apache/iceberg · error · IllegalArgumentException

Cannot initialize AuthManager implementation

Error message

Cannot initialize AuthManager implementation %s: %s

What it means

Thrown by AuthManagers.loadAuthManager when a custom AuthManager impl class cannot be instantiated reflectively — DynConstructors found no matching constructor taking (String name) or (String name, AuthManager delegate), e.g. class missing, not visible, or wrong constructor signature.

Solutions

  1. Verify the class is on the runtime classpath (check for typos in the FQCN)
  2. Add a public constructor AuthManager(String name) or (String name, AuthManager delegate)
  3. Confirm the class implements org.apache.iceberg.rest.auth.AuthManager
  4. Check that security providers/jars are included in the shaded/fat jar

Example fix

// before
class MyAuthManager {
  MyAuthManager(String name, Map<String,String> props) { ... }
}
// after
class MyAuthManager implements AuthManager {
  public MyAuthManager(String name) { ... }
  public MyAuthManager(String name, AuthManager delegate) { ... }
}
Defensive patterns

Strategy: validation

Validate before calling

// pre-validate the configured impl class
Class<?> cls = Class.forName(implClassName);
boolean ok = AuthManager.class.isAssignableFrom(cls)
  && java.util.Arrays.stream(cls.getConstructors())
      .anyMatch(c -> {
        Class<?>[] p = c.getParameterTypes();
        return (p.length == 1 && p[0] == String.class)
          || (p.length == 2 && p[0] == String.class && AuthManager.class.isAssignableFrom(p[1]));
      });

Type guard

boolean isInstantiableAuthManager(String impl) {
  try {
    Class<?> c = Class.forName(impl);
    return AuthManager.class.isAssignableFrom(c);
  } catch (ClassNotFoundException e) { return false; }
}

Try / catch

try { authManager = AuthManagers.loadAuthManager(config); } catch (IllegalArgumentException e) {
  if (e.getMessage().startsWith("Cannot initialize AuthManager implementation")) { /* fix impl class */ }
  else throw e;
}

Prevention

When it happens

Trigger: Setting an AuthManager impl (via rest.auth.type=impl-class or catalog config) whose class has neither a (String) nor (String, AuthManager) constructor, or whose class cannot be loaded.

Common situations: Typos in the fully-qualified class name; class not on the classpath; custom AuthManager missing the required constructor; wrong constructor visibility (not public).

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/acbae43f12c7c905. Report an issue: GitHub.

Appendix: source

Thrown at core/src/main/java/org/apache/iceberg/rest/auth/AuthManagers.java:118

        break;
      case AuthProperties.AUTH_TYPE_OAUTH2:
        impl = AuthProperties.AUTH_MANAGER_IMPL_OAUTH2;
        break;
      default:
        impl = authType;
    }

    LOG.info("Loading AuthManager implementation: {}", impl);
    DynConstructors.Ctor<AuthManager> ctor;
    try {
      ctor =
          DynConstructors.builder(AuthManager.class)
              .loader(AuthManagers.class.getClassLoader())
              .impl(impl, String.class) // with name
              .impl(impl, String.class, AuthManager.class) // with name and delegate
              .buildChecked();
    } catch (NoSuchMethodException e) {
      throw new IllegalArgumentException(
          String.format(
              "Cannot initialize AuthManager implementation %s: %s", impl, e.getMessage()),
          e);
    }

    AuthManager authManager;
    try {
      authManager = ctor.newInstance(name, delegate);
    } catch (ClassCastException e) {
      throw new IllegalArgumentException(
          String.format("Cannot initialize AuthManager, %s does not implement AuthManager", impl),
          e);
    }

    return authManager;
  }
}

View on GitHub (pinned to 86d9c8fc54)