{"record":{"id":"6b4e219f746613ca","repo":"apache/seatunnel","slug":"packet-aes-key-missing","errorCode":"PACKET_AES_KEY_MISSING","errorMessage":"Missing secret_key when packet encryption is AES_GCM","messagePattern":"Missing secret_key when packet encryption is AES_GCM","errorType":"error_code","errorClass":"EdgeSocketConnectorException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/serialize/record/EdgeSocketPacketRecordDeserializer.java","lineNumber":98,"sourceCode":"     * @param payloadBytes base64-decoded payload bytes from packet\n     * @param packet ingress packet metadata\n     * @param encryptionType resolved encryption type\n     * @return decrypted payload bytes (or original bytes when encryption is NONE)\n     */\n    private byte[] decodeEncryption(\n            byte[] payloadBytes,\n            EdgeSocketIngressPacket packet,\n            EdgeSocketEncryptionType encryptionType) {\n        if (encryptionType == EdgeSocketEncryptionType.NONE) {\n            return payloadBytes;\n        }\n        if (encryptionType != EdgeSocketEncryptionType.AES_GCM) {\n            throw new EdgeSocketConnectorException(\n                    EdgeSocketConnectorErrorCode.PACKET_UNSUPPORTED_ENCRYPTION,\n                    \"Unsupported packet encryption type: \" + encryptionType);\n        }\n        if (config.getSecretKeyBytes() == null || config.getSecretKeyBytes().length == 0) {\n            throw new EdgeSocketConnectorException(\n                    EdgeSocketConnectorErrorCode.PACKET_AES_KEY_MISSING,\n                    \"Missing secret_key when packet encryption is AES_GCM\");\n        }\n        if (packet.getIv() == null || packet.getIv().isEmpty()) {\n            throw new EdgeSocketConnectorException(\n                    EdgeSocketConnectorErrorCode.PACKET_DECODE_ERROR,\n                    \"Missing iv in AES_GCM packet\");\n        }\n        try {\n            byte[] iv = Base64.getDecoder().decode(packet.getIv());\n            Cipher cipher = Cipher.getInstance(\"AES/GCM/NoPadding\");\n            SecretKeySpec key = new SecretKeySpec(config.getSecretKeyBytes(), \"AES\");\n            cipher.init(\n                    Cipher.DECRYPT_MODE, key, new GCMParameterSpec(AES_GCM_TAG_LENGTH_BITS, iv));\n            return cipher.doFinal(payloadBytes);\n        } catch (GeneralSecurityException securityException) {\n            throw new EdgeSocketConnectorException(\n                    EdgeSocketConnectorErrorCode.PACKET_DECODE_ERROR,","sourceCodeStart":80,"sourceCodeEnd":116,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/serialize/record/EdgeSocketPacketRecordDeserializer.java#L80-L116","documentation":"When an incoming packet declares AES_GCM encryption, decodeEncryption() requires the connector config to carry the shared secret. If config.getSecretKeyBytes() is null or empty, it throws EdgeSocketConnectorException with code PACKET_AES_KEY_MISSING. Without the key, AES-GCM packets cannot be decrypted, so the consumer fails fast rather than emitting undecryptable records.","triggerScenarios":"decodeEncryption() processes an AES_GCM-encrypted packet while the consumer's config lacks the secret_key option (missing, empty, or failed to derive key bytes).","commonSituations":"Producer enables encryption but the consumer config was not updated with the matching secret_key, blank secret_key value, or a config loading step that dropped the field.","solutions":["Add or fix the secret_key config option on the edge-socket consumer so it matches the producer.","Verify the key derivation produces non-empty bytes (check secret_key is not blank).","If encryption is not intended, set the producer's encryption to 'none'."],"exampleFix":"// before\n# (secret_key absent)\n// after\nsecret_key = \"shared-hex-or-base64-key\"","handlingStrategy":"validation","validationCode":"if (config.getSecretKeyBytes() == null || config.getSecretKeyBytes().length == 0) {\n    throw new IllegalStateException(\"secret_key must be set when packet encryption is AES_GCM\");\n}","typeGuard":null,"tryCatchPattern":"try {\n    byte[] payload = decryptedPayload(payloadBytes, packet, encryptionType);\n} catch (EdgeSocketConnectorException e) {\n    if (e.getErrorCode() == EdgeSocketConnectorErrorCode.PACKET_AES_KEY_MISSING) {\n        // fail fast: load secret_key into config before retrying\n    }\n}","preventionTips":["Always pair encryption=aes_gcm with a non-empty secret_key in every environment's config.","Add a config pre-flight check that secret_key is present when encryption is enabled.","Use config management so the key cannot be silently dropped between deploys."],"tags":["encryption","config","aes-gcm"],"backgroundTag":"missing-api-key","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}