apache/seatunnel · error · IllegalArgumentException

paimon privilege is enabled, user and password is required

Error message

paimon privilege is enabled, user and password is required

What it means

PaimonCatalogLoader.loadCatalog creates the Paimon catalog and, if the resulting catalog is a PrivilegedCatalog (Paimon privilege/access-control enabled), verifies that user and password were supplied. When both are blank it throws IllegalArgumentException stating that user and password are required. Paimon privilege mode authenticates every operation, so anonymous access is rejected before any table operation runs.

Solutions

  1. Set the paimon.user (USER) and paimon.password (PASSWORD) options in the SeaTunnel catalog/source/sink configuration.
  2. Check the Paimon conf used via paimon-conf-dir/warehouse settings: if privilege is intentionally off, disable it so PrivilegedCatalog is not created.
  3. Ensure values are non-blank (no whitespace-only strings) and valid for the Paimon privilege system.
  4. If credentials come from a secrets manager, verify the substitution actually produced non-empty values.

Example fix

// before
Paimon {
  warehouse = "hdfs://ns/paimon"
}
// after
Paimon {
  warehouse = "hdfs://ns/paimon"
  user = "etl_user"
  password = "${PAIMON_PASSWORD}"
}
Defensive patterns

Strategy: validation

Validate before calling

String user = options.get(PaimonBaseOptions.USER);
String password = options.get(PaimonBaseOptions.PASSWORD);
if (privilegeEnabled && (isBlank(user) || isBlank(password))) {
    throw new ConfigValidationException("paimon user/password required");
}

Try / catch

try {
    Catalog c = loader.loadCatalog();
} catch (IllegalArgumentException e) {
    if (e.getMessage().contains("user and password is required")) {
        throw new ConfigException("add paimon user/password options");
    }
    throw e;
}

Prevention

When it happens

Trigger: Creating a PaimonCatalogLoader/catalog where the Paimon conf enables its privilege/access-control layer (PrivilegedCatalog is instantiated) but the SeaTunnel options PaimonBaseOptions.USER and PaimonBaseOptions.PASSWORD are unset or empty strings.

Common situations: Migrating a SeaTunnel job from a privilege-free Paimon cluster to one with access control enabled; user/password configured in paimon-conf instead of the SeaTunnel options (they must be in the connector options); blanks/whitespace-only values.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/4a2b316e72d30dd5. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-paimon/src/main/java/org/apache/seatunnel/connectors/seatunnel/paimon/catalog/PaimonCatalogLoader.java:115

            optionsMap.put(CatalogOptions.URI.key(), catalogUri);
            optionsMap.putAll(paimonHadoopConfiguration.getPropsWithPrefix(StringUtils.EMPTY));
        }
        final Options options = Options.fromMap(optionsMap);
        PaimonSecurityContext.shouldEnableKerberos(paimonHadoopConfiguration);
        final CatalogContext catalogContext =
                CatalogContext.create(options, paimonHadoopConfiguration);
        try {
            // If paimon privilege enabled, there will be system tables named user.sys and
            // privilege.sys in the warehouse.
            // It returns a PrivilegedCatalog. Otherwise, it returns a CachingCatalog.
            // If paimon privilege enabled, perform user and password verification accordingly.
            Catalog catalog =
                    PaimonSecurityContext.runSecured(
                            () -> CatalogFactory.createCatalog(catalogContext));
            if (catalog instanceof PrivilegedCatalog
                    && StringUtils.isBlank(user)
                    && StringUtils.isBlank(password)) {
                throw new IllegalArgumentException(
                        "paimon privilege is enabled, user and password is required");
            }
            return catalog;
        } catch (Exception e) {
            throw new PaimonConnectorException(
                    PaimonConnectorErrorCode.LOAD_CATALOG, e.getMessage(), e);
        }
    }

    void checkConfiguration(Configuration configuration, String key) {
        Iterator<Map.Entry<String, String>> entryIterator = configuration.iterator();
        while (entryIterator.hasNext()) {
            Map.Entry<String, String> entry = entryIterator.next();
            if (entry.getKey().equals(key)) {
                if (StringUtils.isBlank(entry.getValue())) {
                    throw new IllegalArgumentException("The value of" + key + " is required");
                }
                return;

View on GitHub (pinned to cf67b549a7)