apache/iceberg · error · UnsupportedOperationException
Pre-signing not allowed.
Error message
Pre-signing not allowed.
What it means
S3V4RestSignerClient.presign() unconditionally throws UnsupportedOperationException. This remote signer only supports signing request headers/payload after credential refresh; it never pre-signs full requests, and the AWS SDK must not ask it to.
Solutions
- Remove presigning-related SDK options so the signer is used in normal (sign) mode.
- Configure the S3FileIO/catalog to use the remote signer's default auth scheme.
- If you need presigned URLs, generate them separately (e.g. S3Presigner) rather than via this client.
- Check SDK version compatibility for S3 Access Grants remote signing.
Example fix
// before S3Client.builder().requestSignerVersion(mySigner).build(); // triggers presign path // after S3FileIOProperties props = new S3FileIOProperties(); props.setRemoteSigningEnabled(true); // normal sign path, no presigning
Defensive patterns
Strategy: validation
Validate before calling
// Java
// ensure remote signing mode, not presigning, is configured
boolean remoteSigning = props.isRemoteSigningEnabled();
if (!remoteSigning) {
throw new IllegalStateException("Use remote signing mode with S3V4RestSignerClient");
} Try / catch
// Java
try {
io.newInputFile(s3Path).newStream();
} catch (UnsupportedOperationException e) {
if (e.getMessage().contains("Pre-signing")) {
LOG.error("Disable presigning in SDK/auth config when using the REST S3 signer");
}
} Prevention
- Never enable SDK presigning options alongside the remote signer
- Use S3Presigner separately if presigned URLs are actually needed
- Keep SDK versions aligned with the Iceberg remote-signing support matrix
When it happens
Trigger: Configuring the S3 Access Grants/remote signing auth scheme in a mode that requests presigned URLs, or an SDK version/configuration invoking presign() on this signer.
Common situations: Client misconfiguration selecting 'presigning' auth for the REST-backed S3 signer; using an SDK option (e.g. enablePresigning) incompatible with remote signing.
Related errors
- Chunked encoding not supported
- Payload signing not supported
- Found unsupported view representations
- AboveMax has no comparator
- Altering partition keys is not supported yet.
AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12).
Data as JSON: /api/errors/4f39aa042ca9a846.
Report an issue: GitHub.
Appendix: source
Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java:283
SdkHttpFullRequest.Builder mutableRequest,
byte[] signature,
byte[] signingKey,
Aws4SignerRequestParams signerRequestParams,
AwsS3V4SignerParams signerParams,
SdkChecksum sdkChecksum) {
checkSignerParams(signerParams);
}
@Override
protected String calculateContentHashPresign(
SdkHttpFullRequest.Builder mutableRequest, Aws4PresignerParams signerParams) {
return UNSIGNED_PAYLOAD;
}
@Override
public SdkHttpFullRequest presign(
SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {
throw new UnsupportedOperationException("Pre-signing not allowed.");
}
@Override
public SdkHttpFullRequest sign(
SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {
AwsS3V4SignerParams signerParams =
extractSignerParams(AwsS3V4SignerParams.builder(), executionAttributes).build();
RemoteSignRequest remoteSigningRequest =
ImmutableRemoteSignRequest.builder()
.method(request.method().name())
.region(signerParams.signingRegion().id())
.uri(request.getUri())
.headers(request.headers())
.properties(requestPropertiesSupplier().get())
.body(bodyAsString(request))
.provider(S3_PROVIDER)
.build();View on GitHub (pinned to 86d9c8fc54)