apache/seatunnel · warning
Unauthorized to read config.collections or config.chunks
Error message
Unauthorized to read config.collections or config.chunks: {}, fallback to SampleSplitter. What it means
When ShardedSplitStrategy reads config.collections/config.chunks the server returned an Unauthorized (code 13) MongoQueryException. The strategy logs this warning and falls back to SampleBucketSplitter because the connected user lacks permission to read the config database.
Solutions
- Grant the CDC user a role that can read the config database (e.g. clusterManager or read on config).
- Or accept the fallback: configure/keep the SampleSplitter as the intended strategy.
- Check with db.runCommand({connectionStatus: 1}) which roles the connector user holds.
- On Atlas, assign an Atlas built-in role with config access or use sampling instead.
Example fix
// in mongosh, grant config read
use admin
db.grantRolesToUser("seaTunnelUser", [{role: "clusterManager", db: "admin"}]) Defensive patterns
Strategy: validation
Validate before calling
// verify user can read config db
const ok = db.getSiblingDB('config').collections.findOne({_id: 'mydb.mycoll'});
print(ok ? 'config read OK' : 'config read DENIED'); Prevention
- Grant clusterManager (or config-read) role to the CDC user at provisioning time.
- Test permissions with a minimal query on config.collections before running the job.
- Prefer explicit SampleSplitter config when config-db access is intentionally restricted.
When it happens
Trigger: split() executes readCollectionMetadata/readChunks against a sharded cluster and MongoDB rejects the query with error code 13 (Unauthorized), typically because the user lacks read on the config database.
Common situations: Connecting with a role limited to the target database only (no clusterManager/config read); hosted MongoDB Atlas with restricted roles; security-hardened deployments where config db access is denied to app users.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Collection does not appear to be sharded, fallback to…
- Read config.chunks collection failed
- Unauthorized to execute splitVector command
- Cannot extract clusterTime from change stream event…
- Change stream cursor has expired, trying to recreate cursor
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/d9682bd35517a93b.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-cdc/connector-cdc-mongodb/src/main/java/org/apache/seatunnel/connectors/seatunnel/cdc/mongodb/source/splitters/ShardedSplitStrategy.java:70
@Override
public Collection<SnapshotSplit> split(@Nonnull SplitContext splitContext) {
TableId collectionId = splitContext.getCollectionId();
MongoClient mongoClient = splitContext.getMongoClient();
List<BsonDocument> chunks;
BsonDocument collectionMetadata;
try {
collectionMetadata = readCollectionMetadata(mongoClient, collectionId);
if (!isValidShardedCollection(collectionMetadata)) {
log.warn(
"Collection {} does not appear to be sharded, fallback to SampleSplitter.",
collectionId);
return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
}
chunks = readChunks(mongoClient, collectionMetadata);
} catch (MongoQueryException e) {
if (e.getErrorCode() == UNAUTHORIZED_ERROR) {
log.warn(
"Unauthorized to read config.collections or config.chunks: {}, fallback to SampleSplitter.",
e.getErrorMessage());
} else {
log.warn(
"Read config.chunks collection failed: {}, fallback to SampleSplitter",
e.getErrorMessage());
}
return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
}
if (chunks.isEmpty()) {
log.warn(
"Collection {} does not appear to be sharded, fallback to SampleSplitter.",
collectionId);
return SampleBucketSplitStrategy.INSTANCE.split(splitContext);
}
BsonDocument splitKeys = collectionMetadata.getDocument(SHARD_KEY_FIELD);View on GitHub (pinned to cf67b549a7)