{"record":{"id":"5e5acd0449f5a4a8","repo":"apache/iceberg","slug":"cannot-assume-role-to-sign-rest-requests-becaus","errorCode":null,"errorMessage":"Cannot assume role {} to sign REST requests because {} is not set; falling back to the default credentials provider.","messagePattern":"Cannot assume role (.+?) to sign REST requests because (.+?) is not set; falling back to the default credentials provider\\.","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"aws/src/main/java/org/apache/iceberg/aws/AwsProperties.java","lineNumber":521,"sourceCode":"      } else {\n        return StaticCredentialsProvider.create(\n            AwsSessionCredentials.create(accessKeyId, secretAccessKey, sessionToken));\n      }\n    }\n\n    if (!Strings.isNullOrEmpty(this.clientCredentialsProvider)) {\n      return credentialsProvider(this.clientCredentialsProvider);\n    }\n\n    // When a role is configured to be assumed (e.g. via AssumeRoleAwsClientFactory), sign requests\n    // with the assumed-role credentials so that they do not diverge from the credentials used for\n    // S3, Glue, KMS and DynamoDB. See https://github.com/apache/iceberg/issues/16667.\n    if (!Strings.isNullOrEmpty(this.clientAssumeRoleArn)) {\n      if (!Strings.isNullOrEmpty(this.clientAssumeRoleRegion)) {\n        return assumeRoleCredentialsProvider();\n      }\n\n      LOG.warn(\n          \"Cannot assume role {} to sign REST requests because {} is not set; \"\n              + \"falling back to the default credentials provider.\",\n          this.clientAssumeRoleArn,\n          CLIENT_ASSUME_ROLE_REGION);\n    }\n\n    // Create a new credential provider for each client\n    return DefaultCredentialsProvider.builder().build();\n  }\n\n  StsAssumeRoleCredentialsProvider assumeRoleCredentialsProvider() {\n    Preconditions.checkNotNull(\n        this.clientAssumeRoleRegion,\n        \"Cannot create StsAssumeRoleCredentialsProvider with null region\");\n    return StsAssumeRoleCredentialsProvider.builder()\n        .stsClient(\n            StsClient.builder()\n                .applyMutation(httpClientProperties::applyHttpClientConfigurations)","sourceCodeStart":503,"sourceCodeEnd":539,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/aws/src/main/java/org/apache/iceberg/aws/AwsProperties.java#L503-L539","documentation":"When AwsProperties is configured with a client assume-role ARN (client.assume-role.arn) to sign REST catalog requests, it also requires client.assume-role.region to build an assume-role credentials provider. If the ARN is set but the region is missing, Iceberg logs this warning and falls back to the default AWS credentials provider instead of assuming the role — requests still proceed, but with different credentials than intended.","triggerScenarios":"Setting client.assume-role.arn (clientAssumeRoleArn) in catalog properties for a REST catalog without setting client.assume-role.region (clientAssumeRoleRegion); the credentialsProvider() path then warns and returns DefaultCredentialsProvider instead of assumeRoleCredentialsProvider().","commonSituations":"Partial migration of catalog config where assume-role ARN was added but the companion region property was overlooked; copying example configs that mention the ARN property only; environments where the region was expected to be inherited from other S3 settings but the REST signing path requires its own explicit value.","solutions":["Set the client.assume-role.region property (e.g. in your Spark/Flink catalog configuration or REST catalog properties) to the AWS region of the role to assume.","Verify the property key spelling matches CLIENT_ASSUME_ROLE_REGION (client.assume-role.region) in your config source.","If you don't need role assumption for REST signing, remove client.assume-role.arn so the default credentials provider is used intentionally and without warnings.","After fixing, restart the job and confirm the warning is gone and requests are signed with the assumed-role credentials."],"exampleFix":"// before\n{\"type\": \"rest\", \"uri\": \"...\", \"client.assume-role.arn\": \"arn:aws:iam::123:role/iceberg\"}\n\n// after\n{\"type\": \"rest\", \"uri\": \"...\", \"client.assume-role.arn\": \"arn:aws:iam::123:role/iceberg\", \"client.assume-role.region\": \"us-east-1\"}","handlingStrategy":"validation","validationCode":"// Fail fast if assume-role ARN is set without region, before building the catalog\nString arn = catalogProps.get(\"client.assume-role.arn\");\nString region = catalogProps.get(\"client.assume-role.region\");\nif (arn != null && !arn.isEmpty() && (region == null || region.isEmpty())) {\n  throw new IllegalArgumentException(\"client.assume-role.region must be set when client.assume-role.arn is configured\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always set client.assume-role.arn and client.assume-role.region as a pair in catalog config.","Validate catalog properties at deployment/startup rather than relying on runtime warnings.","Search config templates for one assume-role property and add the other.","Watch for fallback behavior in logs: this warning means requests are signed with default credentials, which may silently change permissions."],"tags":["aws","assume-role","configuration","credentials","rest-catalog","fallback"],"backgroundTag":"missing-required-config-field","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}