apache/iceberg · error · UnsupportedOperationException
Payload signing not supported
Error message
Payload signing not supported
What it means
checkSignerParams() rejects AwsS3V4SignerParams with enablePayloadSigning()=true. The remote REST signer signs requests without transmitting payloads to the signer and requires unsigned payloads; payload signing is explicitly unsupported.
Solutions
- Enable remote signing without payload signing (Iceberg handles the s3.remote-signing-enabled wiring automatically).
- Check which operation triggered signed payloads and whether it is compatible with remote signing.
- Fall back to standard AWS credentials (non-remote signing) if payload signing is mandatory for your workload.
- Upgrade Iceberg/SDK versions where payload-signing defaults are handled.
Example fix
// before // remote signer with payload signing enabled by SDK default S3Client.builder().credentialsProvider(accessGrantsProvider).build(); // after // let Iceberg configure the signer with unsigned payload S3FileIO io = new S3FileIO(props); // remoteSigningEnabled handles params
Defensive patterns
Strategy: validation
Validate before calling
// Java
if (signerParams.enablePayloadSigning()) {
throw new IllegalStateException("Remote S3 signer requires payload signing disabled");
} Try / catch
// Java
try {
io.newOutputFile(loc).createOrOverwrite();
} catch (UnsupportedOperationException e) {
if (e.getMessage().equals("Payload signing not supported")) {
LOG.error("Disable payload signing or fall back to standard credential signing");
}
} Prevention
- Do not force payload signing in SDK config when remote signing is enabled
- Test write operations (PutObject) under remote signing before production
- Fall back to normal AWS credentials for workloads that mandate signed payloads
When it happens
Trigger: The AWS SDK produces signer params with payload signing enabled (e.g. certain request types or SDK defaults) while using the remote S3 signer via processRequestPayload.
Common situations: S3 Access Grants flows where the SDK enables payload signing by default; clients not setting the Iceberg property to disable payload signing; certain operations (e.g. PutObject with checksums) forcing signed payloads.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- Chunked encoding not supported
- Pre-signing not allowed.
- AboveMax has no comparator
- Altering partition keys is not supported yet.
- Altering partition keys is not supported yet.
AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12).
Data as JSON: /api/errors/f5660d0f1c8b14e9.
Report an issue: GitHub.
Appendix: source
Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java:387
Map<String, List<String>> signedAndUnsignedHeaders,
SdkHttpFullRequest.Builder mutableRequest) {
Map<String, List<String>> headers = Maps.newHashMap(signedAndUnsignedHeaders);
// we need to remove the Cache-Control header that is being sent by the server
headers.remove(CACHE_CONTROL);
// we need to overwrite whatever headers the server signed/unsigned with the ones from the
// original request and then put all headers back to the request
headers.putAll(mutableRequest.headers());
headers.forEach(mutableRequest::putHeader);
}
private boolean canBeCached(Map<String, String> responseHeaders) {
return CACHE_CONTROL_PRIVATE.equals(responseHeaders.get(CACHE_CONTROL));
}
private void checkSignerParams(AwsS3V4SignerParams signerParams) {
if (signerParams.enablePayloadSigning()) {
throw new UnsupportedOperationException("Payload signing not supported");
}
if (signerParams.enableChunkedEncoding()) {
throw new UnsupportedOperationException("Chunked encoding not supported");
}
}
@Value.Immutable
interface Key {
String method();
String region();
String uri();
static Key from(RemoteSignRequest request) {
return ImmutableKey.builder()
.method(request.method())View on GitHub (pinned to 86d9c8fc54)