apache/seatunnel · warning

Unauthorized to read config.collections or config.chunks

Error message

Unauthorized to read config.collections or config.chunks: {}, fallback to SampleSplitter.

What it means

When ShardedSplitStrategy reads config.collections/config.chunks the server returned an Unauthorized (code 13) MongoQueryException. The strategy logs this warning and falls back to SampleBucketSplitter because the connected user lacks permission to read the config database.

Solutions

  1. Grant the CDC user a role that can read the config database (e.g. clusterManager or read on config).
  2. Or accept the fallback: configure/keep the SampleSplitter as the intended strategy.
  3. Check with db.runCommand({connectionStatus: 1}) which roles the connector user holds.
  4. On Atlas, assign an Atlas built-in role with config access or use sampling instead.

Example fix

// in mongosh, grant config read
use admin
db.grantRolesToUser("seaTunnelUser", [{role: "clusterManager", db: "admin"}])
Defensive patterns

Strategy: validation

Validate before calling

// verify user can read config db
const ok = db.getSiblingDB('config').collections.findOne({_id: 'mydb.mycoll'});
print(ok ? 'config read OK' : 'config read DENIED');

Prevention

When it happens

Trigger: split() executes readCollectionMetadata/readChunks against a sharded cluster and MongoDB rejects the query with error code 13 (Unauthorized), typically because the user lacks read on the config database.

Common situations: Connecting with a role limited to the target database only (no clusterManager/config read); hosted MongoDB Atlas with restricted roles; security-hardened deployments where config db access is denied to app users.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/d9682bd35517a93b. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-cdc/connector-cdc-mongodb/src/main/java/org/apache/seatunnel/connectors/seatunnel/cdc/mongodb/source/splitters/ShardedSplitStrategy.java:70

    @Override
    public Collection<SnapshotSplit> split(@Nonnull SplitContext splitContext) {
        TableId collectionId = splitContext.getCollectionId();
        MongoClient mongoClient = splitContext.getMongoClient();

        List<BsonDocument> chunks;
        BsonDocument collectionMetadata;
        try {
            collectionMetadata = readCollectionMetadata(mongoClient, collectionId);
            if (!isValidShardedCollection(collectionMetadata)) {
                log.warn(
                        "Collection {} does not appear to be sharded, fallback to SampleSplitter.",
                        collectionId);
                return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
            }
            chunks = readChunks(mongoClient, collectionMetadata);
        } catch (MongoQueryException e) {
            if (e.getErrorCode() == UNAUTHORIZED_ERROR) {
                log.warn(
                        "Unauthorized to read config.collections or config.chunks: {}, fallback to SampleSplitter.",
                        e.getErrorMessage());
            } else {
                log.warn(
                        "Read config.chunks collection failed: {}, fallback to SampleSplitter",
                        e.getErrorMessage());
            }
            return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
        }

        if (chunks.isEmpty()) {
            log.warn(
                    "Collection {} does not appear to be sharded, fallback to SampleSplitter.",
                    collectionId);
            return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
        }

        BsonDocument splitKeys = collectionMetadata.getDocument(SHARD_KEY_FIELD);

View on GitHub (pinned to cf67b549a7)