risingwavelabs/risingwave · error

ALTER ICEBERG TABLE does not support SECRET or CONNECTION…

Error message

ALTER ICEBERG TABLE does not support SECRET or CONNECTION now

What it means

Altering an Iceberg table's properties (connector options) that include SECRET references or a CONNECTION is not supported; the handler resolves the changed WITH options and bails if any secret refs exist or a connection ref was used. Secrets/connections for Iceberg tables must currently be managed outside ALTER.

Solutions

  1. Drop and recreate the Iceberg table with the new secret/connection options
  2. Alter the properties with literal (non-secret) option values
  3. Manage credential rotation at the catalog/secret level if your version supports it

Example fix

-- before
ALTER ICEBERG TABLE t SET (connection = 'my_conn');
-- after
-- recreate table or set literal options
ALTER ICEBERG TABLE t SET ('s3.endpoint' = 'https://...');
Defensive patterns

Strategy: try-catch

Validate before calling

-- Inspect current table options for secret/connection usage first
SHOW CREATE TABLE iceberg_t;

Try / catch

try {
  await conn.query("ALTER ICEBERG TABLE t SET (...)");
} catch (e) {
  if (String(e.message).includes('does not support SECRET or CONNECTION')) {
    // recreate table with new options
  }
}

Prevention

When it happens

Trigger: ALTER ICEBERG TABLE ... SET (options referencing an existing secret or connection), i.e. changed_secret_refs non-empty or connector_conn_ref present after resolving the WITH options.

Common situations: Users trying to rotate credentials on an Iceberg table via ALTER with a secret/connection; migrations that parameterize connector options with secrets.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/e68def94fb54af4d. Report an issue: GitHub.

Appendix: source

Thrown at src/frontend/src/handler/alter_table_props.rs:97

        session.check_privilege_for_drop_alter(schema_name, &**table)?;
        (sink.id, source.id, table.id)
    } else {
        return Err(ErrorCode::NotSupported(
            "ALTER TABLE With is only supported for iceberg tables".to_owned(),
            "Try `ALTER TABLE .. ADD/DROP COLUMN ...`".to_owned(),
        )
        .into());
    };

    let meta_client = session.env().meta_client();
    let (resolved_with_options, _, connector_conn_ref) = resolve_connection_ref_and_secret_ref(
        WithOptions::try_from(changed_props.as_ref() as &[SqlOption])?,
        &session,
        None,
    )?;
    let (changed_props, changed_secret_refs) = resolved_with_options.into_parts();
    if !changed_secret_refs.is_empty() || connector_conn_ref.is_some() {
        bail!("ALTER ICEBERG TABLE does not support SECRET or CONNECTION now")
    }
    meta_client
        .alter_iceberg_table_props(
            table_id,
            sink_id,
            source_id,
            changed_props,
            changed_secret_refs,
            connector_conn_ref,
        )
        .await?;

    Ok(PgResponse::empty_result(StatementType::ALTER_TABLE))
}

View on GitHub (pinned to 6469eb736d)