{"record":{"id":"f8e6024377c12560","repo":"risingwavelabs/risingwave","slug":"secret-error-0-f8e602","errorCode":null,"errorMessage":"Secret error: {0}","messagePattern":"Secret error: (.+?)","errorType":"error_code","errorClass":"MetaError","httpStatus":null,"severity":"error","filePath":"src/meta/src/error.rs","lineNumber":144,"sourceCode":"        #[from]\n        #[backtrace]\n        anyhow::Error,\n    ),\n\n    // Indicates that recovery was triggered manually.\n    #[error(\"adhoc recovery triggered\")]\n    AdhocRecovery,\n\n    #[error(\"Integrity check failed\")]\n    IntegrityCheckFailed,\n\n    #[error(\"{0} has been deprecated, please use {1} instead.\")]\n    Deprecated(String, String),\n\n    #[error(transparent)]\n    NotImplemented(#[from] NotImplemented),\n\n    #[error(\"Secret error: {0}\")]\n    SecretError(\n        #[from]\n        #[backtrace]\n        SecretError,\n    ),\n}\n\nimpl MetaError {\n    /// Provide the Postgres error code for the error.\n    fn provide_postgres_error_code(&self, request: &mut std::error::Request<'_>) {\n        match self.inner() {\n            MetaErrorInner::CatalogIdNotFound { .. } => {\n                request.provide_value(PostgresErrorCode::UndefinedObject);\n            }\n            MetaErrorInner::Duplicated { .. } => {\n                request.provide_value(PostgresErrorCode::DuplicateObject);\n            }\n            _ => {}","sourceCodeStart":126,"sourceCodeEnd":162,"githubUrl":"https://github.com/risingwavelabs/risingwave/blob/6469eb736d691e8e9b8a419a57edd6429ca77417/src/meta/src/error.rs#L126-L162","documentation":"MetaError::SecretError wraps a SecretError from the secret-management subsystem into the meta error enum (`#[from]` auto-converts). It is raised when meta-node code creates, reads, or references secrets (used by connectors/sinks for credentials) and the secret layer fails, e.g. the secret cannot be found, decoded, or produced for the cluster.","triggerScenarios":"CREATE SECRET or secret-related RPCs failing validation/encoding; a sink or source referencing a secret_id that cannot be read from the meta store; secret payload decoding failures during connector startup on the meta side.","commonSituations":"Secret referenced by a sink/source was dropped or never created; corrupted or unsupported secret encoding; permission/consistency issues between frontend, meta, and compute nodes regarding secret read APIs.","solutions":["Inspect the wrapped SecretError source for the exact cause","Recreate the secret with CREATE SECRET and update the sink/source to reference the new secret id","Verify the secret exists: `SHOW SECRETS` and check the referenced id","Check meta node logs/backtrace for the failing secret read/write path","Ensure the secret payload format is supported by the cluster version"],"exampleFix":"// before\nlet secret = meta.read_secret(id).await?; // propagates MetaError::SecretError\n// after\nlet secret = meta.read_secret(id).await\n    .map_err(|e| { tracing::error!(\"secret {} unavailable: {e}\", id); e })?;","handlingStrategy":"validation","validationCode":"// Before creating a sink/source that references a secret\nlet exists = show_secrets(conn).await?.iter().any(|s| s.name == secret_name);\nif !exists {\n    return Err(format!(\"secret {secret_name} must be created first\").into());\n}","typeGuard":"fn is_secret_error(e: &MetaError) -> Option<&SecretError> {\n    match e { MetaError::SecretError(s) => Some(s), _ => None }\n}","tryCatchPattern":"match create_result {\n    Err(MetaError::SecretError(e)) => {\n        tracing::error!(\"secret layer failed: {e:#}\");\n        // recreate secret, then retry the operation\n    }\n    other => other?,\n}","preventionTips":["CREATE SECRET before any sink/source that references it","Never drop a secret still referenced by a sink/source","Validate secret payload encoding against supported formats"],"tags":["secret","credentials","meta-node"],"backgroundTag":"missing-credentials","analyzedSha":"6469eb736d691e8e9b8a419a57edd6429ca77417","analyzedAt":"2026-09-11T21:06:21.487Z","contentChangedAt":"2026-09-11T21:06:21.487Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}