{"record":{"id":"d1b8c5c1e1862afa","repo":"apache/iceberg","slug":"failed-to-create-impersonated-credentials-for-gcs","errorCode":null,"errorMessage":"Failed to create impersonated credentials for GCS","messagePattern":"Failed to create impersonated credentials for GCS","errorType":"exception","errorClass":"UncheckedIOException","httpStatus":null,"severity":"error","filePath":"gcp/src/main/java/org/apache/iceberg/gcp/gcs/PrefixedStorage.java","lineNumber":182,"sourceCode":"  }\n\n  private Credentials buildImpersonatedCredentials(GCPProperties properties) {\n    try {\n      GoogleCredentials sourceCredentials = GoogleCredentials.getApplicationDefault();\n\n      ImpersonatedCredentials impersonatedCredentials =\n          ImpersonatedCredentials.create(\n              sourceCredentials,\n              properties.impersonateServiceAccount().get(),\n              properties.impersonateDelegates(),\n              properties.impersonateScopes(),\n              properties.impersonateLifetimeSeconds());\n\n      // Refresh to get initial token\n      impersonatedCredentials.refresh();\n      return impersonatedCredentials;\n    } catch (IOException e) {\n      throw new UncheckedIOException(\"Failed to create impersonated credentials for GCS\", e);\n    }\n  }\n}\n","sourceCodeStart":164,"sourceCodeEnd":186,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/gcp/src/main/java/org/apache/iceberg/gcp/gcs/PrefixedStorage.java#L164-L186","documentation":"PrefixedStorage.buildImpersonatedCredentials() wraps IOException from creating or refreshing Google impersonated credentials into UncheckedIOException. It means the service-account impersonation flow for GCS access could not be set up or its initial token fetched.","triggerScenarios":"Configuring gcs.project-id / impersonation properties (impersonated service account, delegation token, lifetime) and the underlying Google credentials.refresh() fails — bad key file, missing IAM permissions, or network failure to the token endpoint.","commonSituations":"Wrong service account email in impersonation config; caller lacking roles/iam.serviceAccountTokenCreator; unreachable OAuth2 token endpoint (proxy/firewall); invalid or unreadable credential key file.","solutions":["Verify the impersonated service-account email and that the caller has serviceAccountTokenCreator IAM role","Check the configured credential source (key file / ADC) is valid: gcloud auth application-default login","Test network reachability to the OAuth2 token endpoint (oauth2.googleapis.com)","Review gcs.* impersonation properties (target principal, lifetime, delegation tokens) for typos"],"exampleFix":"// before\nCatalog catalog = CatalogLoader.load(...); // with wrong gcs.impersonation target\n// after\nconf.set(\"io.iceberg.gcs.impersonate-service-account\", \"correct-sa@project.iam.gserviceaccount.com\");","handlingStrategy":"validation","validationCode":"// pre-check: GoogleCredentials source loads and IAM tokenCreator role exists\n// gcloud storage ls gs://bucket && gcloud iam service-accounts describe SA_EMAIL","typeGuard":null,"tryCatchPattern":"try { storage = new PrefixedStorage(...).credentials(); } catch (UncheckedIOException e) { throw new IllegalStateException(\"Impersonation setup failed: \" + e.getCause(), e); }","preventionTips":["Verify impersonation target SA email and tokenCreator IAM grant","Use valid ADC/key-file credentials locally and workload identity in GCP","Confirm network access to oauth2.googleapis.com"],"tags":["gcs","gcp","impersonated-credentials","authentication"],"backgroundTag":"oauth-token-exchange-failed","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}