risingwavelabs/risingwave · error · SinkError::Config
auth.method=password must not set…
Error message
auth.method=password must not set `private_key_file`/`private_key_pem`
What it means
Password authentication and key-pair authentication are exclusive. from_btreemap rejects `auth.method = 'password'` when `private_key_file` or `private_key_pem` is also present, because the two credential sets cannot both be used.
Solutions
- Remove `private_key_file` and `private_key_pem` from the WITH options
- Or change `auth.method` to 'key_pair_file'/'key_pair_object' if key-pair auth is intended
Example fix
// before WITH (connector='snowflake', auth.method='password', password='***', private_key_file='/keys/rsa.p8'); // after WITH (connector='snowflake', auth.method='password', password='***');
Defensive patterns
Strategy: validation
Validate before calling
if auth_method == "password" && (options.contains_key("private_key_file") || options.contains_key("private_key_pem")) {
return Err("password auth conflicts with key-pair options");
} Prevention
- Provide exactly one credential kind per sink
- Audit merged/generated DDLs for leftover credential options
- Use separate templates per auth method
When it happens
Trigger: CREATE SINK with `auth.method = 'password'` while also setting `private_key_file` and/or `private_key_pem` in the WITH options.
Common situations: Merging two sink DDLs (one password, one key-pair) and keeping both credential options; a secrets template that always injects key files regardless of auth.method.
Related errors
- auth.method=key_pair_file must not set `password`
- auth.method=key_pair_file must not set `private_key_pem`
- auth.method=key_pair_file requires `private_key_file`
- auth.method=key_pair_object requires `private_key_pem`
- auth.method=password requires `password`
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/aad198530195cad1.
Report an issue: GitHub.
Appendix: source
Thrown at src/connector/src/sink/snowflake_redshift/snowflake.rs:288
// Normalize and validate authentication method
let has_password = config.password.is_some();
let has_file = config.private_key_file.is_some();
let has_pem = config.private_key_pem.as_deref().is_some();
let normalized_auth_method = match config
.auth_method
.as_deref()
.map(|s| s.trim().to_ascii_lowercase())
{
Some(method) if method == AUTH_METHOD_PASSWORD => {
if !has_password {
return Err(SinkError::Config(anyhow!(
"auth.method=password requires `password`"
)));
}
if has_file || has_pem {
return Err(SinkError::Config(anyhow!(
"auth.method=password must not set `private_key_file`/`private_key_pem`"
)));
}
AUTH_METHOD_PASSWORD.to_owned()
}
Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {
if !has_file {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file requires `private_key_file`"
)));
}
if has_password {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file must not set `password`"
)));
}
if has_pem {
return Err(SinkError::Config(anyhow!(View on GitHub (pinned to 6469eb736d)