apache/iceberg · info

S3 signer URI is configured via deprecated property

Error message

S3 signer URI is configured via deprecated property {}, this won't be supported in future releases. Please remove this property to let the signer use the default URI instead.

What it means

S3V4RestSignerClient.check() validates signer configuration. Setting the deprecated SIGNER_URI property still works but logs this deprecation warning, telling users to remove the property so the signer falls back to the default/catalog URI.

Solutions

  1. Remove s3.signer.uri from catalog properties
  2. Set the desired URI via the standard CatalogProperties.URI (rest.catalog.uri) instead
  3. Re-run and confirm the warning disappears

Example fix

// before
's3.signer.uri' = 'https://signer.example.com'
// after
'rest.catalog.uri' = 'https://catalog.example.com'  // signer uses this by default
Defensive patterns

Strategy: validation

Validate before calling

Properties props = catalog.properties();
if (props.containsKey("s3.signer.uri")) {
  throw new IllegalArgumentException("Remove deprecated s3.signer.uri; configure rest.catalog.uri instead");
}

Prevention

When it happens

Trigger: Configuring s3.signer.uri in catalog properties while using the REST S3 signer; the property key is read at client initialization via check().

Common situations: Upgrading Iceberg after the signer URI handling moved to the catalog URI; copied older config templates; docs/blog posts referencing the old property.

Understand the failure class

Background: "is deprecated and will be removed" — deprecation warnings for old API names, keywords, and options, and how to migrate before the removal release — this error's family across 29 libraries.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/4c351f3183456d26. Report an issue: GitHub.

Appendix: source

Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java:238

  private boolean credentialProvided() {
    return null != credential() && !credential().isEmpty();
  }

  @Value.Check
  protected void check() {
    Preconditions.checkArgument(
        properties().containsKey(RESTCatalogProperties.SIGNER_ENDPOINT)
            || properties().containsKey(RESTCatalogProperties.REMOTE_SIGNING_ENDPOINT),
        "Remote signing endpoint is required");

    Preconditions.checkArgument(
        properties().containsKey(RESTCatalogProperties.SIGNER_URI)
            || properties().containsKey(CatalogProperties.URI),
        "S3 signer service URI is required");

    if (properties().containsKey(RESTCatalogProperties.SIGNER_URI)) {
      LOG.warn(
          "S3 signer URI is configured via deprecated property {}, this won't be supported in future releases. "
              + "Please remove this property to let the signer use the default URI instead.",
          RESTCatalogProperties.SIGNER_URI);
    }

    if (properties().containsKey(RESTCatalogProperties.SIGNER_ENDPOINT)) {
      LOG.warn(
          "Signer endpoint is configured via deprecated property {}, this won't be supported in future releases. "
              + "Please remove this property to let the signer use the default endpoint instead.",
          RESTCatalogProperties.SIGNER_ENDPOINT);
    }
  }

  @Override
  protected void processRequestPayload(
      SdkHttpFullRequest.Builder mutableRequest,
      byte[] signature,
      byte[] signingKey,

View on GitHub (pinned to 86d9c8fc54)