{"record":{"id":"9d30b97ebb2af48b","repo":"apache/iceberg","slug":"file-encryption-key-metadata-is-present-but-no-en","errorCode":null,"errorMessage":"File encryption key metadata is present, but no encryption has been configured.","messagePattern":"File encryption key metadata is present, but no encryption has been configured\\.","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"core/src/main/java/org/apache/iceberg/encryption/PlaintextEncryptionManager.java","lineNumber":39,"sourceCode":"import org.apache.iceberg.io.InputFile;\nimport org.apache.iceberg.io.OutputFile;\nimport org.slf4j.Logger;\nimport org.slf4j.LoggerFactory;\n\npublic class PlaintextEncryptionManager implements EncryptionManager {\n  private static final EncryptionManager INSTANCE = new PlaintextEncryptionManager();\n  private static final Logger LOG = LoggerFactory.getLogger(PlaintextEncryptionManager.class);\n\n  private PlaintextEncryptionManager() {}\n\n  public static EncryptionManager instance() {\n    return INSTANCE;\n  }\n\n  @Override\n  public InputFile decrypt(EncryptedInputFile encrypted) {\n    if (encrypted.keyMetadata().buffer() != null) {\n      LOG.warn(\"File encryption key metadata is present, but no encryption has been configured.\");\n    }\n    return encrypted.encryptedInputFile();\n  }\n\n  @Override\n  public EncryptedOutputFile encrypt(OutputFile rawOutput) {\n    return EncryptedFiles.encryptedOutput(rawOutput, EncryptionKeyMetadata.empty());\n  }\n}\n","sourceCodeStart":21,"sourceCodeEnd":49,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/core/src/main/java/org/apache/iceberg/encryption/PlaintextEncryptionManager.java#L21-L49","documentation":"PlaintextEncryptionManager.decrypt logs a WARN when it is asked to decrypt a file that carries encryption key metadata, but no encryption manager is configured for the table. The file is returned as-is (read as plaintext); if the file is actually encrypted the read will subsequently fail or produce garbage.","triggerScenarios":"Reading/compacting a table whose manifest entries contain file key metadata (encrypted files) while table encryption is unset, so the plaintext manager is used and just logs and passes through the encrypted input file.","commonSituations":"Table cloned/copied with encryption metadata but encryption properties dropped; mixing encrypted and unencrypted files in one table; loading a table without the configured EncryptionManager (e.g. in a custom catalog or engine integration).","solutions":["Configure the table's encryption properties/EncryptionManager so files with key metadata are decrypted properly.","Identify which files carry key metadata (manifest key_metadata) and decide whether they are truly encrypted; rewrite them unencrypted if not needed.","If the files are genuinely plaintext and metadata is stale, remove stale key metadata by rewriting the data files."],"exampleFix":"// before\ntable encryption unset -> PlaintextEncryptionManager used\n// after\nTableProperties + encrypted catalog: load table with encryption-aware catalog or set\n'encryption.key-metadata' handling so EncryptingFileIO decrypts key metadata","handlingStrategy":"validation","validationCode":"// before reading, check files for key metadata\nboolean hasKeyMetadata = manifests.stream()\n    .flatMap(m -> ManifestFiles.read(m.file(), table.io()))\n    .anyMatch(f -> f.keyMetadata() != null);","typeGuard":null,"tryCatchPattern":"if (hasKeyMetadata) {\n  // load table via an encryption-aware catalog / configure EncryptingFileIO\n}","preventionTips":["Use the same catalog (with encryption config) for reading as for writing.","Do not drop encryption table properties when copying/cloning tables.","Audit manifest key_metadata before migrating tables between catalogs."],"tags":["encryption","config","io"],"backgroundTag":"missing-credentials","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}