{"record":{"id":"b000d7bc4626c3d8","repo":"apache/seatunnel","slug":"edge-socket-ingress-decryption-failed-decrypt-fai","errorCode":null,"errorMessage":"Edge socket ingress decryption failed (DECRYPT_FAILED): verify output.aes-secret-key-base64 matches EdgeSocket source secret_key","messagePattern":"Edge socket ingress decryption failed \\(DECRYPT_FAILED\\): verify output\\.aes-secret-key-base64 matches EdgeSocket source secret_key","errorType":"exception","errorClass":"IOException","httpStatus":null,"severity":"critical","filePath":"seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java","lineNumber":68,"sourceCode":"            if (EdgeSocketProtocol.RESP_RECEIVED.equals(reply)) {\n                return;\n            }\n            if (EdgeSocketProtocol.RESP_RETRY.equals(reply)) {\n                attempts++;\n                EdgeTransportConfig.sleepQuiet(\n                        EdgeTransportConfig.computeBackoffMillis(\n                                attempts - 1,\n                                config.getInitialBackoffMs(),\n                                config.getMaxBackoffMs()));\n                continue;\n            }\n            if (reply.startsWith(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX)) {\n                long waitMs = parseQueueFullBackoffMs(reply);\n                EdgeTransportConfig.sleepQuiet(waitMs);\n                continue;\n            }\n            if (EdgeSocketProtocol.RESP_DECRYPT_FAILED.equals(reply)) {\n                throw new IOException(\n                        \"Edge socket ingress decryption failed (DECRYPT_FAILED): verify \"\n                                + \"output.aes-secret-key-base64 matches EdgeSocket source \"\n                                + \"secret_key\");\n            }\n            throw new IOException(\n                    \"Unexpected batch response: \"\n                            + reply\n                            + \" (expected \"\n                            + EdgeSocketProtocol.RESP_RECEIVED\n                            + \", \"\n                            + EdgeSocketProtocol.RESP_RETRY\n                            + \", or \"\n                            + EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX\n                            + \"<ms>)\");\n        }\n        throw new IOException(\n                \"Exceeded maxBatchSendAttempts=\"\n                        + config.getMaxBatchSendAttempts()","sourceCodeStart":50,"sourceCodeEnd":86,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java#L50-L86","documentation":"After sending a batch, the agent reads the collector's reply; a DECRYPT_FAILED response means the EdgeSocket source on the server side could not decrypt the payload with its AES secret key. The transport converts this protocol reply into an IOException telling the operator that the client's output.aes-secret-key-base64 does not match the server source's secret_key.","triggerScenarios":"The collector replies with the RESP_DECRYPT_FAILED token after a batch line is written, i.e. the client encrypted the batch payload with an AES key that differs from the EdgeSocket source's secret_key.","commonSituations":"Sink option output.aes-secret-key-base64 and source option secret_key were generated separately (different base64 keys); key rotated on one side only; whitespace/encoding differences (non-base64, padding) in the configured key; config change not propagated to both jobs after restart.","solutions":["Compare the client's output.aes-secret-key-base64 with the EdgeSocket source's secret_key and set both to the same base64 AES key","Restart/redeploy both sides after rotating the key so no stale config remains","Verify the key is valid base64 of the expected AES length (16/24/32 bytes) with no stray whitespace","Confirm the encryption mode/version on both sides is compatible"],"exampleFix":"# before (sink)\noutput.aes-secret-key-base64 = \"Zx9k...old\"\n# source\nsecret_key = \"Qw7m...new\"\n# after: use the identical key on both sides\noutput.aes-secret-key-base64 = \"Qw7m...new\"\nsecret_key = \"Qw7m...new\"","handlingStrategy":"validation","validationCode":"// fail fast at job start if keys differ\nif (!Objects.equals(sinkAesKeyBase64, sourceSecretKey)) {\n    throw new IllegalStateException(\"output.aes-secret-key-base64 does not match EdgeSocket source secret_key\");\n}","typeGuard":null,"tryCatchPattern":"try { client.send(batchId, payload); } catch (IOException e) { if (e.getMessage().contains(\"DECRYPT_FAILED\")) { alertOperator(\"AES key mismatch; fix output.aes-secret-key-base64 vs source secret_key\"); throw e; } }","preventionTips":["Generate one AES key and copy it verbatim into both sink and source configs","Base64-decode the key locally once to confirm it is valid 16/24/32-byte AES material","Redeploy both sides together after any key rotation","Strip whitespace/quotes from key values in config files"],"tags":["encryption","aes","config-mismatch","socket"],"backgroundTag":"key-mismatch","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}