oscerd opened a new pull request, #27503: URL: https://github.com/apache/camel/pull/27503
## Summary Fix the `trustCerts` option annotation in `KubernetesConfiguration` from `security = "secret"` to `security = "insecure:ssl"` with `insecureValue = "true"`. ## Problem The `trustCerts` option controls TLS certificate validation — when set to `true`, all certificates are trusted without verification. This is a TLS bypass flag, **not a secret**. It was mistakenly annotated with `security = "secret"` by the bulk migration in CAMEL-23250, which mechanically converted all `secret = true` annotations to `security = "secret"` without distinguishing between actual secrets (passwords, tokens) and insecure TLS configuration flags. ## Impact With the wrong annotation, the security policy framework (enabled by `camel.main.profile=prod`) cannot warn or fail-fast when certificate validation is disabled in a production deployment. The `insecure:ssl` annotation is what triggers enforcement under the security policy. ## Fix Changed annotation on `KubernetesConfiguration.trustCerts`: ```java // Before (wrong): @UriParam(label = "security", security = "secret") private Boolean trustCerts; // After (correct): @UriParam(label = "security", security = "insecure:ssl", insecureValue = "true") private Boolean trustCerts; ``` Regenerated all catalog metadata and generated endpoint URI factory classes. Same pattern as CAMEL-24999 (fixed in camel-hivemq ssl option). --- _This change was made by an AI agent (Claude Sonnet 4.5) on behalf of @oscerd_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
