Pangolin: an Apache Iceberg REST catalog in Rust
Multi-tenant, with Git-style branches over catalog state. Pre-1.0, published as 0.8.0.
Pangolin is an open-source catalog for Apache Iceberg tables, written in Rust. It implements the Iceberg REST specification, so PyIceberg, Spark and other Iceberg clients can point at it directly, and it adds multi-tenancy, branches and merges, RBAC, credential vending and a management UI around that protocol. The latest release is 0.8.0, tagged on August 11, 2026. The project calls it beta and pre-1.0.
Install
The server ships as a container image. The Python SDK, PyPangolin, is on PyPI.
docker pull alexmerced/pangolin-api:0.8.0
pip install pypangolin
To build from source you need Rust 1.94 or later:
git clone https://github.com/AlexMercedCoder/Pangolin.git
cd Pangolin/pangolin
cargo run --bin pangolin_api
Since 0.6.0 the server refuses to start without PANGOLIN_JWT_SECRET. For a throwaway local instance, PANGOLIN_DEV_MODE=true generates an ephemeral secret instead. PANGOLIN_NO_AUTH=true only starts on a loopback bind address. The getting started guide covers configuration and the metadata backends.
What it is
A catalog tells a query engine which tables exist and where their metadata lives, and it arbitrates commits when several writers touch the same table. Pangolin does that over the Iceberg REST protocol and adds the pieces an operator wants around it:
- Multi-tenancy, with tenant-scoped namespaces and warehouses.
- Git-style branches, tags and 3-way merges over catalog state.
- Credential vending for AWS STS, Azure SAS and GCP downscoped credentials.
- RBAC, service users and API keys for pipelines and CI.
- OpenID Connect with PKCE and
id_tokenvalidation through JWKS, for providers that support it. - Warehouse credentials encrypted at rest with AES-256-GCM when
PANGOLIN_ENCRYPTION_KEYis set. - Audit logging across more than 40 actions and 19 resource types.
- Metadata backends: PostgreSQL (recommended), SQLite, MongoDB or in-memory.
- Federated catalogs that proxy an external Iceberg REST catalog.
- A SvelteKit management UI, two CLIs (
pangolin-adminandpangolin-user), a Helm chart, and PyPangolin.
Status
Beta, pre-1.0. The repository README labels the project beta, and STATUS.md is its reconciled record of what is done. It reports 448 tests across 65 test targets and 18 CI jobs, run against live PostgreSQL, MongoDB and MinIO.
By its own maturity table, the Iceberg REST core (namespaces, tables, commits) and multi-tenant isolation are solid, PostgreSQL is the recommended backend, and the MongoDB backend is still beta. What remains open, in the order it would block a production deployment:
- GitHub logins cannot be OIDC-validated, because GitHub issues no
id_token.PANGOLIN_OIDC_REQUIRE=truerefuses providers that cannot be validated. - Running more than one replica is constrained and unproven. OAuth needs session affinity, rate limits are per replica, and it has not been load tested.
commitTransactionis absent on purpose, because there is no cross-table transaction behind it.- Token revocation fails open if the revocation check itself errors.
- Smaller gaps: no tamper-evident audit trail, HS256 JWTs without rotation, no MFA or account lockout, no point-in-time recovery, and
replaceViewandrenameVieware not implemented.
0.6.0 and later are security releases. Anything older should be upgraded and its tokens rotated.
Changelog
From the project's CHANGELOG.md and its git tags. Since 0.6.0 the server, both CLIs, the Python SDK, the UI and the Helm chart carry one version number.
- 0.8.0 August 11, 2026 Production readiness. OpenID Connect with PKCE and JWKS validation, rate limiting on the authentication endpoints, warehouse credentials encrypted at rest, transactional branch creation by copy, MongoDB index management, and the
registerTable,listViews,viewExistsanddropViewoperations. Adds a backup and restore drill script and a load harness, and fixes defects in the published container images. Tagv0.8.0; PyPangolin 0.8.0 and thealexmerced/pangolin-api:0.8.0image were published the same day. - 0.7.0 August 10, 2026 A security release. Closes a privilege escalation that let any authenticated caller mint a
Roottoken and an endpoint that let any tenant member vend warehouse credentials. Adds a permission matrix test and a cross-backend parity suite to CI. This entry is in the changelog, but there is nov0.7.0tag, and no 0.7.0 image or PyPI release was published. - 0.6.0 August 9, 2026 A security release with breaking changes:
PANGOLIN_JWT_SECRETis required, there are no default root credentials, OAuth moves to a code exchange with allowlisted redirects, health probes move to/health/liveand/health/ready, and unsupported Iceberg commit operations return501instead of a false200. Tagv0.6.0; the release pipeline did not publish an image for it. - 0.5.1 and earlier December 20 to 30, 2025 Tags
v0.1.0throughv0.5.1. No changelog was kept before 0.6.0; the GitHub releases and git history are the record.
PyPangolin on PyPI goes from 0.5.1 (January 2, 2026) straight to 0.8.0 (August 11, 2026).