This is an automated email from the ASF dual-hosted git repository.
oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-kamelets.git
The following commit(s) were added to refs/heads/main by this push:
new 5016cc4fc Fix #2970: require an explicit saslAuthType on kafka-source
(#3069)
5016cc4fc is described below
commit 5016cc4fce07c656c52330f930bbe295b805eb97
Author: Andrea Cosentino <[email protected]>
AuthorDate: Tue Sep 29 12:59:41 2026 +0200
Fix #2970: require an explicit saslAuthType on kafka-source (#3069)
kafka-source declared:
saslAuthType:
type: string
default: NONE
enum: ["NONE", "PLAIN", ...]
and did not list it as required, so deploying the Kamelet with only
`topic` and `bootstrapServers` connected to the broker in plaintext with
no authentication, silently. The name does not say so: the catalog's
convention for that posture is to state it in the name, and the six
`not-secured` Kamelets do -- they omit `saslAuthType` entirely rather
than defaulting it.
Remove the default and make the property required, so the choice is
always explicit. `NONE` stays available and behaves exactly as before;
it just has to be asked for rather than inherited.
This is a breaking change for a deployment that relied on the implicit
default. Such a deployment now fails at startup, by name, instead of
connecting insecurely:
IllegalArgumentException: Route template kafka-source the following
mandatory parameters must be provided: saslAuthType
Verified on Camel 4.22.0 with `camel run` against the working tree:
omitting the property produces exactly that error at route-template
creation, while `saslAuthType: NONE` passes validation and proceeds to
the broker connection unchanged.
Also updated, because they relied on the default:
* The Citrus itest route `kafka/kafka-source-route.yaml` did not set the
property and would have broken. KafkaIT is green with it set:
kafka-router-route-test, kafka-source-route-test and
kafka-sink-route-test all pass.
* `kafka-source-description.adoc` stated the default in two places.
Both pipe templates already pass `saslAuthType: "NONE"` explicitly and
needed no change.
Scoped to kafka-source, which is what this issue covers. kafka-sink,
kafka-batch-source and ceph-event-based-source have the identical shape
and are deliberately left alone here.
Signed-off-by: Andrea Cosentino <[email protected]>
Co-authored-by: Claude Opus 5 <[email protected]>
---
docs/modules/ROOT/partials/kafka-source-description.adoc | 12 +++++++-----
kamelets/kafka-source.kamelet.yaml | 4 ++--
.../src/main/resources/kamelets/kafka-source.kamelet.yaml | 4 ++--
.../src/test/resources/kafka/kafka-source-route.yaml | 1 +
4 files changed, 12 insertions(+), 9 deletions(-)
diff --git a/docs/modules/ROOT/partials/kafka-source-description.adoc
b/docs/modules/ROOT/partials/kafka-source-description.adoc
index 9c335132d..2abb0711f 100644
--- a/docs/modules/ROOT/partials/kafka-source-description.adoc
+++ b/docs/modules/ROOT/partials/kafka-source-description.adoc
@@ -2,9 +2,11 @@
=== Authentication
-Authentication is selected with `saslAuthType`, which defaults to `NONE`, so
out of the box
-the Kamelet connects to an unauthenticated broker. The accepted values are
`NONE`, `PLAIN`,
-`SCRAM_SHA_256`, `SCRAM_SHA_512`, `SSL`, `OAUTH`, `AWS_MSK_IAM` and `KERBEROS`.
+Authentication is selected with `saslAuthType`, which is required and has no
default, so the
+choice is always explicit. The accepted values are `NONE`, `PLAIN`,
`SCRAM_SHA_256`,
+`SCRAM_SHA_512`, `SSL`, `OAUTH`, `AWS_MSK_IAM` and `KERBEROS`. `NONE` is a
valid choice and
+connects to an unauthenticated broker over a plaintext connection -- it just
has to be asked
+for rather than inherited.
Which other properties are needed depends on that choice:
@@ -20,11 +22,11 @@ deployment allows it.
