This is an automated email from the ASF dual-hosted git repository.

oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-kamelets.git


The following commit(s) were added to refs/heads/main by this push:
     new 5016cc4fc Fix #2970: require an explicit saslAuthType on kafka-source 
(#3069)
5016cc4fc is described below

commit 5016cc4fce07c656c52330f930bbe295b805eb97
Author: Andrea Cosentino <[email protected]>
AuthorDate: Tue Sep 29 12:59:41 2026 +0200

    Fix #2970: require an explicit saslAuthType on kafka-source (#3069)
    
    kafka-source declared:
    
        saslAuthType:
          type: string
          default: NONE
          enum: ["NONE", "PLAIN", ...]
    
    and did not list it as required, so deploying the Kamelet with only
    `topic` and `bootstrapServers` connected to the broker in plaintext with
    no authentication, silently. The name does not say so: the catalog's
    convention for that posture is to state it in the name, and the six
    `not-secured` Kamelets do -- they omit `saslAuthType` entirely rather
    than defaulting it.
    
    Remove the default and make the property required, so the choice is
    always explicit. `NONE` stays available and behaves exactly as before;
    it just has to be asked for rather than inherited.
    
    This is a breaking change for a deployment that relied on the implicit
    default. Such a deployment now fails at startup, by name, instead of
    connecting insecurely:
    
        IllegalArgumentException: Route template kafka-source the following
        mandatory parameters must be provided: saslAuthType
    
    Verified on Camel 4.22.0 with `camel run` against the working tree:
    omitting the property produces exactly that error at route-template
    creation, while `saslAuthType: NONE` passes validation and proceeds to
    the broker connection unchanged.
    
    Also updated, because they relied on the default:
    
    * The Citrus itest route `kafka/kafka-source-route.yaml` did not set the
      property and would have broken. KafkaIT is green with it set:
      kafka-router-route-test, kafka-source-route-test and
      kafka-sink-route-test all pass.
    * `kafka-source-description.adoc` stated the default in two places.
    
    Both pipe templates already pass `saslAuthType: "NONE"` explicitly and
    needed no change.
    
    Scoped to kafka-source, which is what this issue covers. kafka-sink,
    kafka-batch-source and ceph-event-based-source have the identical shape
    and are deliberately left alone here.
    
    Signed-off-by: Andrea Cosentino <[email protected]>
    Co-authored-by: Claude Opus 5 <[email protected]>
---
 docs/modules/ROOT/partials/kafka-source-description.adoc     | 12 +++++++-----
 kamelets/kafka-source.kamelet.yaml                           |  4 ++--
 .../src/main/resources/kamelets/kafka-source.kamelet.yaml    |  4 ++--
 .../src/test/resources/kafka/kafka-source-route.yaml         |  1 +
 4 files changed, 12 insertions(+), 9 deletions(-)

diff --git a/docs/modules/ROOT/partials/kafka-source-description.adoc 
b/docs/modules/ROOT/partials/kafka-source-description.adoc
index 9c335132d..2abb0711f 100644
--- a/docs/modules/ROOT/partials/kafka-source-description.adoc
+++ b/docs/modules/ROOT/partials/kafka-source-description.adoc
@@ -2,9 +2,11 @@
 
 === Authentication
 
-Authentication is selected with `saslAuthType`, which defaults to `NONE`, so 
out of the box
-the Kamelet connects to an unauthenticated broker. The accepted values are 
`NONE`, `PLAIN`,
-`SCRAM_SHA_256`, `SCRAM_SHA_512`, `SSL`, `OAUTH`, `AWS_MSK_IAM` and `KERBEROS`.
+Authentication is selected with `saslAuthType`, which is required and has no 
default, so the
+choice is always explicit. The accepted values are `NONE`, `PLAIN`, 
`SCRAM_SHA_256`,
+`SCRAM_SHA_512`, `SSL`, `OAUTH`, `AWS_MSK_IAM` and `KERBEROS`. `NONE` is a 
valid choice and
+connects to an unauthenticated broker over a plaintext connection -- it just 
has to be asked
+for rather than inherited.
 
