{"record":{"id":"0a9a94b4299a08e2","repo":"apache/seatunnel","slug":"failed-to-s-config-please-check-your-configurati","errorCode":null,"errorMessage":"Failed to %s config. Please check your configuration.","messagePattern":"Failed to (.+?) config\\. Please check your configuration\\.","errorType":"validation","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"seatunnel-core/seatunnel-core-starter/src/main/java/org/apache/seatunnel/core/starter/utils/ConfigShadeUtils.java","lineNumber":231,"sourceCode":"            transforms.forEach(\n                    transform -> {\n                        for (String sensitiveOption : sensitiveOptions) {\n                            transform.computeIfPresent(sensitiveOption, processFunction);\n                        }\n                    });\n            configMap.put(Constants.SOURCE, sources);\n            configMap.put(Constants.SINK, sinks);\n            configMap.put(Constants.TRANSFORM, transforms);\n            return ConfigFactory.parseMap(configMap);\n        } catch (Exception e) {\n            // Log desensitized error information\n            log.error(\n                    \"Failed to {} config with identifier: {}\",\n                    isDecrypted ? \"decrypt\" : \"encrypt\",\n                    identifier,\n                    e);\n            // Rethrow exception without sensitive information\n            throw new IllegalArgumentException(\n                    String.format(\n                            \"Failed to %s config. Please check your configuration.\",\n                            isDecrypted ? \"decrypt\" : \"encrypt\"),\n                    e);\n        }\n    }\n\n    public static Set<String> getSensitiveOptions(Config config) {\n        Set<String> sensitiveOptions =\n                new HashSet<>(\n                        TypesafeConfigUtils.getConfig(\n                                config != null && config.hasPath(Constants.ENV)\n                                        ? config.getConfig(Constants.ENV)\n                                        : ConfigFactory.empty(),\n                                SHADE_OPTIONS_OPTION,\n                                new ArrayList<>()));\n        sensitiveOptions.addAll(Arrays.asList(DEFAULT_SENSITIVE_KEYWORDS));\n        return sensitiveOptions;","sourceCodeStart":213,"sourceCodeEnd":249,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-core/seatunnel-core-starter/src/main/java/org/apache/seatunnel/core/starter/utils/ConfigShadeUtils.java#L213-L249","documentation":"ConfigShadeUtils.processConfig applies a config encryption/decryption plugin identified by 'shade.identifier'. When the plugin throws, it logs the real cause but rethrows an IllegalArgumentException with a sanitized message so sensitive material never leaks, appending the original exception as the cause.","triggerScenarios":"Calling encryptConfig/decryptConfig on a config whose shade.identifier names a plugin that fails (e.g. unknown identifier, wrong base64 data, bad key/algorithm config).","commonSituations":"Typo'd shade.identifier (e.g. 'base64' vs 'base64Decode'), encrypting a password with a different plugin than used to decrypt, malformed encrypted values in the HOCON file.","solutions":["Verify shade.identifier matches the plugin actually used to encrypt the values","Re-encrypt the sensitive values with the same identifier/algorithm","Check the cause exception (logged server-side) for the underlying crypto error"],"exampleFix":"// before\nenv { shade.identifier = \"base64\" }  # but values were encrypted with aes\n// after\nenv { shade.identifier = \"aes\" }  # or re-encrypt values using base64","handlingStrategy":"try-catch","validationCode":"// verify identifier is known before processing\nSet<String> known = Set.of(\"base64\", \"aes\", \"sm4\", \"none\"); if (!known.contains(shadeIdentifier)) throw new IllegalArgumentException(\"Unknown shade.identifier: \" + shadeIdentifier);","typeGuard":null,"tryCatchPattern":"try { decryptConfig(config); } catch (IllegalArgumentException e) { log.error(\"Shade processing failed: {}\", e.getMessage(), e.getCause()); }","preventionTips":["Keep shade.identifier consistent between encrypt and decrypt steps","Round-trip test encrypted values in CI","Never log decrypted content or keys"],"tags":["config","encryption","decryption"],"backgroundTag":"invalid-config-value","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}