apache/seatunnel · warning
Connect/auth failed for
Error message
Connect/auth failed for {} What it means
EdgeTransportClient.ensureAuthenticatedSession tries to establish and authenticate a socket to the configured endpoint. On connect or auth failure it closes the socket, logs 'Connect/auth failed for {endpoint}' with the exception, doubles the backoff up to maxBackoffMs, sleeps, and retries. The client eventually succeeds or the caller's timeout/interrupt surfaces the underlying error.
Solutions
- Verify the endpoint host:port is correct and the receiver is listening (`nc -vz host port`).
- Check agent credentials/token against the receiver's current auth config (rotation is the usual culprit).
- Open firewall/security-group rules for the transport port.
- Review backoff logs: repeated failures with growing backoff indicate a persistent config/network problem, not a transient one.
Example fix
// before: wrong port after receiver reconfiguration
transport {
endpoint = "10.0.0.5:5801"
}
// after
transport {
endpoint = "10.0.0.5:5802"
} Defensive patterns
Strategy: retry
Validate before calling
# Validate endpoint and auth before starting the agent nc -zv "$HOST" "$PORT" || echo 'endpoint unreachable' # verify credential freshness ./agent auth verify --endpoint "$ENDPOINT"
Try / catch
try {
client.open();
} catch (IOException e) {
// after repeated 'Connect/auth failed' warnings with max backoff,
// escalate: check endpoint reachability and rotate credentials
alert("transport cannot connect to " + endpoint + ": " + e.getMessage());
} Prevention
- Validate endpoint host:port in agent config at startup.
- Automate credential/token rotation and verify before expiry.
- Open firewall rules for the transport port in every environment.
- Watch backoff patterns: capped max-backoff retries signal persistent config problems.
When it happens
Trigger: open() or sendUntilReceived() -> session establishment fails: TCP connect refused/timed out, or authentication handshake rejected (bad credentials/token, protocol mismatch).
Common situations: Receiver not started or listening on a different port, firewall blocking the port, expired/rotated auth credentials on the agent, or hostname misconfiguration in the endpoint.
Understand the failure class
Background: ECONNREFUSED and "connection refused" / "could not connect to server" errors: what they mean and how to fix them — this error's family across 44 libraries.
Related errors
- Failed to list BigQuery databases (datasets)
- Login failed on server
- accessId and accesskey must be provided when sts_token is…
- AmazonDocumentDB option 'uri' must include authentication…
- AUTH_FAILED
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/5f4208cd8cee85d3.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeTransportClient.java:186
return;
} catch (EdgeSocketCollectorRejectedException ex) {
if (socket != null) {
try {
socket.close();
} catch (IOException closeEx) {
LOG.debug("Error closing socket after REJECTED", closeEx);
}
}
throw ex;
} catch (IOException connectOrAuthEx) {
if (socket != null) {
try {
socket.close();
} catch (IOException closeEx) {
LOG.debug("Error closing socket after connect/auth failure", closeEx);
}
}
LOG.warn("Connect/auth failed for {}", endpoint, connectOrAuthEx);
backoff =
Math.min(
config.getMaxBackoffMs(),
Math.max(backoff, config.getInitialBackoffMs()) * 2);
EdgeTransportConfig.sleepQuiet(backoff);
}
}
throw new IOException(
"Cannot connect to edge ingress "
+ endpoint
+ " after "
+ config.getMaxReconnectCycles()
+ " cycles");
}
private static final class SocketHolder implements AutoCloseable {
private final Socket socket;
private final BufferedReader reader;View on GitHub (pinned to cf67b549a7)