --bin pangolin_api

Since 0.6.0 the server refuses to start without PANGOLIN_JWT_SECRET. For a throwaway local instance, PANGOLIN_DEV_MODE=true generates an ephemeral secret instead. PANGOLIN_NO_AUTH=true only starts on a loopback bind address. The getting started guide covers configuration and the metadata backends.

What it is

A catalog tells a query engine which tables exist and where their metadata lives, and it arbitrates commits when several writers touch the same table. Pangolin does that over the Iceberg REST protocol and adds the pieces an operator wants around it:

  • Multi-tenancy, with tenant-scoped namespaces and warehouses.
  • Git-style branches, tags and 3-way merges over catalog state.
  • Credential vending for AWS STS, Azure SAS and GCP downscoped credentials.
  • RBAC, service users and API keys for pipelines and CI.
  • OpenID Connect with PKCE and id_token validation through JWKS, for providers that support it.
  • Warehouse credentials encrypted at rest with AES-256-GCM when PANGOLIN_ENCRYPTION_KEY is set.
  • Audit logging across more than 40 actions and 19 resource types.
  • Metadata backends: PostgreSQL (recommended), SQLite, MongoDB or in-memory.
  • Federated catalogs that proxy an external Iceberg REST catalog.
  • A SvelteKit management UI, two CLIs (pangolin-admin and pangolin-user), a Helm chart, and PyPangolin.

Status

Beta, pre-1.0. The repository README labels the project beta, and STATUS.md is its reconciled record of what is done. It reports 448 tests across 65 test targets and 18 CI jobs, run against live PostgreSQL, MongoDB and MinIO.

By its own maturity table, the Iceberg REST core (namespaces, tables, commits) and multi-tenant isolation are solid, PostgreSQL is the recommended backend, and the MongoDB backend is still beta. What remains open, in the order it would block a production deployment:

  • GitHub logins cannot be OIDC-validated, because GitHub issues no id_token. PANGOLIN_OIDC_REQUIRE=true refuses providers that cannot be validated.
  • Running more than one replica is constrained and unproven. OAuth needs session affinity, rate limits are per replica, and it has not been load tested.
  • commitTransaction is absent on purpose, because there is no cross-table transaction behind it.
  • Token revocation fails open if the revocation check itself errors.
  • Smaller gaps: no tamper-evident audit trail, HS256 JWTs without rotation, no MFA or account lockout, no point-in-time recovery, and replaceView and renameView are not implemented.

0.6.0 and later are security releases. Anything older should be upgraded and its tokens rotated.

Changelog

From the project's CHANGELOG.md and its git tags. Since 0.6.0 the server, both CLIs, the Python SDK, the UI and the Helm chart carry one version number.

  • 0.8.0 August 11, 2026 Production readiness. OpenID Connect with PKCE and JWKS validation, rate limiting on the authentication endpoints, warehouse credentials encrypted at rest, transactional branch creation by copy, MongoDB index management, and the registerTable, listViews, viewExists and dropView operations. Adds a backup and restore drill script and a load harness, and fixes defects in the published container images. Tag v0.8.0; PyPangolin 0.8.0 and the alexmerced/pangolin-api:0.8.0 image were published the same day.
  • 0.7.0 August 10, 2026 A security release. Closes a privilege escalation that let any authenticated caller mint a Root token and an endpoint that let any tenant member vend warehouse credentials. Adds a permission matrix test and a cross-backend parity suite to CI. This entry is in the changelog, but there is no v0.7.0 tag, and no 0.7.0 image or PyPI release was published.
  • 0.6.0 August 9, 2026 A security release with breaking changes: PANGOLIN_JWT_SECRET is required, there are no default root credentials, OAuth moves to a code exchange with allowlisted redirects, health probes move to /health/live and /health/ready, and unsupported Iceberg commit operations return 501 instead of a false 200. Tag v0.6.0; the release pipeline did not publish an image for it.
  • 0.5.1 and earlier December 20 to 30, 2025 Tags v0.1.0 through v0.5.1. No changelog was kept before 0.6.0; the GitHub releases and git history are the record.

PyPangolin on PyPI goes from 0.5.1 (January 2, 2026) straight to 0.8.0 (August 11, 2026).

Work with Alex