{"record":{"id":"e68def94fb54af4d","repo":"risingwavelabs/risingwave","slug":"alter-iceberg-table-does-not-support-secret-or-con","errorCode":null,"errorMessage":"ALTER ICEBERG TABLE does not support SECRET or CONNECTION now","messagePattern":"ALTER ICEBERG TABLE does not support SECRET or CONNECTION now","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/frontend/src/handler/alter_table_props.rs","lineNumber":97,"sourceCode":"        session.check_privilege_for_drop_alter(schema_name, &**table)?;\n        (sink.id, source.id, table.id)\n    } else {\n        return Err(ErrorCode::NotSupported(\n            \"ALTER TABLE With is only supported for iceberg tables\".to_owned(),\n            \"Try `ALTER TABLE .. ADD/DROP COLUMN ...`\".to_owned(),\n        )\n        .into());\n    };\n\n    let meta_client = session.env().meta_client();\n    let (resolved_with_options, _, connector_conn_ref) = resolve_connection_ref_and_secret_ref(\n        WithOptions::try_from(changed_props.as_ref() as &[SqlOption])?,\n        &session,\n        None,\n    )?;\n    let (changed_props, changed_secret_refs) = resolved_with_options.into_parts();\n    if !changed_secret_refs.is_empty() || connector_conn_ref.is_some() {\n        bail!(\"ALTER ICEBERG TABLE does not support SECRET or CONNECTION now\")\n    }\n    meta_client\n        .alter_iceberg_table_props(\n            table_id,\n            sink_id,\n            source_id,\n            changed_props,\n            changed_secret_refs,\n            connector_conn_ref,\n        )\n        .await?;\n\n    Ok(PgResponse::empty_result(StatementType::ALTER_TABLE))\n}\n","sourceCodeStart":79,"sourceCodeEnd":112,"githubUrl":"https://github.com/risingwavelabs/risingwave/blob/6469eb736d691e8e9b8a419a57edd6429ca77417/src/frontend/src/handler/alter_table_props.rs#L79-L112","documentation":"Altering an Iceberg table's properties (connector options) that include SECRET references or a CONNECTION is not supported; the handler resolves the changed WITH options and bails if any secret refs exist or a connection ref was used. Secrets/connections for Iceberg tables must currently be managed outside ALTER.","triggerScenarios":"ALTER ICEBERG TABLE ... SET (options referencing an existing secret or connection), i.e. changed_secret_refs non-empty or connector_conn_ref present after resolving the WITH options.","commonSituations":"Users trying to rotate credentials on an Iceberg table via ALTER with a secret/connection; migrations that parameterize connector options with secrets.","solutions":["Drop and recreate the Iceberg table with the new secret/connection options","Alter the properties with literal (non-secret) option values","Manage credential rotation at the catalog/secret level if your version supports it"],"exampleFix":"-- before\nALTER ICEBERG TABLE t SET (connection = 'my_conn');\n-- after\n-- recreate table or set literal options\nALTER ICEBERG TABLE t SET ('s3.endpoint' = 'https://...');","handlingStrategy":"try-catch","validationCode":"-- Inspect current table options for secret/connection usage first\nSHOW CREATE TABLE iceberg_t;","typeGuard":null,"tryCatchPattern":"try {\n  await conn.query(\"ALTER ICEBERG TABLE t SET (...)\");\n} catch (e) {\n  if (String(e.message).includes('does not support SECRET or CONNECTION')) {\n    // recreate table with new options\n  }\n}","preventionTips":["Avoid SECRET/CONNECTION refs in ALTER ICEBERG TABLE options","Plan credential rotation via table recreation","Verify supported alter operations for Iceberg tables in your version"],"tags":["frontend","iceberg","secret","connection"],"backgroundTag":"unsupported-operation","analyzedSha":"6469eb736d691e8e9b8a419a57edd6429ca77417","analyzedAt":"2026-09-11T21:06:21.487Z","contentChangedAt":"2026-09-11T21:06:21.487Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}