apache/seatunnel · critical · EdgeSocketCollectorRejectedException
Edge socket authentication rejected (AUTH_FAILED): check…
Error message
Edge socket authentication rejected (AUTH_FAILED): check output token matches EdgeSocket source secret_key
What it means
During the AUTH handshake, handleAuthResponse maps the collector's reply to outcomes: REJECTED means the collector refused this agent, AUTH_FAILED means the presented token did not authenticate. This EdgeSocketCollectorRejectedException with the AUTH_FAILED message signals the client's auth token does not match the EdgeSocket source's secret_key.
Solutions
- Set the agent's output token to exactly the EdgeSocket source's secret_key value
- Redeploy/restart both jobs after any token rotation so both sides agree
- Verify the token has no truncated characters, surrounding quotes, or whitespace in the config
- Check that the collector is reading the config file you think it is (right cluster/namespace)
Example fix
# before (agent sink) token = "tok-old-value" # source secret_key = "tok-current-value" # after token = "tok-current-value" secret_key = "tok-current-value"
Defensive patterns
Strategy: validation
Validate before calling
if (!Objects.equals(agentToken, collectorSecretKey)) { throw new IllegalStateException("agent token must equal EdgeSocket source secret_key"); } Try / catch
try { client.probeReachable(); } catch (EdgeSocketCollectorRejectedException e) { alertOperator("AUTH_FAILED: sync output token with source secret_key"); throw e; } Prevention
- Deploy token and secret_key from one shared secret source
- Rotate tokens on both sides in the same change window
- Validate tokens with a lightweight auth probe before production sends
- Watch for config quoting/whitespace corrupting token values
When it happens
Trigger: authenticate() writes the AUTH line with config.getToken(); the collector answers AUTH_FAILED because the token differs from its configured secret_key.
Common situations: output token option on the agent sink and secret_key on the EdgeSocket source configured with different values; token rotated on the server only; copy/paste truncation of the token; trailing whitespace or quoting issues in the config file.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Collector authentication timeout from
- Edge socket ingress decryption failed (DECRYPT_FAILED)…
- Unexpected auth response
- accessId and accesskey must be provided when sts_token is…
- AmazonDocumentDB option 'uri' must include authentication…
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/9ef588fbe22807da.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java:96
+ ", "
+ EdgeSocketProtocol.RESP_RETRY
+ ", or "
+ EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX
+ "<ms>)");
}
throw new IOException(
"Exceeded maxBatchSendAttempts="
+ config.getMaxBatchSendAttempts()
+ " without RECEIVED for batch "
+ batchId);
}
private static void handleAuthResponse(String reply) throws IOException {
if (EdgeSocketProtocol.RESP_REJECTED.equals(reply)) {
throw new EdgeSocketCollectorRejectedException();
}
if (EdgeSocketProtocol.RESP_AUTH_FAILED.equals(reply)) {
throw new EdgeSocketCollectorRejectedException(
"Edge socket authentication rejected (AUTH_FAILED): check output token matches"
+ " EdgeSocket source secret_key");
}
if (!EdgeSocketProtocol.RESP_ACK.equals(reply)) {
throw new IOException(
"Unexpected auth response: "
+ reply
+ " (expected "
+ EdgeSocketProtocol.RESP_ACK
+ " or "
+ EdgeSocketProtocol.RESP_REJECTED
+ ")");
}
}
private static long parseQueueFullBackoffMs(String reply) {
String suffix = reply.substring(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX.length());
try {View on GitHub (pinned to cf67b549a7)