{"record":{"id":"9330c8269dc0079d","repo":"apache/seatunnel","slug":"the-s3a-credentials-provider-class-s-does-not-i","errorCode":null,"errorMessage":"The S3A credentials provider class '%s' does not implement '%s'. Please check the value of '%s' and configure a class that implements the AWS credentials provider contract.","messagePattern":"The S3A credentials provider class '(.+?)' does not implement '(.+?)'\\. Please check the value of '(.+?)' and configure a class that implements the AWS credentials provider contract\\.","errorType":"validation","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-file/connector-file-s3/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/s3/config/S3HadoopConf.java","lineNumber":213,"sourceCode":"                S3FileBaseOptions.S3A_AWS_CREDENTIALS_PROVIDER_CLASS.key(),\n                AWS_CREDENTIALS_PROVIDER_INTERFACE);\n    }\n\n    /**\n     * Asserts the resolved provider class can actually be used by Hadoop S3A: it must implement\n     * {@link #AWS_CREDENTIALS_PROVIDER_INTERFACE} and must not be abstract. These are exactly the\n     * two conditions {@code S3AUtils.createAWSCredentialProvider} enforces before instantiation, so\n     * this check never rejects a class Hadoop would have accepted — it only surfaces the failure at\n     * config-parse time with an actionable message instead of an opaque worker-side error.\n     *\n     * <p>The caller resolves both classes through the same candidate classloader. If either class\n     * is unavailable it tries the next loader, so an isolated thread context classloader cannot\n     * bypass validation when the connector classloader can perform it.\n     */\n    private static void assertImplementsCredentialsProvider(\n            Class<?> providerClass, Class<?> providerInterface) {\n        if (!providerInterface.isAssignableFrom(providerClass)) {\n            throw new IllegalArgumentException(\n                    String.format(\n                            \"The S3A credentials provider class '%s' does not implement '%s'. \"\n                                    + \"Please check the value of '%s' and configure a class that \"\n                                    + \"implements the AWS credentials provider contract.\",\n                            providerClass.getName(),\n                            AWS_CREDENTIALS_PROVIDER_INTERFACE,\n                            S3FileBaseOptions.S3A_AWS_CREDENTIALS_PROVIDER_CLASS.key()));\n        }\n        if (Modifier.isAbstract(providerClass.getModifiers())) {\n            throw new IllegalArgumentException(\n                    String.format(\n                            \"The S3A credentials provider class '%s' configured via '%s' is \"\n                                    + \"abstract and cannot be instantiated. Please configure a \"\n                                    + \"concrete AWS credentials provider class.\",\n                            providerClass.getName(),\n                            S3FileBaseOptions.S3A_AWS_CREDENTIALS_PROVIDER_CLASS.key()));\n        }\n    }","sourceCodeStart":195,"sourceCodeEnd":231,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-file/connector-file-s3/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/s3/config/S3HadoopConf.java#L195-L231","documentation":"Thrown by S3HadoopConf when validating the configured S3A credentials provider class. The library reflects on the class named by the S3A AWS credentials provider option and requires it to implement the AWS credentials provider contract (AWSCredentialsProvider / AWSCredentialsProviderV2); if isAssignableFrom fails, it throws this IllegalArgumentException so misconfiguration fails fast instead of at S3 connection time.","triggerScenarios":"S3FileBaseOptions.S3A_AWS_CREDENTIALS_PROVIDER_CLASS is set to a class that either does not implement AWSCredentialsProvider/V2 at all, or whose fully qualified name was resolved to the wrong class by checkCredentialsProviderClass's dual classloader lookup (context + connector classloader).","commonSituations":"Typo or stale fully-qualified class name in config; pointing the option at a helper class that wraps (but does not implement) AWSCredentialsProvider; picking a provider from a different AWS SDK major version (v1 vs v2 provider interfaces) than the connector shades; copy-pasting a Hadoop s3a provider class that doesn't exist on the connector classpath so a similarly-named wrong class loads.","solutions":["Check the config value and set it to a fully qualified class that implements com.amazonaws.auth.AWSCredentialsProvider (or the V2 interface the connector expects), e.g. com.amazonaws.auth.EnvironmentVariableCredentialsProvider","Verify the class is on the connector/plugin classpath (it must load via the connector classloader) and that the FQCN is spelled exactly, no leading/trailing spaces","If you have a custom wrapper, make it implement AWSCredentialsProvider directly instead of delegating without implementing","Rebuild/redeploy the connector with the shaded AWS SDK matching the provider interface you implement"],"exampleFix":"// before\ns3.aws.credentials-provider-class = \"com.example.MyProviderHelper\" // does not implement AWSCredentialsProvider\n// after\ns3.aws.credentials-provider-class = \"com.amazonaws.auth.EnvironmentVariableCredentialsProvider\"","handlingStrategy":"validation","validationCode":"String cls = conf.get(\"s3a.aws.credentials-provider-class\");\nClass<?> c = Class.forName(cls);\nif (!com.amazonaws.auth.AWSCredentialsProvider.class.isAssignableFrom(c))\n    throw new IllegalArgumentException(cls + \" must implement AWSCredentialsProvider\");","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use built-in concrete providers from com.amazonaws.auth whenever possible","Keep the FQCN in config exactly matching a class on the connector classpath","Match AWS SDK major version of your custom provider to the connector's shaded SDK"],"tags":["config","aws-s3","validation"],"backgroundTag":"invalid-config-value","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}