=== Configuration
-Only `topic` and `bootstrapServers` are required. The Kamelet supports:
+`topic`, `bootstrapServers` and `saslAuthType` are required. The Kamelet
supports:
- **topic**: Comma-separated list of Kafka topic names to consume from
(required)
- **bootstrapServers**: Comma-separated list of Kafka bootstrap servers
(required)
-- **saslAuthType**: Authentication mechanism, default `NONE`
+- **saslAuthType**: Authentication mechanism, no default (required)
- **saslUsername** / **saslPassword**: Credentials for the username and
password mechanisms
- **oauthClientId** / **oauthClientSecret** / **oauthTokenEndpointUri** /
**oauthScope**:
OAuth 2.0 settings
diff --git a/kamelets/kafka-source.kamelet.yaml
b/kamelets/kafka-source.kamelet.yaml
index 7c755901f..c7e0dbdb0 100644
--- a/kamelets/kafka-source.kamelet.yaml
+++ b/kamelets/kafka-source.kamelet.yaml
@@ -34,6 +34,7 @@ spec:
required:
- topic
- bootstrapServers
+ - saslAuthType
type: object
properties:
topic:
@@ -46,9 +47,8 @@ spec:
type: string
saslAuthType:
title: Authentication Type
- description: Authentication type to use. Use NONE for no
authentication, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512 for username/password, SSL
for certificate-based, OAUTH for OAuth 2.0, AWS_MSK_IAM for MSK, or KERBEROS
for Kerberos.
+ description: Authentication type to use. This has no default and must
be set explicitly. Use NONE for no authentication, which leaves the broker
connection plaintext and unauthenticated, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512
for username/password, SSL for certificate-based, OAUTH for OAuth 2.0,
AWS_MSK_IAM for MSK, or KERBEROS for Kerberos.
type: string
- default: NONE
enum: ["NONE", "PLAIN", "SCRAM_SHA_256", "SCRAM_SHA_512", "SSL",
"OAUTH", "AWS_MSK_IAM", "KERBEROS"]
saslUsername:
title: Username
diff --git
a/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml
b/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml
index 7c755901f..c7e0dbdb0 100644
---
a/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml
+++
b/library/camel-kamelets/src/main/resources/kamelets/kafka-source.kamelet.yaml
@@ -34,6 +34,7 @@ spec:
required:
- topic
- bootstrapServers
+ - saslAuthType
type: object
properties:
topic:
@@ -46,9 +47,8 @@ spec:
type: string
saslAuthType:
title: Authentication Type
- description: Authentication type to use. Use NONE for no
authentication, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512 for username/password, SSL
for certificate-based, OAUTH for OAuth 2.0, AWS_MSK_IAM for MSK, or KERBEROS
for Kerberos.
+ description: Authentication type to use. This has no default and must
be set explicitly. Use NONE for no authentication, which leaves the broker
connection plaintext and unauthenticated, PLAIN or SCRAM_SHA_256/SCRAM_SHA_512
for username/password, SSL for certificate-based, OAUTH for OAuth 2.0,
AWS_MSK_IAM for MSK, or KERBEROS for Kerberos.
type: string
- default: NONE
enum: ["NONE", "PLAIN", "SCRAM_SHA_256", "SCRAM_SHA_512", "SSL",
"OAUTH", "AWS_MSK_IAM", "KERBEROS"]
saslUsername:
title: Username
diff --git
a/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml
b/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml
index 8019fd425..64a56601e 100644
---
a/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml
+++
b/tests/camel-kamelets-itest/src/test/resources/kafka/kafka-source-route.yaml
@@ -21,6 +21,7 @@
parameters:
bootstrapServers: '{{kafka.bootstrapServers}}'
topic: '{{kafka.topic}}'
+ saslAuthType: 'NONE'
deserializeHeaders: '{{kafka.deserializeHeaders}}'
steps:
- to: