Snowflake Password Workspace Stopped Working? Migrate It to Key Pair
Snowflake has started converting remaining LEGACY_SERVICE users to SERVICE, which breaks password-authenticated workspaces. Running "Migrate to Key Pair authentication" on the affected workspace repairs it, with its content intact.
As part of its Phase 3 rollout, Snowflake is converting the remaining LEGACY_SERVICE users to the SERVICE user type. In some accounts this is happening ahead of the enforcement dates we published in July. Once a workspace user is converted, Snowflake no longer accepts a password for it, so any Keboola workspace that still authenticates with a password stops working.
How to recognize it
- Connecting to the workspace with your existing password fails.
- Resetting the workspace password fails. The Reset password action in the workspace detail will not fix this, so there is no need to retry it.
- The workspace shows the orange key icon in the workspace list, marking it as password-authenticated.
How to fix it
Open the workspace detail and select Migrate to Key Pair authentication. The migration works even after Snowflake has already converted the user. It moves the workspace user to the correct configuration, provisions a key pair, and the workspace is usable again right away. All workspace content is preserved. Note that the migration is permanent, as with any password-to-key-pair migration.
This is the same migration we asked you to run in Action Required: Snowflake Blocks All Password Authentication. If you still have password-authenticated workspaces, we recommend migrating them now rather than waiting for them to fail.
If the migration does not resolve the issue, please submit a support ticket and include the workspace ID.