 Which other properties are needed depends on that choice:
 
@@ -20,11 +22,11 @@ deployment allows it.
 
 === Configuration
 
-Only `topic` and `bootstrapServers` are required. The Kamelet supports:
+`topic`, `bootstrapServers` and `saslAuthType` are required. The Kamelet 
supports:
 
 - **topic**: Comma-separated list of Kafka topic names to consume from 
(required)
 - **bootstrapServers**: Comma-separated list of Kafka bootstrap servers 
(required)
-- **saslAuthType**: Authentication mechanism, default `NONE`
+- **saslAuthType**: Authentication mechanism, no default (required)
 - **saslUsername** / **saslPassword**: Credentials for the username and 
password mechanisms
 - **oauthClientId** / **oauthClientSecret** / **oauthTokenEndpointUri** / 
**oauthScope**:
   OAuth 2.0 settings
diff --git a/kamelets/kafka-source.kamelet.yaml 
b/kamelets/kafka-source.kamelet.yaml
index 7c755901f..c7e0dbdb0 100644
--- a/kamelets/kafka-source.kamelet.yaml
+++ b/kamelets/kafka-source.kamelet.yaml
@@ -34,6 +34,7 @@ spec:
     required:
       - topic
       - bootstrapServers
+      - saslAuthType
     type: object
     properties:
       topic:
@@ -46,9 +47,8 @@ spec:
         type: string
       saslAuthType:
         title: Authentication Type
-        description: Authentication type to use. Use NONE for no 
authentication, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512 for username/password, SSL 
for certificate-based, OAUTH for OAuth 2.0, AWS_MSK_IAM for MSK, or KERBEROS 
for Kerberos.
+        description: Authentication type to use. This has no default and must 
be set explicitly. Use NONE for no authentication, which leaves the broker 
connection plaintext and unauthenticated, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512 
for username/password, SSL for certificate-based, OAUTH for OAuth 2.0, 
AWS_MSK_IAM for MSK, or KERBEROS for Kerberos.
         type: string
-        default: NONE
         enum: ["NONE", "PLAIN", "SCRAM_SHA_256", "SCRAM_SHA_512", "SSL", 
"OAUTH", "AWS_MSK_IAM", "KERBEROS"]
       saslUsername:
         title: Username
diff --git 
a/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml 
b/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml
index 7c755901f..c7e0dbdb0 100644
--- 
a/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml
+++ 
b/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml
@@ -34,6 +34,7 @@ spec:
     required:
       - topic
       - bootstrapServers
+      - saslAuthType
     type: object
     properties:
       topic:
@@ -46,9 +47,8 @@ spec:
         type: string
       saslAuthType:
         title: Authentication Type
-        description: Authentication type to use. Use NONE for no 
authentication, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512 for username/password, SSL 
for certificate-based, OAUTH for OAuth 2.0, AWS_MSK_IAM for MSK, or KERBEROS 
for Kerberos.
+        description: Authentication type to use. This has no default and must 
be set explicitly. Use NONE for no authentication, which leaves the broker 
connection plaintext and unauthenticated, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512 
for username/password, SSL for certificate-based, OAUTH for OAuth 2.0, 
AWS_MSK_IAM for MSK, or KERBEROS for Kerberos.
         type: string
-        default: NONE
         enum: ["NONE", "PLAIN", "SCRAM_SHA_256", "SCRAM_SHA_512", "SSL", 
"OAUTH", "AWS_MSK_IAM", "KERBEROS"]
       saslUsername:
         title: Username
diff --git 
a/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml 
b/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml
index 8019fd425..64a56601e 100644
--- 
a/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml
+++ 
b/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml
@@ -21,6 +21,7 @@
       parameters:
         bootstrapServers: '{{kafka.bootstrapServers}}'
         topic: '{{kafka.topic}}'
+        saslAuthType: 'NONE'
         deserializeHeaders: '{{kafka.deserializeHeaders}}'
       steps:
         - to:

Reply via email to