apache/iceberg · error · UnsupportedOperationException

Payload signing not supported

Error message

Payload signing not supported

What it means

checkSignerParams() rejects AwsS3V4SignerParams with enablePayloadSigning()=true. The remote REST signer signs requests without transmitting payloads to the signer and requires unsigned payloads; payload signing is explicitly unsupported.

Solutions

  1. Enable remote signing without payload signing (Iceberg handles the s3.remote-signing-enabled wiring automatically).
  2. Check which operation triggered signed payloads and whether it is compatible with remote signing.
  3. Fall back to standard AWS credentials (non-remote signing) if payload signing is mandatory for your workload.
  4. Upgrade Iceberg/SDK versions where payload-signing defaults are handled.

Example fix

// before
// remote signer with payload signing enabled by SDK default
S3Client.builder().credentialsProvider(accessGrantsProvider).build();
// after
// let Iceberg configure the signer with unsigned payload
S3FileIO io = new S3FileIO(props); // remoteSigningEnabled handles params
Defensive patterns

Strategy: validation

Validate before calling

// Java
if (signerParams.enablePayloadSigning()) {
  throw new IllegalStateException("Remote S3 signer requires payload signing disabled");
}

Try / catch

// Java
try {
  io.newOutputFile(loc).createOrOverwrite();
} catch (UnsupportedOperationException e) {
  if (e.getMessage().equals("Payload signing not supported")) {
    LOG.error("Disable payload signing or fall back to standard credential signing");
  }
}

Prevention

When it happens

Trigger: The AWS SDK produces signer params with payload signing enabled (e.g. certain request types or SDK defaults) while using the remote S3 signer via processRequestPayload.

Common situations: S3 Access Grants flows where the SDK enables payload signing by default; clients not setting the Iceberg property to disable payload signing; certain operations (e.g. PutObject with checksums) forcing signed payloads.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/f5660d0f1c8b14e9. Report an issue: GitHub.

Appendix: source

Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java:387

      Map<String, List<String>> signedAndUnsignedHeaders,
      SdkHttpFullRequest.Builder mutableRequest) {
    Map<String, List<String>> headers = Maps.newHashMap(signedAndUnsignedHeaders);
    // we need to remove the Cache-Control header that is being sent by the server
    headers.remove(CACHE_CONTROL);

    // we need to overwrite whatever headers the server signed/unsigned with the ones from the
    // original request and then put all headers back to the request
    headers.putAll(mutableRequest.headers());
    headers.forEach(mutableRequest::putHeader);
  }

  private boolean canBeCached(Map<String, String> responseHeaders) {
    return CACHE_CONTROL_PRIVATE.equals(responseHeaders.get(CACHE_CONTROL));
  }

  private void checkSignerParams(AwsS3V4SignerParams signerParams) {
    if (signerParams.enablePayloadSigning()) {
      throw new UnsupportedOperationException("Payload signing not supported");
    }

    if (signerParams.enableChunkedEncoding()) {
      throw new UnsupportedOperationException("Chunked encoding not supported");
    }
  }

  @Value.Immutable
  interface Key {
    String method();

    String region();

    String uri();

    static Key from(RemoteSignRequest request) {
      return ImmutableKey.builder()
          .method(request.method())

View on GitHub (pinned to 86d9c8fc54)