apache/seatunnel · critical · IOException

Edge socket ingress decryption failed (DECRYPT_FAILED)…

Error message

Edge socket ingress decryption failed (DECRYPT_FAILED): verify output.aes-secret-key-base64 matches EdgeSocket source secret_key

What it means

After sending a batch, the agent reads the collector's reply; a DECRYPT_FAILED response means the EdgeSocket source on the server side could not decrypt the payload with its AES secret key. The transport converts this protocol reply into an IOException telling the operator that the client's output.aes-secret-key-base64 does not match the server source's secret_key.

Solutions

  1. Compare the client's output.aes-secret-key-base64 with the EdgeSocket source's secret_key and set both to the same base64 AES key
  2. Restart/redeploy both sides after rotating the key so no stale config remains
  3. Verify the key is valid base64 of the expected AES length (16/24/32 bytes) with no stray whitespace
  4. Confirm the encryption mode/version on both sides is compatible

Example fix

# before (sink)
output.aes-secret-key-base64 = "Zx9k...old"
# source
secret_key = "Qw7m...new"
# after: use the identical key on both sides
output.aes-secret-key-base64 = "Qw7m...new"
secret_key = "Qw7m...new"
Defensive patterns

Strategy: validation

Validate before calling

// fail fast at job start if keys differ
if (!Objects.equals(sinkAesKeyBase64, sourceSecretKey)) {
    throw new IllegalStateException("output.aes-secret-key-base64 does not match EdgeSocket source secret_key");
}

Try / catch

try { client.send(batchId, payload); } catch (IOException e) { if (e.getMessage().contains("DECRYPT_FAILED")) { alertOperator("AES key mismatch; fix output.aes-secret-key-base64 vs source secret_key"); throw e; } }

Prevention

When it happens

Trigger: The collector replies with the RESP_DECRYPT_FAILED token after a batch line is written, i.e. the client encrypted the batch payload with an AES key that differs from the EdgeSocket source's secret_key.

Common situations: Sink option output.aes-secret-key-base64 and source option secret_key were generated separately (different base64 keys); key rotated on one side only; whitespace/encoding differences (non-base64, padding) in the configured key; config change not propagated to both jobs after restart.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/b000d7bc4626c3d8. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java:68

            if (EdgeSocketProtocol.RESP_RECEIVED.equals(reply)) {
                return;
            }
            if (EdgeSocketProtocol.RESP_RETRY.equals(reply)) {
                attempts++;
                EdgeTransportConfig.sleepQuiet(
                        EdgeTransportConfig.computeBackoffMillis(
                                attempts - 1,
                                config.getInitialBackoffMs(),
                                config.getMaxBackoffMs()));
                continue;
            }
            if (reply.startsWith(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX)) {
                long waitMs = parseQueueFullBackoffMs(reply);
                EdgeTransportConfig.sleepQuiet(waitMs);
                continue;
            }
            if (EdgeSocketProtocol.RESP_DECRYPT_FAILED.equals(reply)) {
                throw new IOException(
                        "Edge socket ingress decryption failed (DECRYPT_FAILED): verify "
                                + "output.aes-secret-key-base64 matches EdgeSocket source "
                                + "secret_key");
            }
            throw new IOException(
                    "Unexpected batch response: "
                            + reply
                            + " (expected "
                            + EdgeSocketProtocol.RESP_RECEIVED
                            + ", "
                            + EdgeSocketProtocol.RESP_RETRY
                            + ", or "
                            + EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX
                            + "<ms>)");
        }
        throw new IOException(
                "Exceeded maxBatchSendAttempts="
                        + config.getMaxBatchSendAttempts()

View on GitHub (pinned to cf67b549a7)