apache/seatunnel · error · IllegalArgumentException
paimon privilege is enabled, user and password is required
Error message
paimon privilege is enabled, user and password is required
What it means
PaimonCatalogLoader.loadCatalog creates the Paimon catalog and, if the resulting catalog is a PrivilegedCatalog (Paimon privilege/access-control enabled), verifies that user and password were supplied. When both are blank it throws IllegalArgumentException stating that user and password are required. Paimon privilege mode authenticates every operation, so anonymous access is rejected before any table operation runs.
Solutions
- Set the paimon.user (USER) and paimon.password (PASSWORD) options in the SeaTunnel catalog/source/sink configuration.
- Check the Paimon conf used via paimon-conf-dir/warehouse settings: if privilege is intentionally off, disable it so PrivilegedCatalog is not created.
- Ensure values are non-blank (no whitespace-only strings) and valid for the Paimon privilege system.
- If credentials come from a secrets manager, verify the substitution actually produced non-empty values.
Example fix
// before
Paimon {
warehouse = "hdfs://ns/paimon"
}
// after
Paimon {
warehouse = "hdfs://ns/paimon"
user = "etl_user"
password = "${PAIMON_PASSWORD}"
} Defensive patterns
Strategy: validation
Validate before calling
String user = options.get(PaimonBaseOptions.USER);
String password = options.get(PaimonBaseOptions.PASSWORD);
if (privilegeEnabled && (isBlank(user) || isBlank(password))) {
throw new ConfigValidationException("paimon user/password required");
} Try / catch
try {
Catalog c = loader.loadCatalog();
} catch (IllegalArgumentException e) {
if (e.getMessage().contains("user and password is required")) {
throw new ConfigException("add paimon user/password options");
}
throw e;
} Prevention
- Always set user and password options when Paimon access control is on
- Keep credentials in connector options, not only paimon-conf
- Inject secrets via env vars and verify they resolve
- Document privilege requirements when migrating clusters
When it happens
Trigger: Creating a PaimonCatalogLoader/catalog where the Paimon conf enables its privilege/access-control layer (PrivilegedCatalog is instantiated) but the SeaTunnel options PaimonBaseOptions.USER and PaimonBaseOptions.PASSWORD are unset or empty strings.
Common situations: Migrating a SeaTunnel job from a privilege-free Paimon cluster to one with access control enabled; user/password configured in paimon-conf instead of the SeaTunnel options (they must be in the connector options); blanks/whitespace-only values.
Related errors
- AzureCosmosDB requires key, primary_key, secondary_key, or…
- Database already exists in catalog
- Database does not exist in catalog
- LOAD_CATALOG
- Table already exists in catalog
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/4a2b316e72d30dd5.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-paimon/src/main/java/org/apache/seatunnel/connectors/seatunnel/paimon/catalog/PaimonCatalogLoader.java:115
optionsMap.put(CatalogOptions.URI.key(), catalogUri);
optionsMap.putAll(paimonHadoopConfiguration.getPropsWithPrefix(StringUtils.EMPTY));
}
final Options options = Options.fromMap(optionsMap);
PaimonSecurityContext.shouldEnableKerberos(paimonHadoopConfiguration);
final CatalogContext catalogContext =
CatalogContext.create(options, paimonHadoopConfiguration);
try {
// If paimon privilege enabled, there will be system tables named user.sys and
// privilege.sys in the warehouse.
// It returns a PrivilegedCatalog. Otherwise, it returns a CachingCatalog.
// If paimon privilege enabled, perform user and password verification accordingly.
Catalog catalog =
PaimonSecurityContext.runSecured(
() -> CatalogFactory.createCatalog(catalogContext));
if (catalog instanceof PrivilegedCatalog
&& StringUtils.isBlank(user)
&& StringUtils.isBlank(password)) {
throw new IllegalArgumentException(
"paimon privilege is enabled, user and password is required");
}
return catalog;
} catch (Exception e) {
throw new PaimonConnectorException(
PaimonConnectorErrorCode.LOAD_CATALOG, e.getMessage(), e);
}
}
void checkConfiguration(Configuration configuration, String key) {
Iterator<Map.Entry<String, String>> entryIterator = configuration.iterator();
while (entryIterator.hasNext()) {
Map.Entry<String, String> entry = entryIterator.next();
if (entry.getKey().equals(key)) {
if (StringUtils.isBlank(entry.getValue())) {
throw new IllegalArgumentException("The value of" + key + " is required");
}
return;View on GitHub (pinned to cf67b549a7)