risingwavelabs/risingwave · error
Failed to get secret in secret manager, secret_id
Error message
Failed to get secret in secret manager, secret_id: {} What it means
Raised in `handle_alter_secret` when ALTER SECRET needs the original secret payload (to preserve unchanged fields like the backend type) but `LocalSecretManager::global().get_secret(secret_id)` returns `None`. It means the in-memory local secret manager in the frontend process does not hold the secret with the given id, even though the secret catalog entry exists.
Solutions
- Provide the full secret payload in the ALTER statement (include new content options) so the original secret does not need to be fetched from the local manager.
- Restart the frontend/meta services to force re-sync of secrets from the meta store, then retry the ALTER.
- Check meta node logs for secret sync/cache errors and verify the secret exists via `SHOW SECRETS` / system catalog.
- Upgrade to a version where secret cache sync between meta and frontend is fixed if this reproduces after failover.
Example fix
-- before (forces read of cached original payload) ALTER SECRET my_secret; -- after (supply payload so local cache lookup is avoided) ALTER SECRET my_secret WITH (password = 'new_value');
Defensive patterns
Strategy: fallback
Validate before calling
// before ALTER without new payload, confirm the secret is resolvable SHOW SECRETS; -- ensure the target secret exists and consider always supplying the payload
Try / catch
match LocalSecretManager::global().get_secret(secret_id) {
Some(bytes) => proceed_with_original(bytes),
None => {
// fallback: require caller-supplied payload or trigger meta resync, then retry once
return Err(anyhow!("secret {} not cached locally; re-run ALTER with full payload", secret_id));
}
} Prevention
- Always pass the complete secret payload in ALTER SECRET instead of relying on the cached original.
- Avoid ALTER operations immediately after a frontend restart before caches warm up.
- Monitor secret sync between meta and frontend nodes; alert on cache misses.
- Keep frontend and meta nodes on matching versions.
When it happens
Trigger: Running `ALTER SECRET name ...` without new payload options (empty `sql_options`), which forces a read of the existing secret from the local secret manager, when the frontend has not loaded/cached that secret (e.g. after a frontend restart, a stale meta cache, or when the secret was created by a different node and not synced).
Common situations: Frontend service restarted and local secret cache is empty or stale; ALTER issued on a node different from where the secret was materialized; meta/frontend version skew or cache invalidation problems after failover.
Understand the failure class
Background: Record Not Found Errors: "not found", RecordNotFound, and "was not found" — what they mean and how to fix them — this error's family across 28 libraries.
Related errors
- source has no unaligned_join
- {0}
- ALTER SINK_RATE_LIMIT is not for sink into table
- ALTER SOURCE_RATE_LIMIT is not for table without source
- ALTER STREAMING ENABLE UNALIGNED JOIN is only supported in…
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/e1aa57d207fe27f0.
Report an issue: GitHub.
Appendix: source
Thrown at src/frontend/src/handler/alter_secret.rs:46
pub async fn handle_alter_secret(
handler_args: HandlerArgs,
secret_name: ObjectName,
sql_options: Vec<SqlOption>,
credential: Value,
) -> Result<RwPgResponse> {
Feature::SecretManagement.check_available()?;
let session = handler_args.session;
if let Some((secret_catalog, _, _)) =
fetch_secret_catalog_with_db_schema_id(&session, &secret_name, false)?
{
let secret_id = secret_catalog.id;
let secret_payload = if sql_options.is_empty() {
let original_pb_secret_bytes = LocalSecretManager::global()
.get_secret(secret_id)
.ok_or(anyhow!(
"Failed to get secret in secret manager, secret_id: {}",
secret_id
))?;
let original_secret_backend =
LocalSecretManager::get_pb_secret_backend(&original_pb_secret_bytes)?;
match original_secret_backend {
secret::SecretBackend::Meta(_) => {
let new_secret_value_bytes = secret_to_str(&credential)?.as_bytes().to_vec();
let secret_payload = risingwave_pb::secret::Secret {
secret_backend: Some(risingwave_pb::secret::secret::SecretBackend::Meta(
risingwave_pb::secret::SecretMetaBackend {
value: new_secret_value_bytes,
},
)),
};
secret_payload.encode_to_vec()
}
secret::SecretBackend::HashicorpVault(_vault_backend) => {View on GitHub (pinned to 6469eb736d)