{"record":{"id":"65fd84f8db9aee7b","repo":"risingwavelabs/risingwave","slug":"auth-method-key-pair-object-requires-private-key","errorCode":null,"errorMessage":"auth.method=key_pair_object requires `private_key_pem`","messagePattern":"auth\\.method=key_pair_object requires `private_key_pem`","errorType":"validation","errorClass":"SinkError::Config","httpStatus":null,"severity":"error","filePath":"src/connector/src/sink/snowflake_redshift/snowflake.rs","lineNumber":314,"sourceCode":"                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file requires `private_key_file`\"\n                    )));\n                }\n                if has_password {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file must not set `password`\"\n                    )));\n                }\n                if has_pem {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file must not set `private_key_pem`\"\n                    )));\n                }\n                AUTH_METHOD_KEY_PAIR_FILE.to_owned()\n            }\n            Some(method) if method == AUTH_METHOD_KEY_PAIR_OBJECT => {\n                if !has_pem {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_object requires `private_key_pem`\"\n                    )));\n                }\n                if has_password {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_object must not set `password`\"\n                    )));\n                }\n                AUTH_METHOD_KEY_PAIR_OBJECT.to_owned()\n            }\n            Some(other) => {\n                return Err(SinkError::Config(anyhow!(\n                    \"invalid auth.method: {} (allowed: password | key_pair_file | key_pair_object)\",\n                    other\n                )));\n            }\n            None => {\n                // Infer auth method from supplied fields","sourceCodeStart":296,"sourceCodeEnd":332,"githubUrl":"https://github.com/risingwavelabs/risingwave/blob/6469eb736d691e8e9b8a419a57edd6429ca77417/src/connector/src/sink/snowflake_redshift/snowflake.rs#L296-L332","documentation":"`auth.method = 'key_pair_object'` authenticates with an inline PEM-encoded private key supplied via `private_key_pem`. from_btreemap requires that option when this method is selected and fails at sink creation otherwise.","triggerScenarios":"CREATE SINK with `auth.method = 'key_pair_object'` but no `private_key_pem` in the WITH options.","commonSituations":"Selecting the inline-key auth method while the key was actually mounted as a file; templated DDL where the PEM placeholder was never substituted.","solutions":["Add `private_key_pem = '-----BEGIN PRIVATE KEY-----...'` to the WITH options","Or set `private_key_file` and use `auth.method = 'key_pair_file'` for a file-based key","Drop the explicit auth.method and let automatic auth detection choose based on the options present"],"exampleFix":"// before\nWITH (connector='snowflake', auth.method='key_pair_object', user='u');\n// after\nWITH (connector='snowflake', auth.method='key_pair_object', user='u', private_key_pem='-----BEGIN PRIVATE KEY-----...');","handlingStrategy":"validation","validationCode":"if auth_method == \"key_pair_object\" && !options.contains_key(\"private_key_pem\") {\n    return Err(\"auth.method=key_pair_object requires private_key_pem\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify the PEM placeholder was substituted before CREATE SINK","Include BEGIN/END header lines in the PEM value","Use key_pair_file instead if the key is provisioned as a mounted file"],"tags":["snowflake","sink","auth","config-validation"],"backgroundTag":"missing-required-config-field","analyzedSha":"6469eb736d691e8e9b8a419a57edd6429ca77417","analyzedAt":"2026-09-11T21:06:21.487Z","contentChangedAt":"2026-09-11T21:06:21.487Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}