risingwavelabs/risingwave · error · SinkError::Config
auth.method=password requires `password`
Error message
auth.method=password requires `password`
What it means
When `auth.method` is explicitly set to `password`, SnowflakeSinkConfig::from_btreemap requires a `password` option to authenticate with. The sink fails at creation when the password-auth method is selected but no password is supplied.
Solutions
- Add `password = '<secret>'` to the WITH options (via secret reference if supported)
- Remove `auth.method = 'password'` if you intend to use the default/auth-detection path
- Provide key-pair credentials instead (`private_key_file` or `private_key_pem`) and set the matching auth.method
Example fix
// before WITH (connector='snowflake', auth.method='password', user='u'); // after WITH (connector='snowflake', auth.method='password', user='u', password='***');
Defensive patterns
Strategy: validation
Validate before calling
if auth_method == "password" && !options.contains_key("password") {
return Err("auth.method=password requires password");
} Prevention
- Store Snowflake credentials in a secrets manager and inject at deploy time
- Verify all options required by the chosen auth.method exist before CREATE SINK
- Prefer explicit auth.method only when its credentials are also present
When it happens
Trigger: CREATE SINK with `auth.method = 'password'` (case-insensitive) but no `password` in the WITH options.
Common situations: Using an example DDL with auth.method=password but keeping credentials in a separate secrets step that was skipped; renaming options when copying configs so `password` was lost; switching from key-pair auth to password auth without adding the password.
Understand the failure class
Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.
Related errors
- auth.method=key_pair_file must not set `password`
- auth.method=key_pair_file must not set `private_key_pem`
- auth.method=key_pair_file requires `private_key_file`
- auth.method=key_pair_object requires `private_key_pem`
- auth.method=password must not set…
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/413b3e2bfc9f47b6.
Report an issue: GitHub.
Appendix: source
Thrown at src/connector/src/sink/snowflake_redshift/snowflake.rs:283
if config.task_serverless && config.snowflake_warehouse.is_some() {
return Err(SinkError::Config(anyhow!(
"`task.serverless` must not be combined with `warehouse`"
)));
}
// Normalize and validate authentication method
let has_password = config.password.is_some();
let has_file = config.private_key_file.is_some();
let has_pem = config.private_key_pem.as_deref().is_some();
let normalized_auth_method = match config
.auth_method
.as_deref()
.map(|s| s.trim().to_ascii_lowercase())
{
Some(method) if method == AUTH_METHOD_PASSWORD => {
if !has_password {
return Err(SinkError::Config(anyhow!(
"auth.method=password requires `password`"
)));
}
if has_file || has_pem {
return Err(SinkError::Config(anyhow!(
"auth.method=password must not set `private_key_file`/`private_key_pem`"
)));
}
AUTH_METHOD_PASSWORD.to_owned()
}
Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {
if !has_file {
return Err(SinkError::Config(anyhow!(
"auth.method=key_pair_file requires `private_key_file`"
)));
}
if has_password {
return Err(SinkError::Config(anyhow!(View on GitHub (pinned to 6469eb736d)