apache/seatunnel · warning
Unauthorized to execute splitVector command
Error message
Unauthorized to execute splitVector command: {}, fallback to SampleSplitter What it means
SplitVectorSplitStrategy runs the splitVector command to compute chunk-sized split keys. If MongoDB rejects the command with error code 13 (Unauthorized) via MongoCommandException, the strategy logs this warning and falls back to SampleBucketSplitter. The user lacks privileges to execute splitVector on the collection.
Solutions
- Grant the connector user privileges to run splitVector (e.g. clusterManager role or a custom role with splitVector action).
- Or select the SampleSplitter strategy explicitly instead of splitVector.
- Test manually: db.runCommand({splitVector: "db.coll", keyPattern: {...}, maxChunkSizeBytes: N}).
- Note some managed services disallow splitVector entirely — use sampling there.
Example fix
// mongosh: grant splitVector-capable role
use admin
db.grantRolesToUser("seaTunnelUser", [{role: "clusterManager", db: "admin"}]) Defensive patterns
Strategy: validation
Validate before calling
// mongosh: probe splitVector privilege upfront
const r = db.runCommand({splitVector: 'mydb.mycoll', keyPattern: {userId: 1}, maxChunkSizeBytes: 64*1024*1024});
print('ok=' + r.ok + ' errmsg=' + (r.errmsg || '')); Prevention
- Grant splitVector privilege (or clusterManager role) to the CDC user.
- On managed services that block splitVector, choose the SampleSplitter strategy by default.
- Pre-flight the command in mongosh with the exact keyPattern/chunk size.
When it happens
Trigger: split() calls splitVector(...) and the server responds with MongoCommandException errorCode == 13, e.g. user without splitVector privilege on the target namespace.
Common situations: Minimal-privilege users that can read data but not run admin/diagnostic commands; splitVector requires specific privileges often missing for app users; restricted deployments (Atlas, managed services) blocking splitVector.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Execute splitVector command failed
- Unauthorized to read config.collections or config.chunks
- Cannot extract clusterTime from change stream event…
- Change stream cursor has expired, trying to recreate cursor
- Collection does not appear to be sharded, fallback to…
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/a2984334295bb171.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-cdc/connector-cdc-mongodb/src/main/java/org/apache/seatunnel/connectors/seatunnel/cdc/mongodb/source/splitters/SplitVectorSplitStrategy.java:67
@Slf4j
public enum SplitVectorSplitStrategy implements SplitStrategy {
INSTANCE;
@Override
public Collection<SnapshotSplit> split(@Nonnull SplitContext splitContext) {
MongoClient mongoClient = splitContext.getMongoClient();
TableId collectionId = splitContext.getCollectionId();
int chunkSizeMB = splitContext.getChunkSizeMB();
BsonDocument keyPattern = new BsonDocument(ID_FIELD, new BsonInt32(1));
BsonDocument splitResult;
try {
splitResult = splitVector(mongoClient, collectionId, keyPattern, chunkSizeMB);
} catch (MongoCommandException e) {
if (e.getErrorCode() == UNAUTHORIZED_ERROR) {
log.warn(
"Unauthorized to execute splitVector command: {}, fallback to SampleSplitter",
e.getErrorMessage());
} else {
log.warn(
"Execute splitVector command failed: {}, fallback to SampleSplitter",
e.getErrorMessage());
}
return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
}
if (!isCommandSucceed(splitResult)) {
log.warn(
"Could not calculate standalone splits: {}, fallback to SampleSplitter",
splitResult.getString("errmsg"));
return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
}
BsonArray splitKeys = splitResult.getArray("splitKeys");View on GitHub (pinned to cf67b549a7)