jkondrat-sd opened a new issue, #18671:
URL: https://github.com/apache/dolphinscheduler/issues/18671

   ### Search before asking
   
   - [x] I had searched in the 
[issues](https://github.com/apache/dolphinscheduler/issues?q=is%3Aissue) and 
found no similar feature requirement.
   
   
   ### Description
   
   This is a follow-up to #17560 / #17561. #18124 updated the bundled zookeeper 
chart to 13.8.7 and pinned the image to 
`bitnamilegacy/zookeeper:3.9.3-debian-12-r21`. As discussed in #17730, 
`docker.io/bitnami` no longer provides ZooKeeper, and `bitnamilegacy/*` is a 
frozen archive: it gets no new versions or security fixes. So the chart's 
default ZooKeeper will stay on 3.9.3 with any future CVEs unpatched.
   
   Proposal: switch `zookeeper.image` to 
[`soldevelo/zookeeper`](https://hub.docker.com/r/soldevelo/zookeeper), a 
maintained, freely available build from 
[SolDevelo/containers](https://github.com/SolDevelo/containers), a fork of 
`bitnami/containers` that keeps the same layout, scripts and environment 
variables (currently ZooKeeper 3.9.6, amd64/arm64).
   
   As noted in #17730, this is not only an image swap: starting with 
`3.9.4-debian-12-r1`, the image checks `ALLOW_EMPTY_PASSWORD` instead of 
`ALLOW_ANONYMOUS_LOGIN`, while the zookeeper chart 13.8.7 (the last publicly 
published version) only sets `ALLOW_ANONYMOUS_LOGIN`. Without setting 
`ALLOW_EMPTY_PASSWORD=yes` via `zookeeper.extraEnvVars`, the ZooKeeper pod 
fails to start, so the change needs that values adjustment as well.
   
   
   ### Are you willing to submit a PR?
   
   - [x] Yes I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [x] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: 
[email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to