risingwavelabs/risingwave · error
ALTER ICEBERG TABLE does not support SECRET or CONNECTION…
Error message
ALTER ICEBERG TABLE does not support SECRET or CONNECTION now
What it means
Altering an Iceberg table's properties (connector options) that include SECRET references or a CONNECTION is not supported; the handler resolves the changed WITH options and bails if any secret refs exist or a connection ref was used. Secrets/connections for Iceberg tables must currently be managed outside ALTER.
Solutions
- Drop and recreate the Iceberg table with the new secret/connection options
- Alter the properties with literal (non-secret) option values
- Manage credential rotation at the catalog/secret level if your version supports it
Example fix
-- before
ALTER ICEBERG TABLE t SET (connection = 'my_conn');
-- after
-- recreate table or set literal options
ALTER ICEBERG TABLE t SET ('s3.endpoint' = 'https://...'); Defensive patterns
Strategy: try-catch
Validate before calling
-- Inspect current table options for secret/connection usage first SHOW CREATE TABLE iceberg_t;
Try / catch
try {
await conn.query("ALTER ICEBERG TABLE t SET (...)");
} catch (e) {
if (String(e.message).includes('does not support SECRET or CONNECTION')) {
// recreate table with new options
}
} Prevention
- Avoid SECRET/CONNECTION refs in ALTER ICEBERG TABLE options
- Plan credential rotation via table recreation
- Verify supported alter operations for Iceberg tables in your version
When it happens
Trigger: ALTER ICEBERG TABLE ... SET (options referencing an existing secret or connection), i.e. changed_secret_refs non-empty or connector_conn_ref present after resolving the WITH options.
Common situations: Users trying to rotate credentials on an Iceberg table via ALTER with a secret/connection; migrations that parameterize connector options with secrets.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- Iceberg engine table only supports with sink decouple, try…
- internal error: entered unreachable code
- {0}
- {0}
- adlsgen2.authority_host does not parse as a URL
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/e68def94fb54af4d.
Report an issue: GitHub.
Appendix: source
Thrown at src/frontend/src/handler/alter_table_props.rs:97
session.check_privilege_for_drop_alter(schema_name, &**table)?;
(sink.id, source.id, table.id)
} else {
return Err(ErrorCode::NotSupported(
"ALTER TABLE With is only supported for iceberg tables".to_owned(),
"Try `ALTER TABLE .. ADD/DROP COLUMN ...`".to_owned(),
)
.into());
};
let meta_client = session.env().meta_client();
let (resolved_with_options, _, connector_conn_ref) = resolve_connection_ref_and_secret_ref(
WithOptions::try_from(changed_props.as_ref() as &[SqlOption])?,
&session,
None,
)?;
let (changed_props, changed_secret_refs) = resolved_with_options.into_parts();
if !changed_secret_refs.is_empty() || connector_conn_ref.is_some() {
bail!("ALTER ICEBERG TABLE does not support SECRET or CONNECTION now")
}
meta_client
.alter_iceberg_table_props(
table_id,
sink_id,
source_id,
changed_props,
changed_secret_refs,
connector_conn_ref,
)
.await?;
Ok(PgResponse::empty_result(StatementType::ALTER_TABLE))
}
View on GitHub (pinned to 6469eb736d)