kta1kri opened a new pull request, #12513:
URL: https://github.com/apache/seatunnel/pull/12513

   ### Purpose of this pull request
   
   The Kubernetes Helm chart's Hazelcast configuration enables the deprecated 
Zeta REST API v1, while the standalone config and the v1 documentation state 
that it is disabled by default:
   
   - `deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml` and 
`hazelcast-worker.yaml` set `rest-api.enabled: true`.
   - `config/hazelcast.yaml` and `config/hazelcast-master.yaml` set 
`rest-api.enabled: false`, and `docs/en/seatunnel-engine/rest-api-v1.md` states 
that v1 is already disabled by default.
   
   REST API v1 is served on the Hazelcast member port (5801) without 
authentication — the optional HTTP Basic auth applies only to the Jetty 
listener used by REST API v2 and the Web UI. Because the chart mounts these 
files through the ConfigMap and exposes port 5801, a deployment following the 
chart ships a management endpoint that the documentation describes as off by 
default.
   
   This aligns the chart with the standalone default and the docs by setting 
`rest-api.enabled: false` in both chart Hazelcast configs. The chart already 
directs users to REST API v2 on port 8080. `endpoint-groups` are left 
unchanged, matching `config/hazelcast.yaml` (they are inert while the REST API 
is disabled).
   
   This was discussed privately with the SeaTunnel PMC, who confirmed the 
inconsistency and agreed it should be corrected as a hardening/consistency 
improvement.
   
   ### Does this PR introduce _any_ user-facing change?
   
   Deployments that relied on the chart exposing Zeta REST API v1 on port 5801 
must switch to REST API v2 on port 8080 (the chart's documented interface, and 
the standalone default). Operators are also encouraged to restrict the 
Hazelcast member port (5801) with a NetworkPolicy.
   
   ### How was this patch tested?
   
   Configuration-only change; the values now mirror `config/hazelcast.yaml`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to