apache/seatunnel · warning

Collector authentication timeout from

Error message

Collector authentication timeout from {}, connection rejected

What it means

A WARN logged by IngressProtocolHandler.authenticate when reading the collector's auth line throws a SocketTimeoutException — the collector connected but did not send its token within the socket's read timeout. The connection is rejected with AUTH_FAILED.

Solutions

  1. Ensure collectors write the auth token line immediately after connecting.
  2. Exclude health-check/probe sources from the EdgeSocket port or make them protocol-aware.
  3. Increase the socket read timeout in the EdgeSocket config if collectors are legitimately slow.
  4. Verify collectors are not stuck waiting for a server banner — the protocol is client-first.
Defensive patterns

Strategy: retry

Validate before calling

// client side: send the token immediately after connect
socket.connect(addr, connectTimeoutMs);
socket.setSoTimeout(readTimeoutMs);
out.write(("token:" + token + "\n").getBytes());
out.flush();

Try / catch

try {
    boolean ok = handler.authenticate(channel);
} catch (SocketTimeoutException e) {
    // expected for silent clients; connection already rejected
}

Prevention

When it happens

Trigger: channel.readLine() in authenticate blocks past the socket SO_TIMEOUT because the collector never writes the auth token line (hung/slow client, half-open connection, or a non-EdgeSocket client probing the port).

Common situations: Load balancer health checks opening TCP connections without speaking the protocol; collector with stalled network; collectors waiting for a server greeting the protocol doesn't send; firewalled/NAT'd clients.

Understand the failure class

Background: Request timed out: what client-side request timeouts mean across libraries (Request timed out, TIMED_OUT, APITimeoutError) — this error's family across 39 libraries.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/4e8452b18d1e3e00. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/protocol/IngressProtocolHandler.java:59

        this.config = config;
        this.handler = handler;
    }

    public boolean authenticate(IngressChannel channel) throws IOException {
        if (config.getAuthType() != EdgeSocketAuthType.TOKEN) {
            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
            log.warn(
                    "Unsupported auth type: {}, from {}",
                    config.getAuthType(),
                    channel.remoteAddress());
            return false;
        }
        String authLine;
        try {
            authLine = channel.readLine();
        } catch (SocketTimeoutException timeoutException) {
            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
            log.warn(
                    "Collector authentication timeout from {}, connection rejected",
                    channel.remoteAddress());
            return false;
        }
        if (authLine == null) {
            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
            log.warn(
                    "Collector from {} closed connection before authentication",
                    channel.remoteAddress());
            return false;
        }
        String presentedToken = parseAuthToken(authLine);
        if (!constantTimeEquals(config.getToken(), presentedToken)) {
            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
            log.warn("Collector authentication failed from {}", channel.remoteAddress());
            return false;
        }
        channel.writeLine(EdgeSocketResponseCode.ACK.getCode());

View on GitHub (pinned to cf67b549a7)