apache/seatunnel · error · IllegalArgumentException
Failed to config. Please check your configuration.
Error message
Failed to %s config. Please check your configuration.
What it means
ConfigShadeUtils.processConfig applies a config encryption/decryption plugin identified by 'shade.identifier'. When the plugin throws, it logs the real cause but rethrows an IllegalArgumentException with a sanitized message so sensitive material never leaks, appending the original exception as the cause.
Solutions
- Verify shade.identifier matches the plugin actually used to encrypt the values
- Re-encrypt the sensitive values with the same identifier/algorithm
- Check the cause exception (logged server-side) for the underlying crypto error
Example fix
// before
env { shade.identifier = "base64" } # but values were encrypted with aes
// after
env { shade.identifier = "aes" } # or re-encrypt values using base64 Defensive patterns
Strategy: try-catch
Validate before calling
// verify identifier is known before processing
Set<String> known = Set.of("base64", "aes", "sm4", "none"); if (!known.contains(shadeIdentifier)) throw new IllegalArgumentException("Unknown shade.identifier: " + shadeIdentifier); Try / catch
try { decryptConfig(config); } catch (IllegalArgumentException e) { log.error("Shade processing failed: {}", e.getMessage(), e.getCause()); } Prevention
- Keep shade.identifier consistent between encrypt and decrypt steps
- Round-trip test encrypted values in CI
- Never log decrypted content or keys
When it happens
Trigger: Calling encryptConfig/decryptConfig on a config whose shade.identifier names a plugin that fails (e.g. unknown identifier, wrong base64 data, bad key/algorithm config).
Common situations: Typo'd shade.identifier (e.g. 'base64' vs 'base64Decode'), encrypting a password with a different plugin than used to decrypt, malformed encrypted values in the HOCON file.
Understand the failure class
Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.
Related errors
- Invalid secret_key: not Base64 encoded
- PACKET_AES_KEY_MISSING
- transport.aes-secret-key-base64 is required when…
- Unknown encryption
- Unsupported encryption type
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/0a9a94b4299a08e2.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-core/seatunnel-core-starter/src/main/java/org/apache/seatunnel/core/starter/utils/ConfigShadeUtils.java:231
transforms.forEach(
transform -> {
for (String sensitiveOption : sensitiveOptions) {
transform.computeIfPresent(sensitiveOption, processFunction);
}
});
configMap.put(Constants.SOURCE, sources);
configMap.put(Constants.SINK, sinks);
configMap.put(Constants.TRANSFORM, transforms);
return ConfigFactory.parseMap(configMap);
} catch (Exception e) {
// Log desensitized error information
log.error(
"Failed to {} config with identifier: {}",
isDecrypted ? "decrypt" : "encrypt",
identifier,
e);
// Rethrow exception without sensitive information
throw new IllegalArgumentException(
String.format(
"Failed to %s config. Please check your configuration.",
isDecrypted ? "decrypt" : "encrypt"),
e);
}
}
public static Set<String> getSensitiveOptions(Config config) {
Set<String> sensitiveOptions =
new HashSet<>(
TypesafeConfigUtils.getConfig(
config != null && config.hasPath(Constants.ENV)
? config.getConfig(Constants.ENV)
: ConfigFactory.empty(),
SHADE_OPTIONS_OPTION,
new ArrayList<>()));
sensitiveOptions.addAll(Arrays.asList(DEFAULT_SENSITIVE_KEYWORDS));
return sensitiveOptions;View on GitHub (pinned to cf67b549a7)