risingwavelabs/risingwave · critical

Private Link Connection has been deprecated

Error message

Private Link Connection has been deprecated

What it means

create_connection in src/meta/service/src/ddl_service.rs:1035 unconditionally panics with this message when a CreateConnectionRequest carries the legacy PrivateLink payload. Private Link connections were removed from RisingWave; the variant is kept only to fail fast on clients still sending it.

Solutions

  1. Remove the private link connection usage; use `ConnectionParams` (e.g. Kafka/ES connection params) instead.
  2. Upgrade or rewrite the client/tooling to a version whose CREATE CONNECTION request uses the ConnectionParams payload.
  3. Configure VPC connectivity at the infrastructure layer rather than as a RisingWave connection object.

Example fix

// before (legacy client payload)
payload: create_connection_request::Payload::Privatelink(privatelink)

// after
payload: create_connection_request::Payload::ConnectionParams(connection_params)
Defensive patterns

Strategy: validation

Validate before calling

// client-side guard before building the request
if (request.getPayloadCase() === CreateConnectionRequest.PayloadCase.PRIVATE_LINK) {
  throw new Error('Private Link connections are deprecated; use ConnectionParams');
}

Type guard

function isLegacyPrivateLink(payload) {
  return payload && 'privatelink' in payload;
}

Try / catch

// This panics server-side (no catchable status); guard before sending.
try {
  await client.createConnection(req);
} catch (e) {
  if (e.message?.includes('Private Link Connection has been deprecated')) {
    throw new Error('Upgrade client: rebuild request with ConnectionParams payload');
  }
  throw e;
}

Prevention

When it happens

Trigger: Issuing CREATE CONNECTION with a private-link payload, typically via an old CLI, old SDK, or a hand-built CreateConnectionRequest with `Payload::PrivateLink`.

Common situations: Scripts or terraform/tooling written against older RisingWave versions that supported AWS PrivateLink connections, run against a newer cluster.

Understand the failure class

Background: "is deprecated and will be removed" — deprecation warnings for old API names, keywords, and options, and how to migrate before the removal release — this error's family across 29 libraries.

Related errors


AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11). Data as JSON: /api/errors/f1051ca01170111e. Report an issue: GitHub.

Appendix: source

Thrown at src/meta/service/src/ddl_service.rs:1035

    ) -> Result<Response<GetDdlProgressResponse>, Status> {
        Ok(Response::new(GetDdlProgressResponse {
            ddl_progress: self.ddl_controller.get_ddl_progress().await?,
        }))
    }

    async fn create_connection(
        &self,
        request: Request<CreateConnectionRequest>,
    ) -> Result<Response<CreateConnectionResponse>, Status> {
        let req = request.into_inner();
        if req.payload.is_none() {
            return Err(Status::invalid_argument("request is empty"));
        }

        match req.payload.unwrap() {
            #[expect(deprecated)]
            create_connection_request::Payload::PrivateLink(_) => {
                panic!("Private Link Connection has been deprecated")
            }
            create_connection_request::Payload::ConnectionParams(params) => {
                let pb_connection = Connection {
                    id: 0.into(),
                    schema_id: req.schema_id,
                    database_id: req.database_id,
                    name: req.name,
                    info: Some(ConnectionInfo::ConnectionParams(params)),
                    owner: req.owner_id,
                };
                let version = self
                    .ddl_controller
                    .run_command(DdlCommand::CreateConnection(pb_connection))
                    .await?;
                Ok(Response::new(CreateConnectionResponse { version }))
            }
        }
    }

View on GitHub (pinned to 6469eb736d)