Documentation
How Rustberg authenticates callers, authorizes every operation against Cedar policy, federates catalogs, vends storage credentials, and records what it decided.
Rustberg is one authenticated, policy-controlled Apache Iceberg REST endpoint in front of every catalog you own — a single Rust binary, and an embeddable crate.
If you have five minutes, start with Getting started:
one command brings up a catalog, mints an admin key and prints the curl that
uses it. If you are evaluating whether Rustberg fits, read
Architecture for how a request is actually decided, then
Security for what is enforced and — just as importantly —
where enforcement stops.
Start here
Governance
Authentication
How Rustberg establishes who a caller is: OIDC/JWT with JWKS rotation, and API keys as configuration.
Authorization
Cedar policies over a resource hierarchy: path-scoped grants, tenant isolation, row filters and column masks.
Security
Rustberg's threat model, what it enforces, where enforcement stops, and what a deployment must guarantee itself.
Encryption
What Rustberg encrypts, what it deliberately does not, and where table encryption actually belongs.
Catalogs & storage
Catalog and warehouse
Where Rustberg keeps the catalog — an embedded redb file or Postgres — and where the tables themselves live.
Federation
Mount several Iceberg catalogs under one endpoint and one identity, routed by top-level namespace.
API reference
Every Iceberg REST endpoint Rustberg serves, what it returns, and what it declines with which status code.
Run it
Configuration
Every Rustberg setting: the TOML file, environment variables, and CLI flags, and which wins.
Kubernetes
Deploying Rustberg on Kubernetes: the Helm chart, replica shapes, probes, and network policy.
Clients and engines
Connecting PyIceberg, Spark, Trino, Flink and DuckDB to Rustberg, with working configuration.
Library
Using Rustberg as a Rust crate: the catalog, Cedar policy and credential vending in-process, no server.