apache/iceberg · error · UnsupportedOperationException

Pre-signing not allowed.

Error message

Pre-signing not allowed.

What it means

S3V4RestSignerClient.presign() unconditionally throws UnsupportedOperationException. This remote signer only supports signing request headers/payload after credential refresh; it never pre-signs full requests, and the AWS SDK must not ask it to.

Solutions

  1. Remove presigning-related SDK options so the signer is used in normal (sign) mode.
  2. Configure the S3FileIO/catalog to use the remote signer's default auth scheme.
  3. If you need presigned URLs, generate them separately (e.g. S3Presigner) rather than via this client.
  4. Check SDK version compatibility for S3 Access Grants remote signing.

Example fix

// before
S3Client.builder().requestSignerVersion(mySigner).build(); // triggers presign path
// after
S3FileIOProperties props = new S3FileIOProperties();
props.setRemoteSigningEnabled(true); // normal sign path, no presigning
Defensive patterns

Strategy: validation

Validate before calling

// Java
// ensure remote signing mode, not presigning, is configured
boolean remoteSigning = props.isRemoteSigningEnabled();
if (!remoteSigning) {
  throw new IllegalStateException("Use remote signing mode with S3V4RestSignerClient");
}

Try / catch

// Java
try {
  io.newInputFile(s3Path).newStream();
} catch (UnsupportedOperationException e) {
  if (e.getMessage().contains("Pre-signing")) {
    LOG.error("Disable presigning in SDK/auth config when using the REST S3 signer");
  }
}

Prevention

When it happens

Trigger: Configuring the S3 Access Grants/remote signing auth scheme in a mode that requests presigned URLs, or an SDK version/configuration invoking presign() on this signer.

Common situations: Client misconfiguration selecting 'presigning' auth for the REST-backed S3 signer; using an SDK option (e.g. enablePresigning) incompatible with remote signing.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/4f39aa042ca9a846. Report an issue: GitHub.

Appendix: source

Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java:283

      SdkHttpFullRequest.Builder mutableRequest,
      byte[] signature,
      byte[] signingKey,
      Aws4SignerRequestParams signerRequestParams,
      AwsS3V4SignerParams signerParams,
      SdkChecksum sdkChecksum) {
    checkSignerParams(signerParams);
  }

  @Override
  protected String calculateContentHashPresign(
      SdkHttpFullRequest.Builder mutableRequest, Aws4PresignerParams signerParams) {
    return UNSIGNED_PAYLOAD;
  }

  @Override
  public SdkHttpFullRequest presign(
      SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {
    throw new UnsupportedOperationException("Pre-signing not allowed.");
  }

  @Override
  public SdkHttpFullRequest sign(
      SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {
    AwsS3V4SignerParams signerParams =
        extractSignerParams(AwsS3V4SignerParams.builder(), executionAttributes).build();

    RemoteSignRequest remoteSigningRequest =
        ImmutableRemoteSignRequest.builder()
            .method(request.method().name())
            .region(signerParams.signingRegion().id())
            .uri(request.getUri())
            .headers(request.headers())
            .properties(requestPropertiesSupplier().get())
            .body(bodyAsString(request))
            .provider(S3_PROVIDER)
            .build();

View on GitHub (pinned to 86d9c8fc54)