apache/seatunnel · critical · EdgeSocketCollectorRejectedException

Edge socket authentication rejected (AUTH_FAILED): check…

Error message

Edge socket authentication rejected (AUTH_FAILED): check output token matches EdgeSocket source secret_key

What it means

During the AUTH handshake, handleAuthResponse maps the collector's reply to outcomes: REJECTED means the collector refused this agent, AUTH_FAILED means the presented token did not authenticate. This EdgeSocketCollectorRejectedException with the AUTH_FAILED message signals the client's auth token does not match the EdgeSocket source's secret_key.

Solutions

  1. Set the agent's output token to exactly the EdgeSocket source's secret_key value
  2. Redeploy/restart both jobs after any token rotation so both sides agree
  3. Verify the token has no truncated characters, surrounding quotes, or whitespace in the config
  4. Check that the collector is reading the config file you think it is (right cluster/namespace)

Example fix

# before (agent sink)
token = "tok-old-value"
# source
secret_key = "tok-current-value"
# after
token = "tok-current-value"
secret_key = "tok-current-value"
Defensive patterns

Strategy: validation

Validate before calling

if (!Objects.equals(agentToken, collectorSecretKey)) { throw new IllegalStateException("agent token must equal EdgeSocket source secret_key"); }

Try / catch

try { client.probeReachable(); } catch (EdgeSocketCollectorRejectedException e) { alertOperator("AUTH_FAILED: sync output token with source secret_key"); throw e; }

Prevention

When it happens

Trigger: authenticate() writes the AUTH line with config.getToken(); the collector answers AUTH_FAILED because the token differs from its configured secret_key.

Common situations: output token option on the agent sink and secret_key on the EdgeSocket source configured with different values; token rotated on the server only; copy/paste truncation of the token; trailing whitespace or quoting issues in the config file.

Understand the failure class

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/9ef588fbe22807da. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java:96

                            + ", "
                            + EdgeSocketProtocol.RESP_RETRY
                            + ", or "
                            + EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX
                            + "<ms>)");
        }
        throw new IOException(
                "Exceeded maxBatchSendAttempts="
                        + config.getMaxBatchSendAttempts()
                        + " without RECEIVED for batch "
                        + batchId);
    }

    private static void handleAuthResponse(String reply) throws IOException {
        if (EdgeSocketProtocol.RESP_REJECTED.equals(reply)) {
            throw new EdgeSocketCollectorRejectedException();
        }
        if (EdgeSocketProtocol.RESP_AUTH_FAILED.equals(reply)) {
            throw new EdgeSocketCollectorRejectedException(
                    "Edge socket authentication rejected (AUTH_FAILED): check output token matches"
                            + " EdgeSocket source secret_key");
        }
        if (!EdgeSocketProtocol.RESP_ACK.equals(reply)) {
            throw new IOException(
                    "Unexpected auth response: "
                            + reply
                            + " (expected "
                            + EdgeSocketProtocol.RESP_ACK
                            + " or "
                            + EdgeSocketProtocol.RESP_REJECTED
                            + ")");
        }
    }

    private static long parseQueueFullBackoffMs(String reply) {
        String suffix = reply.substring(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX.length());
        try {

View on GitHub (pinned to cf67b549a7)