apache/iceberg · warning

Failed to refresh storage credentials

Error message

Failed to refresh storage credentials

What it means

S3FileIO can refresh storage credentials periodically (e.g. when initialized with credential providers that rotate). refreshStorageCredentials() catches any exception during the refresh and logs this warning, keeping the previously loaded credentials in place. If refresh keeps failing, the stored credentials may eventually expire and requests will start failing with auth errors.

Solutions

  1. Check the attached exception to find why the provider failed (auth vs network vs config)
  2. Verify the AWS credentials chain and role trust policies are still valid
  3. Ensure the catalog exposing credentials is reachable at refresh time
  4. Correct clock skew on the client host if SigV4 signing errors appear
Defensive patterns

Strategy: try-catch

Validate before calling

// before initialize, verify the credential provider can resolve credentials
AwsCredentials c = DefaultCredentialsProvider.create().resolveCredentials();

Try / catch

try { io.initialize(props); } catch (RuntimeException e) { throw e; } // refresh failures are warnings; watch for later auth errors

Prevention

When it happens

Trigger: Scheduled credential refresh runs while the credential provider cannot fetch new credentials (network failure, revoked AssumeRole, catalog unreachable, expired refresh token).

Common situations: IAM role trust policy changed; catalog/STS temporarily unavailable; clock skew invalidating SigV4 signatures; credentials configured statically so refresh always fails.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/9af3798404980bd5. Report an issue: GitHub.

Appendix: source

Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/S3FileIO.java:476

  private void refreshStorageCredentials() {
    if (isResourceClosed.get()) {
      return;
    }

    try (VendedCredentialsProvider provider = VendedCredentialsProvider.create(properties)) {
      List<StorageCredential> refreshed =
          provider.fetchCredentials().credentials().stream()
              .filter(c -> c.prefix().startsWith(ROOT_PREFIX))
              .map(c -> StorageCredential.create(c.prefix(), c.config()))
              .collect(Collectors.toList());

      if (!refreshed.isEmpty() && !isResourceClosed.get()) {
        this.storageCredentials = Lists.newArrayList(refreshed);
        scheduleCredentialRefresh();
      }
    } catch (Exception e) {
      LOG.warn("Failed to refresh storage credentials", e);
    }
  }

  private ScheduledExecutorService executorService() {
    if (executorService == null) {
      synchronized (S3FileIO.class) {
        if (executorService == null) {
          executorService =
              ThreadPools.newExitingScheduledPool(
                  "iceberg-s3fileio-tasks",
                  clientForStoragePath(ROOT_PREFIX).s3FileIOProperties().deleteThreads(),
                  Duration.ofSeconds(10));
        }
      }
    }

    return executorService;
  }

View on GitHub (pinned to 86d9c8fc54)