risingwavelabs/risingwave · error · SinkError::Config
auth.method=key_pair_file requires `private_key_file`
Error message
auth.method=key_pair_file requires `private_key_file`
What it means
`auth.method = 'key_pair_file'` loads the RSA private key from a local file path given by `private_key_file`. from_btreemap requires that option when this method is selected and fails at sink creation otherwise.
Solutions
- Add `private_key_file = '/path/to/private_key.p8'` to the WITH options
- Or set `private_key_pem` and use `auth.method = 'key_pair_object'` if the key is inline
- Drop the explicit auth.method to rely on automatic auth detection
Example fix
// before WITH (connector='snowflake', auth.method='key_pair_file', user='u'); // after WITH (connector='snowflake', auth.method='key_pair_file', user='u', private_key_file='/keys/rsa.p8');
Defensive patterns
Strategy: validation
Validate before calling
if auth_method == "key_pair_file" && !options.contains_key("private_key_file") {
return Err("auth.method=key_pair_file requires private_key_file");
} Prevention
- Mount the key file on the cluster and reference its path consistently
- Check the key file path exists and is readable from compute nodes
- Match the auth.method to how the key is actually supplied (file vs inline PEM)
When it happens
Trigger: CREATE SINK with `auth.method = 'key_pair_file'` but no `private_key_file` in the WITH options.
Common situations: Switching auth.method to key_pair_file while credentials were previously supplied as an inline PEM; option renamed or dropped when parameterizing the DDL.
Understand the failure class
Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.
Related errors
- auth.method=key_pair_file must not set `password`
- auth.method=key_pair_file must not set `private_key_pem`
- auth.method=key_pair_object requires `private_key_pem`
- auth.method=password must not set…
- auth.method=password requires `password`
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/9750846bafdbd068.
Report an issue: GitHub.
Appendix: source
Thrown at src/connector/src/sink/snowflake_redshift/snowflake.rs:296
.as_deref()
.map(|s| s.trim().to_ascii_lowercase())
{
Some(method) if method == AUTH_METHOD_PASSWORD => {
if !has_password {
return Err(SinkError::Config(anyhow!(
"auth.method=password requires `password`"
)));
}
if has_file || has_pem {
return Err(SinkError::Config(anyhow!(
"auth.method=password must not set `private_key_file`/`private_key_pem`"
)));
}
AUTH_METHOD_PASSWORD.to_owned()
}
Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {
if !has_file {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file requires `private_key_file`"
)));
}
if has_password {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file must not set `password`"
)));
}
if has_pem {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file must not set `private_key_pem`"
)));
}
AUTH_METHOD_KEY_PAIR_FILE.to_owned()
}
Some(method) if method == AUTH_METHOD_KEY_PAIR_OBJECT => {
if !has_pem {
return Err(SinkError::Config(anyhow!(View on GitHub (pinned to 6469eb736d)