risingwavelabs/risingwave · error · SinkError::Config

auth.method=key_pair_object requires `private_key_pem`

Error message

auth.method=key_pair_object requires `private_key_pem`

What it means

`auth.method = 'key_pair_object'` authenticates with an inline PEM-encoded private key supplied via `private_key_pem`. from_btreemap requires that option when this method is selected and fails at sink creation otherwise.

Solutions

  1. Add `private_key_pem = '-----BEGIN PRIVATE KEY-----...'` to the WITH options
  2. Or set `private_key_file` and use `auth.method = 'key_pair_file'` for a file-based key
  3. Drop the explicit auth.method and let automatic auth detection choose based on the options present

Example fix

// before
WITH (connector='snowflake', auth.method='key_pair_object', user='u');
// after
WITH (connector='snowflake', auth.method='key_pair_object', user='u', private_key_pem='-----BEGIN PRIVATE KEY-----...');
Defensive patterns

Strategy: validation

Validate before calling

if auth_method == "key_pair_object" && !options.contains_key("private_key_pem") {
    return Err("auth.method=key_pair_object requires private_key_pem");
}

Prevention

When it happens

Trigger: CREATE SINK with `auth.method = 'key_pair_object'` but no `private_key_pem` in the WITH options.

Common situations: Selecting the inline-key auth method while the key was actually mounted as a file; templated DDL where the PEM placeholder was never substituted.

Understand the failure class

Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/65fd84f8db9aee7b. Report an issue: GitHub.

Appendix: source

Thrown at src/connector/src/sink/snowflake_redshift/snowflake.rs:314

                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_file requires `private_key_file`"
                    )));
                }
                if has_password {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_file must not set `password`"
                    )));
                }
                if has_pem {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_file must not set `private_key_pem`"
                    )));
                }
                AUTH_METHOD_KEY_PAIR_FILE.to_owned()
            }
            Some(method) if method == AUTH_METHOD_KEY_PAIR_OBJECT => {
                if !has_pem {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_object requires `private_key_pem`"
                    )));
                }
                if has_password {
                    return Err(SinkError::Config(anyhow!(
                        "auth.method=key_pair_object must not set `password`"
                    )));
                }
                AUTH_METHOD_KEY_PAIR_OBJECT.to_owned()
            }
            Some(other) => {
                return Err(SinkError::Config(anyhow!(
                    "invalid auth.method: {} (allowed: password | key_pair_file | key_pair_object)",
                    other
                )));
            }
            None => {
                // Infer auth method from supplied fields

View on GitHub (pinned to 6469eb736d)