apache/seatunnel · error · EdgeSocketConnectorException
DECRYPT_FAILED
DECRYPT_FAILED
Error message
Decryption failed for batchId={}, check secret_key configuration What it means
WARN log in handleBatchRecord's EdgeSocketConnectorException branch when isDecryptionError() matched, meaning the batch payload could not be decrypted — almost always a secret_key mismatch between the edge sender and the connector. The batch is rejected with the DECRYPT_FAILED response code rather than failing the task, since it is a per-batch data error.
Solutions
- Verify secret_key in the EdgeSocket source config exactly matches the key used by the sending device (byte-for-byte, no stray whitespace)
- Roll out coordinated key rotation: update devices and connector together, or support overlap of old/new keys temporarily
- Confirm the device encryption algorithm/mode matches what the connector's decryptor implements
- Test with an unencrypted batch (device encryption disabled) to isolate whether decryption or encoding is at fault
- Inspect the logged connectorException stack trace for the precise crypto error (bad key size vs bad padding)
Example fix
# before: mismatched key secret_key = "st-old-shared-key" # after: key matching the edge device's current key secret_key = "st-current-shared-key-2024"
Defensive patterns
Strategy: validation
Validate before calling
// sender-side sanity: key configured and non-empty, same length as receiver key
if (secretKey == null || secretKey.isEmpty()) throw new IllegalStateException("secret_key not set");
if (secretKey.length() != expectedKeyLength) throw new IllegalStateException("key size mismatch"); Try / catch
// sender: treat DECRYPT_FAILED as fatal config error, stop retrying with same key
if ("DECRYPT_FAILED".equals(responseCode)) {
log.error("Receiver rejected key; verify secret_key parity before resending");
throw new ConfigurationException("secret_key mismatch with connector");
} Prevention
- Keep device and connector keys in one source of truth / secret store
- Test decryption with a canary batch after any key rotation
- Avoid trailing whitespace/encoding drift in key config values
When it happens
Trigger: handleBatchRecord -> decode path throws EdgeSocketConnectorException classified as a decryption error (wrong/rotated AES key, corrupted ciphertext, key not configured while payload is encrypted).
Common situations: secret_key changed on the connector but edge devices still use the old key (or vice versa); different devices provisioned with different keys; payload encrypted with a different algorithm/IV scheme than the connector expects; secret_key whitespace/encoding differences between config and device.
Understand the failure class
Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.
Related errors
- DECODE_FAILED
- Failed to config. Please check your configuration.
- Ingress queue at backpressure watermark, returning…
- Ingress queue physically full, returning RETRY
- SHA-256 is not supported by this JVM
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/88115a740ddfb9c9.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/source/EdgeSocketSourceReader.java:203
if (offerResult == QueueOfferResult.ACCEPTED) {
sourceState.markRecordReceived(batchId);
return EdgeSocketResponseCode.RECEIVED.getCode();
}
}
queueFullCount++;
if (queueFullCount == 1 || queueFullCount % 100 == 0) {
log.warn(
"Ingress queue physically full, returning RETRY "
+ "(capacity={}, rejectCount={}, batchId={})",
config.getLocalQueueCapacity(),
queueFullCount,
batchId);
}
return EdgeSocketResponseCode.RETRY.getCode();
} catch (EdgeSocketConnectorException connectorException) {
if (isDecryptionError(connectorException)) {
log.warn(
"Decryption failed for batchId={}, check secret_key configuration",
batchId,
connectorException);
return EdgeSocketResponseCode.DECRYPT_FAILED.getCode();
}
log.warn("Decode ingress packet failed for batchId={}", batchId, connectorException);
return EdgeSocketResponseCode.DECODE_FAILED.getCode();
} catch (Exception decodeException) {
log.warn("Decode or enqueue ingress packet failed", decodeException);
return EdgeSocketResponseCode.DECODE_FAILED.getCode();
}
}
@Override
public String handleCommitRequest(long batchId) {
synchronized (stateLock) {
return sourceState.resolveCommitResponse(batchId);
}
}View on GitHub (pinned to cf67b549a7)