{"record":{"id":"aad198530195cad1","repo":"risingwavelabs/risingwave","slug":"auth-method-password-must-not-set-private-key-fil","errorCode":null,"errorMessage":"auth.method=password must not set `private_key_file`/`private_key_pem`","messagePattern":"auth\\.method=password must not set `private_key_file`/`private_key_pem`","errorType":"validation","errorClass":"SinkError::Config","httpStatus":null,"severity":"error","filePath":"src/connector/src/sink/snowflake_redshift/snowflake.rs","lineNumber":288,"sourceCode":"\n        // Normalize and validate authentication method\n        let has_password = config.password.is_some();\n        let has_file = config.private_key_file.is_some();\n        let has_pem = config.private_key_pem.as_deref().is_some();\n\n        let normalized_auth_method = match config\n            .auth_method\n            .as_deref()\n            .map(|s| s.trim().to_ascii_lowercase())\n        {\n            Some(method) if method == AUTH_METHOD_PASSWORD => {\n                if !has_password {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=password requires `password`\"\n                    )));\n                }\n                if has_file || has_pem {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=password must not set `private_key_file`/`private_key_pem`\"\n                    )));\n                }\n                AUTH_METHOD_PASSWORD.to_owned()\n            }\n            Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {\n                if !has_file {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file requires `private_key_file`\"\n                    )));\n                }\n                if has_password {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file must not set `password`\"\n                    )));\n                }\n                if has_pem {\n                    return Err(SinkError::Config(anyhow!(","sourceCodeStart":270,"sourceCodeEnd":306,"githubUrl":"https://github.com/risingwavelabs/risingwave/blob/6469eb736d691e8e9b8a419a57edd6429ca77417/src/connector/src/sink/snowflake_redshift/snowflake.rs#L270-L306","documentation":"Password authentication and key-pair authentication are exclusive. from_btreemap rejects `auth.method = 'password'` when `private_key_file` or `private_key_pem` is also present, because the two credential sets cannot both be used.","triggerScenarios":"CREATE SINK with `auth.method = 'password'` while also setting `private_key_file` and/or `private_key_pem` in the WITH options.","commonSituations":"Merging two sink DDLs (one password, one key-pair) and keeping both credential options; a secrets template that always injects key files regardless of auth.method.","solutions":["Remove `private_key_file` and `private_key_pem` from the WITH options","Or change `auth.method` to 'key_pair_file'/'key_pair_object' if key-pair auth is intended"],"exampleFix":"// before\nWITH (connector='snowflake', auth.method='password', password='***', private_key_file='/keys/rsa.p8');\n// after\nWITH (connector='snowflake', auth.method='password', password='***');","handlingStrategy":"validation","validationCode":"if auth_method == \"password\" && (options.contains_key(\"private_key_file\") || options.contains_key(\"private_key_pem\")) {\n    return Err(\"password auth conflicts with key-pair options\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Provide exactly one credential kind per sink","Audit merged/generated DDLs for leftover credential options","Use separate templates per auth method"],"tags":["snowflake","sink","auth","config-validation"],"backgroundTag":"mutually-exclusive-options","analyzedSha":"6469eb736d691e8e9b8a419a57edd6429ca77417","analyzedAt":"2026-09-11T21:06:21.487Z","contentChangedAt":"2026-09-11T21:06:21.487Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}