apache/seatunnel · warning
Collector authentication timeout from
Error message
Collector authentication timeout from {}, connection rejected What it means
A WARN logged by IngressProtocolHandler.authenticate when reading the collector's auth line throws a SocketTimeoutException — the collector connected but did not send its token within the socket's read timeout. The connection is rejected with AUTH_FAILED.
Solutions
- Ensure collectors write the auth token line immediately after connecting.
- Exclude health-check/probe sources from the EdgeSocket port or make them protocol-aware.
- Increase the socket read timeout in the EdgeSocket config if collectors are legitimately slow.
- Verify collectors are not stuck waiting for a server banner — the protocol is client-first.
Defensive patterns
Strategy: retry
Validate before calling
// client side: send the token immediately after connect
socket.connect(addr, connectTimeoutMs);
socket.setSoTimeout(readTimeoutMs);
out.write(("token:" + token + "\n").getBytes());
out.flush(); Try / catch
try {
boolean ok = handler.authenticate(channel);
} catch (SocketTimeoutException e) {
// expected for silent clients; connection already rejected
} Prevention
- Collectors must write the auth line first (client-first protocol)
- Exclude non-protocol health probes from the port
- Tune read timeout for slow collectors
When it happens
Trigger: channel.readLine() in authenticate blocks past the socket SO_TIMEOUT because the collector never writes the auth token line (hung/slow client, half-open connection, or a non-EdgeSocket client probing the port).
Common situations: Load balancer health checks opening TCP connections without speaking the protocol; collector with stalled network; collectors waiting for a server greeting the protocol doesn't send; firewalled/NAT'd clients.
Understand the failure class
Background: Request timed out: what client-side request timeouts mean across libraries (Request timed out, TIMED_OUT, APITimeoutError) — this error's family across 39 libraries.
- Timeouts: ETIMEDOUT, deadlines, and hung requests — what actually expires when a request times out.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Collector from closed connection before authentication
- Edge socket authentication rejected (AUTH_FAILED): check…
- Exceeded maxBatchSendAttempts=
- Unexpected auth response
- Unsupported auth type
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/4e8452b18d1e3e00.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/protocol/IngressProtocolHandler.java:59
this.config = config;
this.handler = handler;
}
public boolean authenticate(IngressChannel channel) throws IOException {
if (config.getAuthType() != EdgeSocketAuthType.TOKEN) {
channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
log.warn(
"Unsupported auth type: {}, from {}",
config.getAuthType(),
channel.remoteAddress());
return false;
}
String authLine;
try {
authLine = channel.readLine();
} catch (SocketTimeoutException timeoutException) {
channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
log.warn(
"Collector authentication timeout from {}, connection rejected",
channel.remoteAddress());
return false;
}
if (authLine == null) {
channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
log.warn(
"Collector from {} closed connection before authentication",
channel.remoteAddress());
return false;
}
String presentedToken = parseAuthToken(authLine);
if (!constantTimeEquals(config.getToken(), presentedToken)) {
channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());
log.warn("Collector authentication failed from {}", channel.remoteAddress());
return false;
}
channel.writeLine(EdgeSocketResponseCode.ACK.getCode());View on GitHub (pinned to cf67b549a7)