risingwavelabs/risingwave · error · SinkError::Config

auth.method=key_pair_file must not set `password`

Error message

auth.method=key_pair_file must not set `password`

What it means

Key-pair file authentication must not also carry a password credential. from_btreemap rejects `auth.method = 'key_pair_file'` combined with a `password` option to keep a single unambiguous auth method.

Solutions

  1. Remove the `password` option from the WITH clause
  2. Or change `auth.method` to 'password' if password auth is intended

Example fix

// before
WITH (connector='snowflake', auth.method='key_pair_file', private_key_file='/keys/rsa.p8', password='***');
// after
WITH (connector='snowflake', auth.method='key_pair_file', private_key_file='/keys/rsa.p8');
Defensive patterns

Strategy: validation

Validate before calling

if auth_method == "key_pair_file" && options.contains_key("password") {
    return Err("key_pair_file auth conflicts with password");
}

Prevention

When it happens

Trigger: CREATE SINK with `auth.method = 'key_pair_file'` and `private_key_file` set, but `password` also present in the WITH options.

Common situations: Connection templates that always include a password placeholder; leftover password option after migrating from password auth to key-pair auth.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/07b710d7e8bff1e0. Report an issue: GitHub.

Appendix: source

Thrown at src/connector/src/sink/snowflake_redshift/snowflake.rs:301

                    return Err(SinkError::Config(anyhow!(
                        "auth.method=password requires `password`"
                    )));
                }
                if has_file || has_pem {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=password must not set `private_key_file`/`private_key_pem`"
                    )));
                }
                AUTH_METHOD_PASSWORD.to_owned()
            }
            Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {
                if !has_file {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_file requires `private_key_file`"
                    )));
                }
                if has_password {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_file must not set `password`"
                    )));
                }
                if has_pem {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_file must not set `private_key_pem`"
                    )));
                }
                AUTH_METHOD_KEY_PAIR_FILE.to_owned()
            }
            Some(method) if method == AUTH_METHOD_KEY_PAIR_OBJECT => {
                if !has_pem {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_object requires `private_key_pem`"
                    )));
                }
                if has_password {
                    return Err(SinkError::Config(anyhow!(

View on GitHub (pinned to 6469eb736d)