risingwavelabs/risingwave · error · SinkError::Config
auth.method=key_pair_file must not set `private_key_pem`
Error message
auth.method=key_pair_file must not set `private_key_pem`
What it means
With `auth.method = 'key_pair_file'` the key must come from a file, not an inline PEM string. from_btreemap rejects `private_key_pem` alongside this auth method since the two key sources are exclusive.
Solutions
- Remove `private_key_pem` from the WITH options
- Or switch `auth.method` to 'key_pair_object' to use the inline PEM
Example fix
// before WITH (connector='snowflake', auth.method='key_pair_file', private_key_file='/keys/rsa.p8', private_key_pem='-----BEGIN...'); // after WITH (connector='snowflake', auth.method='key_pair_file', private_key_file='/keys/rsa.p8');
Defensive patterns
Strategy: validation
Validate before calling
if auth_method == "key_pair_file" && options.contains_key("private_key_pem") {
return Err("key_pair_file auth conflicts with private_key_pem");
} Prevention
- Pick one key source: file path (key_pair_file) or inline PEM (key_pair_object)
- Never emit both key options from secret-injection tooling
- Keep inline-PEM configs under a distinct template name
When it happens
Trigger: CREATE SINK with `auth.method = 'key_pair_file'` while also setting `private_key_pem` in the WITH options.
Common situations: Copying a config that embeds the PEM inline and adding an explicit key_pair_file method; secrets manager emitting both file path and inline key.
Related errors
- auth.method=key_pair_file must not set `password`
- auth.method=key_pair_file requires `private_key_file`
- auth.method=key_pair_object requires `private_key_pem`
- auth.method=password must not set…
- auth.method=password requires `password`
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/6d2ae5b81c90e6fe.
Report an issue: GitHub.
Appendix: source
Thrown at src/connector/src/sink/snowflake_redshift/snowflake.rs:306
return Err(SinkError::Config(anyhow!(
"auth.method=password must not set `private_key_file`/`private_key_pem`"
)));
}
AUTH_METHOD_PASSWORD.to_owned()
}
Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {
if !has_file {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file requires `private_key_file`"
)));
}
if has_password {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file must not set `password`"
)));
}
if has_pem {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file must not set `private_key_pem`"
)));
}
AUTH_METHOD_KEY_PAIR_FILE.to_owned()
}
Some(method) if method == AUTH_METHOD_KEY_PAIR_OBJECT => {
if !has_pem {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_object requires `private_key_pem`"
)));
}
if has_password {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_object must not set `password`"
)));
}
AUTH_METHOD_KEY_PAIR_OBJECT.to_owned()
}View on GitHub (pinned to 6469eb736d)