apache/seatunnel · critical · IOException
Edge socket ingress decryption failed (DECRYPT_FAILED)…
Error message
Edge socket ingress decryption failed (DECRYPT_FAILED): verify output.aes-secret-key-base64 matches EdgeSocket source secret_key
What it means
After sending a batch, the agent reads the collector's reply; a DECRYPT_FAILED response means the EdgeSocket source on the server side could not decrypt the payload with its AES secret key. The transport converts this protocol reply into an IOException telling the operator that the client's output.aes-secret-key-base64 does not match the server source's secret_key.
Solutions
- Compare the client's output.aes-secret-key-base64 with the EdgeSocket source's secret_key and set both to the same base64 AES key
- Restart/redeploy both sides after rotating the key so no stale config remains
- Verify the key is valid base64 of the expected AES length (16/24/32 bytes) with no stray whitespace
- Confirm the encryption mode/version on both sides is compatible
Example fix
# before (sink) output.aes-secret-key-base64 = "Zx9k...old" # source secret_key = "Qw7m...new" # after: use the identical key on both sides output.aes-secret-key-base64 = "Qw7m...new" secret_key = "Qw7m...new"
Defensive patterns
Strategy: validation
Validate before calling
// fail fast at job start if keys differ
if (!Objects.equals(sinkAesKeyBase64, sourceSecretKey)) {
throw new IllegalStateException("output.aes-secret-key-base64 does not match EdgeSocket source secret_key");
} Try / catch
try { client.send(batchId, payload); } catch (IOException e) { if (e.getMessage().contains("DECRYPT_FAILED")) { alertOperator("AES key mismatch; fix output.aes-secret-key-base64 vs source secret_key"); throw e; } } Prevention
- Generate one AES key and copy it verbatim into both sink and source configs
- Base64-decode the key locally once to confirm it is valid 16/24/32-byte AES material
- Redeploy both sides together after any key rotation
- Strip whitespace/quotes from key values in config files
When it happens
Trigger: The collector replies with the RESP_DECRYPT_FAILED token after a batch line is written, i.e. the client encrypted the batch payload with an AES key that differs from the EdgeSocket source's secret_key.
Common situations: Sink option output.aes-secret-key-base64 and source option secret_key were generated separately (different base64 keys); key rotated on one side only; whitespace/encoding differences (non-base64, padding) in the configured key; config change not propagated to both jobs after restart.
Related errors
- Edge socket authentication rejected (AUTH_FAILED): check…
- Can't find column in table.
- CATALOG_TABLE_SIZE_IS_ERROR
- Collector authentication timeout from
- Edge socket receiver loop exception, retrying
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/b000d7bc4626c3d8.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java:68
if (EdgeSocketProtocol.RESP_RECEIVED.equals(reply)) {
return;
}
if (EdgeSocketProtocol.RESP_RETRY.equals(reply)) {
attempts++;
EdgeTransportConfig.sleepQuiet(
EdgeTransportConfig.computeBackoffMillis(
attempts - 1,
config.getInitialBackoffMs(),
config.getMaxBackoffMs()));
continue;
}
if (reply.startsWith(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX)) {
long waitMs = parseQueueFullBackoffMs(reply);
EdgeTransportConfig.sleepQuiet(waitMs);
continue;
}
if (EdgeSocketProtocol.RESP_DECRYPT_FAILED.equals(reply)) {
throw new IOException(
"Edge socket ingress decryption failed (DECRYPT_FAILED): verify "
+ "output.aes-secret-key-base64 matches EdgeSocket source "
+ "secret_key");
}
throw new IOException(
"Unexpected batch response: "
+ reply
+ " (expected "
+ EdgeSocketProtocol.RESP_RECEIVED
+ ", "
+ EdgeSocketProtocol.RESP_RETRY
+ ", or "
+ EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX
+ "<ms>)");
}
throw new IOException(
"Exceeded maxBatchSendAttempts="
+ config.getMaxBatchSendAttempts()View on GitHub (pinned to cf67b549a7)