{"record":{"id":"6d2ae5b81c90e6fe","repo":"risingwavelabs/risingwave","slug":"auth-method-key-pair-file-must-not-set-private-ke","errorCode":null,"errorMessage":"auth.method=key_pair_file must not set `private_key_pem`","messagePattern":"auth\\.method=key_pair_file must not set `private_key_pem`","errorType":"validation","errorClass":"SinkError::Config","httpStatus":null,"severity":"error","filePath":"src/connector/src/sink/snowflake_redshift/snowflake.rs","lineNumber":306,"sourceCode":"                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=password must not set `private_key_file`/`private_key_pem`\"\n                    )));\n                }\n                AUTH_METHOD_PASSWORD.to_owned()\n            }\n            Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {\n                if !has_file {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file requires `private_key_file`\"\n                    )));\n                }\n                if has_password {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file must not set `password`\"\n                    )));\n                }\n                if has_pem {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file must not set `private_key_pem`\"\n                    )));\n                }\n                AUTH_METHOD_KEY_PAIR_FILE.to_owned()\n            }\n            Some(method) if method == AUTH_METHOD_KEY_PAIR_OBJECT => {\n                if !has_pem {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_object requires `private_key_pem`\"\n                    )));\n                }\n                if has_password {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_object must not set `password`\"\n                    )));\n                }\n                AUTH_METHOD_KEY_PAIR_OBJECT.to_owned()\n            }","sourceCodeStart":288,"sourceCodeEnd":324,"githubUrl":"https://github.com/risingwavelabs/risingwave/blob/6469eb736d691e8e9b8a419a57edd6429ca77417/src/connector/src/sink/snowflake_redshift/snowflake.rs#L288-L324","documentation":"With `auth.method = 'key_pair_file'` the key must come from a file, not an inline PEM string. from_btreemap rejects `private_key_pem` alongside this auth method since the two key sources are exclusive.","triggerScenarios":"CREATE SINK with `auth.method = 'key_pair_file'` while also setting `private_key_pem` in the WITH options.","commonSituations":"Copying a config that embeds the PEM inline and adding an explicit key_pair_file method; secrets manager emitting both file path and inline key.","solutions":["Remove `private_key_pem` from the WITH options","Or switch `auth.method` to 'key_pair_object' to use the inline PEM"],"exampleFix":"// before\nWITH (connector='snowflake', auth.method='key_pair_file', private_key_file='/keys/rsa.p8', private_key_pem='-----BEGIN...');\n// after\nWITH (connector='snowflake', auth.method='key_pair_file', private_key_file='/keys/rsa.p8');","handlingStrategy":"validation","validationCode":"if auth_method == \"key_pair_file\" && options.contains_key(\"private_key_pem\") {\n    return Err(\"key_pair_file auth conflicts with private_key_pem\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Pick one key source: file path (key_pair_file) or inline PEM (key_pair_object)","Never emit both key options from secret-injection tooling","Keep inline-PEM configs under a distinct template name"],"tags":["snowflake","sink","auth","config-validation"],"backgroundTag":"mutually-exclusive-options","analyzedSha":"6469eb736d691e8e9b8a419a57edd6429ca77417","analyzedAt":"2026-09-11T21:06:21.487Z","contentChangedAt":"2026-09-11T21:06:21.487Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}