davsclaus commented on code in PR #27503: URL: https://github.com/apache/camel/pull/27503#discussion_r4236603754
########## docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc: ########## @@ -1876,6 +1876,28 @@ Only the option of `camel-mongodb` is reported, see the `camel-main` section abo below. To keep `camel.component.mongodb.tlsAllowInvalidHostnames = true` under a `fail` policy, list it in `camel.security.allowedProperties`. +=== camel-kubernetes - trustCerts is marked insecure:ssl + +The `trustCerts` option (shared by all 20 `camel-kubernetes` and `openshift` component endpoints via +`KubernetesConfiguration`) is now marked `insecure:ssl`, so setting it to `true` is reported +by the xref:security-policy.adoc[security policy] check: a warning by default, and a startup failure +with the `prod` profile or `camel.security.insecureSslPolicy = fail`. + +For example, if you have: + +[source,properties] +---- +camel.component.kubernetes-pods.trustCerts = true Review Comment: Optional, not blocking: `trustCerts` is an endpoint-only option. `kubernetes-pods.json` has no component-level `trustCerts`, so `camel.component.kubernetes-pods.trustCerts = true` would fail to bind at startup rather than be flagged. Also, the camel-main policy check (`BaseMainSupport.enforceSecurityPolicies`) only looks at configuration properties, not endpoint URIs. A `kubernetes-pods:...?trustCerts=true` URI is therefore not reported at startup today. It is reported by the route security scan (MCP `SecurityScanTools`) and by `camel.beans.*` keys that end in `trustCerts`. The merged `camel-mongodb` entry has the same pattern (`tlsAllowInvalidHostnames` is endpoint-only too), so this follows precedent. If you want the text to be exact, you could say the option is flagged by the security scan and, at startup, when it is set through configuration properties, and drop the `camel.component.kubernetes-pods.trustCerts` example. Happy to leave it as is otherwise. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
