apache/iceberg · info

Signer endpoint is configured via deprecated property

Error message

Signer endpoint is configured via deprecated property {}, this won't be supported in future releases. Please remove this property to let the signer use the default endpoint instead.

What it means

S3V4RestSignerClient.check() detects the deprecated s3.signer.endpoint property and warns that it will stop being supported; users should remove it so the signer derives the endpoint from the default location instead.

Solutions

  1. Remove s3.signer.endpoint from properties
  2. If a custom endpoint is genuinely needed, upgrade to a version where the replacement mechanism applies, or configure it via the supported URI property
  3. Verify signer traffic hits the intended endpoint after removal

Example fix

// before
's3.signer.endpoint' = '/v1/aws/s3/sign'
// after
// property removed; signer uses default endpoint
Defensive patterns

Strategy: validation

Validate before calling

Properties props = catalog.properties();
if (props.containsKey("s3.signer.endpoint")) {
  throw new IllegalArgumentException("Remove deprecated s3.signer.endpoint; let the signer use the default endpoint");
}

Prevention

When it happens

Trigger: Having s3.signer.endpoint in catalog properties when initializing the REST signer client.

Common situations: Configs migrated from older Iceberg versions; mixed old/new properties kept 'just in case'; environment provisioning scripts that inject legacy signer settings.

Understand the failure class

Background: "is deprecated and will be removed" — deprecation warnings for old API names, keywords, and options, and how to migrate before the removal release — this error's family across 29 libraries.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/2e4f7632724889f6. Report an issue: GitHub.

Appendix: source

Thrown at aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java:245

    Preconditions.checkArgument(
        properties().containsKey(RESTCatalogProperties.SIGNER_ENDPOINT)
            || properties().containsKey(RESTCatalogProperties.REMOTE_SIGNING_ENDPOINT),
        "Remote signing endpoint is required");

    Preconditions.checkArgument(
        properties().containsKey(RESTCatalogProperties.SIGNER_URI)
            || properties().containsKey(CatalogProperties.URI),
        "S3 signer service URI is required");

    if (properties().containsKey(RESTCatalogProperties.SIGNER_URI)) {
      LOG.warn(
          "S3 signer URI is configured via deprecated property {}, this won't be supported in future releases. "
              + "Please remove this property to let the signer use the default URI instead.",
          RESTCatalogProperties.SIGNER_URI);
    }

    if (properties().containsKey(RESTCatalogProperties.SIGNER_ENDPOINT)) {
      LOG.warn(
          "Signer endpoint is configured via deprecated property {}, this won't be supported in future releases. "
              + "Please remove this property to let the signer use the default endpoint instead.",
          RESTCatalogProperties.SIGNER_ENDPOINT);
    }
  }

  @Override
  protected void processRequestPayload(
      SdkHttpFullRequest.Builder mutableRequest,
      byte[] signature,
      byte[] signingKey,
      Aws4SignerRequestParams signerRequestParams,
      AwsS3V4SignerParams signerParams) {
    checkSignerParams(signerParams);
  }

  @SuppressWarnings("deprecation")
  @Override

View on GitHub (pinned to 86d9c8fc54)