{"record":{"id":"1f086561f2928770","repo":"apache/seatunnel","slug":"python-source-is-disabled-by-the-server-side-secur","errorCode":null,"errorMessage":"Python source is disabled by the server-side security policy. Set -D{}=true and configure -D{} with absolute interpreter paths on every worker node.","messagePattern":"Python source is disabled by the server-side security policy\\. Set -D(.+?)=true and configure -D(.+?) with absolute interpreter paths on every worker node\\.","errorType":"exception","errorClass":"IllegalStateException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-python/src/main/java/org/apache/seatunnel/connectors/seatunnel/python/source/PythonSourceExecutionPolicy.java","lineNumber":65,"sourceCode":"            if (sameExecutablePath(resolvedExecutable, allowedExecutable)) {\n                return resolvedExecutable;\n            }\n        }\n        throw new IllegalStateException(\n                \"Python source executable \"\n                        + resolvedExecutable\n                        + \" is not listed in server property \"\n                        + PYTHON_ALLOWED_EXECUTABLES_PROPERTY\n                        + \"=\"\n                        + allowedExecutables);\n    }\n\n    private static void ensureEnabled() {\n        if (Boolean.parseBoolean(\n                System.getProperty(PYTHON_SOURCE_ENABLED_PROPERTY, Boolean.FALSE.toString()))) {\n            return;\n        }\n        throw new IllegalStateException(\n                \"Python source is disabled by the server-side security policy. Set -D\"\n                        + PYTHON_SOURCE_ENABLED_PROPERTY\n                        + \"=true and configure -D\"\n                        + PYTHON_ALLOWED_EXECUTABLES_PROPERTY\n                        + \" with absolute interpreter paths on every worker node.\");\n    }\n\n    private static List<Path> parseAllowedExecutables() {\n        String rawAllowlist = System.getProperty(PYTHON_ALLOWED_EXECUTABLES_PROPERTY, \"\");\n        if (rawAllowlist.trim().isEmpty()) {\n            throw new IllegalStateException(\n                    \"Server property \"\n                            + PYTHON_ALLOWED_EXECUTABLES_PROPERTY\n                            + \" must contain at least one absolute executable path\");\n        }\n        Set<Path> allowedExecutables = new LinkedHashSet<>();\n        for (String rawEntry : rawAllowlist.split(\",\")) {\n            String entry = rawEntry.trim();","sourceCodeStart":47,"sourceCodeEnd":83,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-python/src/main/java/org/apache/seatunnel/connectors/seatunnel/python/source/PythonSourceExecutionPolicy.java#L47-L83","documentation":"PythonSourceExecutionPolicy.ensureEnabled throws this IllegalStateException when the system property PYTHON_SOURCE_ENABLED_PROPERTY is not set to true. The Python source is opt-in and disabled by default as a server-side security policy; enabling also requires configuring the allowed-executables property with absolute interpreter paths on every worker node.","triggerScenarios":"Submitting a job using the Python source when the cluster JVMs were started without -Dpython.source.enabled=true; ensureEnabled runs as part of resolveExecutable before any subprocess launch.","commonSituations":"Fresh cluster deployment where the security properties were never added to JVM options; enabling on the client but forgetting worker nodes; properties set in one config file (e.g. seatunnel-env) but not in the actual JVM start script.","solutions":["Start every node's JVM with -Dpython.source.enabled=true (or the documented property name).","Also set -Dpython.allowed.executables=/abs/path/python3 with absolute interpreter paths on every worker.","Put both properties in the server JVM options file so restarts keep them (e.g. JVM options in seatunnel.sh/env config).","If you do not need the Python source, remove it from the job instead of enabling it cluster-wide.","Verify with a small test job after restart; the properties are read at runtime via System.getProperty, so no rebuild is needed."],"exampleFix":"// before\n./bin/seatunnel-cluster.sh  # python source disabled\n// after\nJAVA_OPTS=\"-Dpython.source.enabled=true -Dpython.allowed.executables=/usr/bin/python3\" \\\n  ./bin/seatunnel-cluster.sh","handlingStrategy":"validation","validationCode":"// Java: preflight before submitting a Python-source job\nboolean enabled = Boolean.parseBoolean(\n    System.getProperty(\"python.source.enabled\", \"false\"));\nif (!enabled) {\n    throw new IllegalStateException(\n        \"Python source disabled: start workers with -Dpython.source.enabled=true \"\n        + \"and -Dpython.allowed.executables=<abs paths>\");\n}","typeGuard":null,"tryCatchPattern":"try { source.prepare(...); } catch (IllegalStateException e) { if (e.getMessage().contains(\"disabled by the server-side security policy\")) { LOG.error(\"Enable via JVM properties on every worker\", e); } }","preventionTips":["Add -Dpython.source.enabled=true to the cluster JVM options, not just the client","Set -Dpython.allowed.executables on every worker node","Persist both properties in the startup script/env so restarts keep them","Confirm with a small smoke-test job after enabling"],"tags":["python","security-policy","feature-flag","system-property"],"backgroundTag":"feature-not-enabled","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}