risingwavelabs/risingwave · error

Failed to get secret in secret manager, secret_id

Error message

Failed to get secret in secret manager, secret_id: {}

What it means

Raised in `handle_alter_secret` when ALTER SECRET needs the original secret payload (to preserve unchanged fields like the backend type) but `LocalSecretManager::global().get_secret(secret_id)` returns `None`. It means the in-memory local secret manager in the frontend process does not hold the secret with the given id, even though the secret catalog entry exists.

Solutions

  1. Provide the full secret payload in the ALTER statement (include new content options) so the original secret does not need to be fetched from the local manager.
  2. Restart the frontend/meta services to force re-sync of secrets from the meta store, then retry the ALTER.
  3. Check meta node logs for secret sync/cache errors and verify the secret exists via `SHOW SECRETS` / system catalog.
  4. Upgrade to a version where secret cache sync between meta and frontend is fixed if this reproduces after failover.

Example fix

-- before (forces read of cached original payload)
ALTER SECRET my_secret;
-- after (supply payload so local cache lookup is avoided)
ALTER SECRET my_secret WITH (password = 'new_value');
Defensive patterns

Strategy: fallback

Validate before calling

// before ALTER without new payload, confirm the secret is resolvable
SHOW SECRETS; -- ensure the target secret exists and consider always supplying the payload

Try / catch

match LocalSecretManager::global().get_secret(secret_id) {
    Some(bytes) => proceed_with_original(bytes),
    None => {
        // fallback: require caller-supplied payload or trigger meta resync, then retry once
        return Err(anyhow!("secret {} not cached locally; re-run ALTER with full payload", secret_id));
    }
}

Prevention

When it happens

Trigger: Running `ALTER SECRET name ...` without new payload options (empty `sql_options`), which forces a read of the existing secret from the local secret manager, when the frontend has not loaded/cached that secret (e.g. after a frontend restart, a stale meta cache, or when the secret was created by a different node and not synced).

Common situations: Frontend service restarted and local secret cache is empty or stale; ALTER issued on a node different from where the secret was materialized; meta/frontend version skew or cache invalidation problems after failover.

Understand the failure class

Background: Record Not Found Errors: "not found", RecordNotFound, and "was not found" — what they mean and how to fix them — this error's family across 28 libraries.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/e1aa57d207fe27f0. Report an issue: GitHub.

Appendix: source

Thrown at src/frontend/src/handler/alter_secret.rs:46

pub async fn handle_alter_secret(
    handler_args: HandlerArgs,
    secret_name: ObjectName,
    sql_options: Vec<SqlOption>,
    credential: Value,
) -> Result<RwPgResponse> {
    Feature::SecretManagement.check_available()?;

    let session = handler_args.session;

    if let Some((secret_catalog, _, _)) =
        fetch_secret_catalog_with_db_schema_id(&session, &secret_name, false)?
    {
        let secret_id = secret_catalog.id;
        let secret_payload = if sql_options.is_empty() {
            let original_pb_secret_bytes = LocalSecretManager::global()
                .get_secret(secret_id)
                .ok_or(anyhow!(
                    "Failed to get secret in secret manager, secret_id: {}",
                    secret_id
                ))?;
            let original_secret_backend =
                LocalSecretManager::get_pb_secret_backend(&original_pb_secret_bytes)?;
            match original_secret_backend {
                secret::SecretBackend::Meta(_) => {
                    let new_secret_value_bytes = secret_to_str(&credential)?.as_bytes().to_vec();
                    let secret_payload = risingwave_pb::secret::Secret {
                        secret_backend: Some(risingwave_pb::secret::secret::SecretBackend::Meta(
                            risingwave_pb::secret::SecretMetaBackend {
                                value: new_secret_value_bytes,
                            },
                        )),
                    };
                    secret_payload.encode_to_vec()
                }
                secret::SecretBackend::HashicorpVault(_vault_backend) => {

View on GitHub (pinned to 6469eb736d)