{"record":{"id":"f442ef19d234a8b3","repo":"apache/iceberg","slug":"failed-to-add-delete-tags-to","errorCode":null,"errorMessage":"Failed to add delete tags: {} to {}","messagePattern":"Failed to add delete tags: (.+?) to (.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"aws/src/main/java/org/apache/iceberg/aws/s3/S3FileIO.java","lineNumber":173,"sourceCode":"  @Override\n  public InputFile newInputFile(String path, long length) {\n    return S3InputFile.fromLocation(path, length, clientForStoragePath(path), metrics);\n  }\n\n  @Override\n  public OutputFile newOutputFile(String path) {\n    return S3OutputFile.fromLocation(path, clientForStoragePath(path), metrics);\n  }\n\n  @Override\n  public void deleteFile(String path) {\n    PrefixedS3Client client = clientForStoragePath(path);\n    S3FileIOProperties s3FileIOProperties = client.s3FileIOProperties();\n    if (s3FileIOProperties.deleteTags() != null && !s3FileIOProperties.deleteTags().isEmpty()) {\n      try {\n        tagFileToDelete(client, path, s3FileIOProperties.deleteTags());\n      } catch (S3Exception e) {\n        LOG.warn(\"Failed to add delete tags: {} to {}\", s3FileIOProperties.deleteTags(), path, e);\n      }\n    }\n\n    if (!s3FileIOProperties.isDeleteEnabled()) {\n      return;\n    }\n\n    S3URI location = new S3URI(path, s3FileIOProperties.bucketToAccessPointMapping());\n    DeleteObjectRequest deleteRequest =\n        DeleteObjectRequest.builder().bucket(location.bucket()).key(location.key()).build();\n\n    client.s3().deleteObject(deleteRequest);\n  }\n\n  @Override\n  public Map<String, String> properties() {\n    return properties.immutableMap();\n  }","sourceCodeStart":155,"sourceCodeEnd":191,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/aws/src/main/java/org/apache/iceberg/aws/s3/S3FileIO.java#L155-L191","documentation":"A warning from S3FileIO.deleteFile: the configured delete tags could not be applied to the object via tagFileToDelete (an S3Exception was raised), but the delete itself is NOT aborted — after logging, the code proceeds with the actual deletion unless deletion is disabled. The tags (often used for lifecycle-based soft delete or recovery, e.g. with the S3 Tables recovery feature) are simply missing on the object.","triggerScenarios":"s3.delete.tags is configured and non-empty, but Object PutTagging fails — typically missing s3:PutObjectTagging permission, object already deleted by a concurrent writer, object versioning issues, or KMS/ownership restrictions.","commonSituations":"IAM policies granting s3:DeleteObject but not s3:PutObjectTagging; buckets with Object Ownership set to bucket-owner-enforced and cross-account tagging restrictions; expireSnapshot/delete operations where a concurrent compaction already removed the file.","solutions":["Grant the principal s3:PutObjectTagging (and s3:GetObjectTagging) on the bucket/objects in the IAM policy","If you don't need delete tags, unset s3.delete.tags so the tagging step is skipped entirely","Verify object ownership settings allow tagging from the writing account","Note the file is still deleted after the warning; if tags were your safety net for recovery, consider enabling delete=false plus a lifecycle policy instead"],"exampleFix":"// before\n{\n  \"Effect\": \"Allow\",\n  \"Action\": [\"s3:DeleteObject\"],\n  \"Resource\": \"arn:aws:s3:::my-bucket/*\"\n}\n// after\n{\n  \"Effect\": \"Allow\",\n  \"Action\": [\"s3:DeleteObject\", \"s3:PutObjectTagging\", \"s3:GetObjectTagging\"],\n  \"Resource\": \"arn:aws:s3:::my-bucket/*\"\n}","handlingStrategy":"validation","validationCode":"// verify tagging permission before deletes\ntry {\n  s3.getObjectTagging(b -> b.bucket(bucket).key(key));\n} catch (S3Exception e) {\n  LOG.warn(\"Tagging not permitted on {}\", key); // PutObjectTagging will fail too\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Grant s3:PutObjectTagging alongside s3:DeleteObject in IAM","Only configure s3.delete.tags if tagging is actually permitted","Watch for concurrent writers deleting objects before tagging","Remember deletes proceed even when tagging fails — plan recovery accordingly"],"tags":["aws","s3","delete","tags","iam"],"backgroundTag":"permission-denied","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}