apache/iceberg · warning
File encryption key metadata is present, but no encryption…
Error message
File encryption key metadata is present, but no encryption has been configured.
What it means
PlaintextEncryptionManager.decrypt logs a WARN when it is asked to decrypt a file that carries encryption key metadata, but no encryption manager is configured for the table. The file is returned as-is (read as plaintext); if the file is actually encrypted the read will subsequently fail or produce garbage.
Solutions
- Configure the table's encryption properties/EncryptionManager so files with key metadata are decrypted properly.
- Identify which files carry key metadata (manifest key_metadata) and decide whether they are truly encrypted; rewrite them unencrypted if not needed.
- If the files are genuinely plaintext and metadata is stale, remove stale key metadata by rewriting the data files.
Example fix
// before table encryption unset -> PlaintextEncryptionManager used // after TableProperties + encrypted catalog: load table with encryption-aware catalog or set 'encryption.key-metadata' handling so EncryptingFileIO decrypts key metadata
Defensive patterns
Strategy: validation
Validate before calling
// before reading, check files for key metadata
boolean hasKeyMetadata = manifests.stream()
.flatMap(m -> ManifestFiles.read(m.file(), table.io()))
.anyMatch(f -> f.keyMetadata() != null); Try / catch
if (hasKeyMetadata) {
// load table via an encryption-aware catalog / configure EncryptingFileIO
} Prevention
- Use the same catalog (with encryption config) for reading as for writing.
- Do not drop encryption table properties when copying/cloning tables.
- Audit manifest key_metadata before migrating tables between catalogs.
When it happens
Trigger: Reading/compacting a table whose manifest entries contain file key metadata (encrypted files) while table encryption is unset, so the plaintext manager is used and just logs and passes through the encrypted input file.
Common situations: Table cloned/copied with encryption metadata but encryption properties dropped; mixing encrypted and unencrypted files in one table; loading a table without the configured EncryptionManager (e.g. in a custom catalog or engine integration).
Related errors
- Failed to close encryption manager
- Failed to read the version byte
- File length is null
- File length unknown, creating an AesGcmInputFile is not safe
- Invalid position
AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12).
Data as JSON: /api/errors/9d30b97ebb2af48b.
Report an issue: GitHub.
Appendix: source
Thrown at core/src/main/java/org/apache/iceberg/encryption/PlaintextEncryptionManager.java:39
import org.apache.iceberg.io.InputFile;
import org.apache.iceberg.io.OutputFile;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class PlaintextEncryptionManager implements EncryptionManager {
private static final EncryptionManager INSTANCE = new PlaintextEncryptionManager();
private static final Logger LOG = LoggerFactory.getLogger(PlaintextEncryptionManager.class);
private PlaintextEncryptionManager() {}
public static EncryptionManager instance() {
return INSTANCE;
}
@Override
public InputFile decrypt(EncryptedInputFile encrypted) {
if (encrypted.keyMetadata().buffer() != null) {
LOG.warn("File encryption key metadata is present, but no encryption has been configured.");
}
return encrypted.encryptedInputFile();
}
@Override
public EncryptedOutputFile encrypt(OutputFile rawOutput) {
return EncryptedFiles.encryptedOutput(rawOutput, EncryptionKeyMetadata.empty());
}
}
View on GitHub (pinned to 86d9c8fc54)