{"record":{"id":"d9682bd35517a93b","repo":"apache/seatunnel","slug":"unauthorized-to-read-config-collections-or-config","errorCode":null,"errorMessage":"Unauthorized to read config.collections or config.chunks: {}, fallback to SampleSplitter.","messagePattern":"Unauthorized to read config\\.collections or config\\.chunks: (.+?), fallback to SampleSplitter\\.","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"seatunnel-connectors-v2/connector-cdc/connector-cdc-mongodb/src/main/java/org/apache/seatunnel/connectors/seatunnel/cdc/mongodb/source/splitters/ShardedSplitStrategy.java","lineNumber":70,"sourceCode":"    @Override\n    public Collection<SnapshotSplit> split(@Nonnull SplitContext splitContext) {\n        TableId collectionId = splitContext.getCollectionId();\n        MongoClient mongoClient = splitContext.getMongoClient();\n\n        List<BsonDocument> chunks;\n        BsonDocument collectionMetadata;\n        try {\n            collectionMetadata = readCollectionMetadata(mongoClient, collectionId);\n            if (!isValidShardedCollection(collectionMetadata)) {\n                log.warn(\n                        \"Collection {} does not appear to be sharded, fallback to SampleSplitter.\",\n                        collectionId);\n                return SampleBucketSplitStrategy.INSTANCE.split(splitContext);\n            }\n            chunks = readChunks(mongoClient, collectionMetadata);\n        } catch (MongoQueryException e) {\n            if (e.getErrorCode() == UNAUTHORIZED_ERROR) {\n                log.warn(\n                        \"Unauthorized to read config.collections or config.chunks: {}, fallback to SampleSplitter.\",\n                        e.getErrorMessage());\n            } else {\n                log.warn(\n                        \"Read config.chunks collection failed: {}, fallback to SampleSplitter\",\n                        e.getErrorMessage());\n            }\n            return SampleBucketSplitStrategy.INSTANCE.split(splitContext);\n        }\n\n        if (chunks.isEmpty()) {\n            log.warn(\n                    \"Collection {} does not appear to be sharded, fallback to SampleSplitter.\",\n                    collectionId);\n            return SampleBucketSplitStrategy.INSTANCE.split(splitContext);\n        }\n\n        BsonDocument splitKeys = collectionMetadata.getDocument(SHARD_KEY_FIELD);","sourceCodeStart":52,"sourceCodeEnd":88,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-cdc/connector-cdc-mongodb/src/main/java/org/apache/seatunnel/connectors/seatunnel/cdc/mongodb/source/splitters/ShardedSplitStrategy.java#L52-L88","documentation":"When ShardedSplitStrategy reads config.collections/config.chunks the server returned an Unauthorized (code 13) MongoQueryException. The strategy logs this warning and falls back to SampleBucketSplitter because the connected user lacks permission to read the config database.","triggerScenarios":"split() executes readCollectionMetadata/readChunks against a sharded cluster and MongoDB rejects the query with error code 13 (Unauthorized), typically because the user lacks read on the config database.","commonSituations":"Connecting with a role limited to the target database only (no clusterManager/config read); hosted MongoDB Atlas with restricted roles; security-hardened deployments where config db access is denied to app users.","solutions":["Grant the CDC user a role that can read the config database (e.g. clusterManager or read on config).","Or accept the fallback: configure/keep the SampleSplitter as the intended strategy.","Check with db.runCommand({connectionStatus: 1}) which roles the connector user holds.","On Atlas, assign an Atlas built-in role with config access or use sampling instead."],"exampleFix":"// in mongosh, grant config read\nuse admin\ndb.grantRolesToUser(\"seaTunnelUser\", [{role: \"clusterManager\", db: \"admin\"}])","handlingStrategy":"validation","validationCode":"// verify user can read config db\nconst ok = db.getSiblingDB('config').collections.findOne({_id: 'mydb.mycoll'});\nprint(ok ? 'config read OK' : 'config read DENIED');","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Grant clusterManager (or config-read) role to the CDC user at provisioning time.","Test permissions with a minimal query on config.collections before running the job.","Prefer explicit SampleSplitter config when config-db access is intentionally restricted."],"tags":["mongodb","cdc","authorization","sharding"],"backgroundTag":"permission-denied","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}