apache/iceberg · warning
Failed to refresh storage credentials
Error message
Failed to refresh storage credentials
What it means
S3FileIO can refresh storage credentials periodically (e.g. when initialized with credential providers that rotate). refreshStorageCredentials() catches any exception during the refresh and logs this warning, keeping the previously loaded credentials in place. If refresh keeps failing, the stored credentials may eventually expire and requests will start failing with auth errors.
Solutions
- Check the attached exception to find why the provider failed (auth vs network vs config)
- Verify the AWS credentials chain and role trust policies are still valid
- Ensure the catalog exposing credentials is reachable at refresh time
- Correct clock skew on the client host if SigV4 signing errors appear
Defensive patterns
Strategy: try-catch
Validate before calling
// before initialize, verify the credential provider can resolve credentials AwsCredentials c = DefaultCredentialsProvider.create().resolveCredentials();
Try / catch
try { io.initialize(props); } catch (RuntimeException e) { throw e; } // refresh failures are warnings; watch for later auth errors Prevention
- Keep role trust policies and STS permissions valid for the refresh identity
- Monitor this warning rate — recurring refresh failures predict future auth failures
- Ensure the credential-granting catalog is reachable from the compute environment
When it happens
Trigger: Scheduled credential refresh runs while the credential provider cannot fetch new credentials (network failure, revoked AssumeRole, catalog unreachable, expired refresh token).
Common situations: IAM role trust policy changed; catalog/STS temporarily unavailable; clock skew invalidating SigV4 signatures; credentials configured statically so refresh always fails.
Related errors
- Cannot assume role to sign REST requests because is not…
- Cannot commit because Glue cannot access the requested…
- Failed to add delete tags
- Failed to refresh storage credentials
- An error occurred while aborting the stream
AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12).
Data as JSON: /api/errors/9af3798404980bd5.
Report an issue: GitHub.
Appendix: source
Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/S3FileIO.java:476
private void refreshStorageCredentials() {
if (isResourceClosed.get()) {
return;
}
try (VendedCredentialsProvider provider = VendedCredentialsProvider.create(properties)) {
List<StorageCredential> refreshed =
provider.fetchCredentials().credentials().stream()
.filter(c -> c.prefix().startsWith(ROOT_PREFIX))
.map(c -> StorageCredential.create(c.prefix(), c.config()))
.collect(Collectors.toList());
if (!refreshed.isEmpty() && !isResourceClosed.get()) {
this.storageCredentials = Lists.newArrayList(refreshed);
scheduleCredentialRefresh();
}
} catch (Exception e) {
LOG.warn("Failed to refresh storage credentials", e);
}
}
private ScheduledExecutorService executorService() {
if (executorService == null) {
synchronized (S3FileIO.class) {
if (executorService == null) {
executorService =
ThreadPools.newExitingScheduledPool(
"iceberg-s3fileio-tasks",
clientForStoragePath(ROOT_PREFIX).s3FileIOProperties().deleteThreads(),
Duration.ofSeconds(10));
}
}
}
return executorService;
}View on GitHub (pinned to 86d9c8fc54)