davsclaus commented on code in PR #27503:
URL: https://github.com/apache/camel/pull/27503#discussion_r4236603754


##########
docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc:
##########
@@ -1876,6 +1876,28 @@ Only the option of `camel-mongodb` is reported, see the 
`camel-main` section abo
 below. To keep `camel.component.mongodb.tlsAllowInvalidHostnames = true` under 
a `fail` policy, list it in
 `camel.security.allowedProperties`.
 
+=== camel-kubernetes - trustCerts is marked insecure:ssl
+
+The `trustCerts` option (shared by all 20 `camel-kubernetes` and `openshift` 
component endpoints via
+`KubernetesConfiguration`) is now marked `insecure:ssl`, so setting it to 
`true` is reported
+by the xref:security-policy.adoc[security policy] check: a warning by default, 
and a startup failure
+with the `prod` profile or `camel.security.insecureSslPolicy = fail`.
+
+For example, if you have:
+
+[source,properties]
+----
+camel.component.kubernetes-pods.trustCerts = true

Review Comment:
   Optional, not blocking: `trustCerts` is an endpoint-only option. 
`kubernetes-pods.json` has no component-level `trustCerts`, so 
`camel.component.kubernetes-pods.trustCerts = true` would fail to bind at 
startup rather than be flagged. Also, the camel-main policy check 
(`BaseMainSupport.enforceSecurityPolicies`) only looks at configuration 
properties, not endpoint URIs. A `kubernetes-pods:...?trustCerts=true` URI is 
therefore not reported at startup today. It is reported by the route security 
scan (MCP `SecurityScanTools`) and by `camel.beans.*` keys that end in 
`trustCerts`.
   
   The merged `camel-mongodb` entry has the same pattern 
(`tlsAllowInvalidHostnames` is endpoint-only too), so this follows precedent. 
If you want the text to be exact, you could say the option is flagged by the 
security scan and, at startup, when it is set through configuration properties, 
and drop the `camel.component.kubernetes-pods.trustCerts` example. Happy to 
leave it as is otherwise.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to