This is an automated email from the ASF dual-hosted git repository.

github-merge-queue[bot] pushed a commit to branch 
gh-readonly-queue/dev/pr-12513-46b75fe8b92097b1d36c75e2df9e82f9d0ae73c1
in repository https://gitbox.apache.org/repos/asf/seatunnel.git

commit 89ce33300a20c2f64a56b9319b2b68c0a1f4b4f8
Author: kta1kri <[email protected]>
AuthorDate: Tue Sep 29 02:51:22 2026 +0000

    [Chart] Disable unauthenticated Zeta REST API v1 in the Kubernetes Helm 
chart defaults (#12513)
---
 .../seatunnel/conf/hazelcast-master.yaml           |  5 ++++-
 .../seatunnel/conf/hazelcast-worker.yaml           |  5 ++++-
 deploy/kubernetes/seatunnel/values.yaml            | 16 ++++++++++++----
 docs/en/getting-started/kubernetes/helm.md         |  8 ++++++++
 .../introduction/concepts/incompatible-changes.md  | 22 ++++++++++++++++++++++
 docs/zh/getting-started/kubernetes/helm.md         |  7 +++++++
 6 files changed, 57 insertions(+), 6 deletions(-)

diff --git a/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml 
b/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml
index 3f1686cef8..7c9bed94fe 100644
--- a/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml
+++ b/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml
@@ -19,7 +19,10 @@ hazelcast:
   cluster-name: {{ include "seatunnel.fullname" . }}
   network:
     rest-api:
-      enabled: true
+      # Disabled by default to mirror the standalone config 
(config/hazelcast.yaml).
+      # The deprecated Zeta REST API v1 is served without authentication on the
+      # Hazelcast member port (5801); use REST API v2 on the Jetty port (8080) 
instead.
+      enabled: false
       endpoint-groups:
         CLUSTER_WRITE:
           enabled: true
diff --git a/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml 
b/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml
index 6d34ac29f2..44b4428dfa 100644
--- a/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml
+++ b/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml
@@ -19,7 +19,10 @@ hazelcast:
   cluster-name: {{ include "seatunnel.fullname" . }}
   network:
     rest-api:
-      enabled: true
+      # Disabled by default to mirror the standalone config 
(config/hazelcast.yaml).
+      # The deprecated Zeta REST API v1 is served without authentication on the
+      # Hazelcast member port (5801); use REST API v2 on the Jetty port (8080) 
instead.
+      enabled: false
       endpoint-groups:
         CLUSTER_WRITE:
           enabled: true
diff --git a/deploy/kubernetes/seatunnel/values.yaml 
b/deploy/kubernetes/seatunnel/values.yaml
index 5bc253ab3f..d8c7cc387b 100644
--- a/deploy/kubernetes/seatunnel/values.yaml
+++ b/deploy/kubernetes/seatunnel/values.yaml
@@ -55,8 +55,12 @@ master:
   ## You can use annotations to attach arbitrary non-identifying metadata to 
objects.
   ## Clients such as tools and libraries can retrieve this metadata.
   annotations:
-    prometheus.io/path: /hazelcast/rest/instance/metrics
-    prometheus.io/port: "5801"
+    ## Zeta REST API v1 on the Hazelcast member port (5801) is disabled by 
default
+    ## (see conf/hazelcast-master.yaml), so scrape metrics from the REST API 
v2 /
+    ## Jetty listener (8080) instead. The /metrics and /openmetrics paths 
there return
+    ## the same Prometheus samples. See docs/en/engines/zeta/telemetry.md.
+    prometheus.io/path: /metrics
+    prometheus.io/port: "8080"
     prometheus.io/scrape: "true"
     prometheus.io/role: "seatunnel-master"
   ## Affinity is a group of affinity scheduling rules. If specified, the pod's 
scheduling constraints.
@@ -115,8 +119,12 @@ worker:
   ## Clients such as tools and libraries can retrieve this metadata.
   ## Add enable prometheus scrape for metrics collection.
   annotations:
-    prometheus.io/path: /hazelcast/rest/instance/metrics
-    prometheus.io/port: "5801"
+    ## Zeta REST API v1 on the Hazelcast member port (5801) is disabled by 
default
+    ## (see conf/hazelcast-worker.yaml), so scrape metrics from the REST API 
v2 /
+    ## Jetty listener (8080) instead. The /metrics and /openmetrics paths 
there return
+    ## the same Prometheus samples. See docs/en/engines/zeta/telemetry.md.
+    prometheus.io/path: /metrics
+    prometheus.io/port: "8080"
     prometheus.io/scrape: "true"
     prometheus.io/role: "seatunnel-worker"
   ## Affinity is a group of affinity scheduling rules. If specified, the pod's 
scheduling constraints.
diff --git a/docs/en/getting-started/kubernetes/helm.md 
b/docs/en/getting-started/kubernetes/helm.md
index 3b263b6cc1..717411cfbb 100644
--- a/docs/en/getting-started/kubernetes/helm.md
+++ b/docs/en/getting-started/kubernetes/helm.md
@@ -91,6 +91,14 @@ curl http://127.0.0.1:8080/system-monitoring-information
 
 After that, submit jobs through [REST API 
V2](../../engines/zeta/rest-api-v2.md).
 
+> **Note:** The Helm chart disables the deprecated Zeta REST API v1 on the 
Hazelcast member port
+> (5801) by default (`hazelcast.network.rest-api.enabled: false`), matching 
the standalone
+> `config/hazelcast.yaml`. Use REST API v2 on port 8080, the interface shown 
above. For the same
+> reason the default Prometheus pod annotations scrape metrics from 
`8080/metrics`. If you must use
+> REST API v1, set `rest-api.enabled: true` in a custom ConfigMap and restrict 
port 5801 with a
+> `NetworkPolicy`. A `helm upgrade` updates the ConfigMap, but running pods 
keep the old
+> configuration until they are restarted.
+
 ## What's More
 
 For now, you have taken a quick look at SeaTunnel. See the connector 
documentation to find all supported sources and sinks.
diff --git a/docs/en/introduction/concepts/incompatible-changes.md 
b/docs/en/introduction/concepts/incompatible-changes.md
index 7df76f3208..3d1e871d57 100644
--- a/docs/en/introduction/concepts/incompatible-changes.md
+++ b/docs/en/introduction/concepts/incompatible-changes.md
@@ -5,6 +5,28 @@ You need to check this document before you upgrade to related 
version.
 
 ## dev
 
+### Helm Chart: Zeta REST API v1 disabled by default
+
+- **Behavior change: the Kubernetes Helm chart no longer enables the 
unauthenticated Zeta REST API v1**
+  - **Affected component**: Helm chart `deploy/kubernetes/seatunnel` 
(`conf/hazelcast-master.yaml`,
+    `conf/hazelcast-worker.yaml`, `values.yaml`)
+  - **Description**: The chart previously set 
`hazelcast.network.rest-api.enabled: true`, exposing the
+    deprecated Zeta REST API v1 (including `submit-job`, `stop-job`, 
`encrypt-config`, logs and thread
+    dump) on the Hazelcast member port (5801) without authentication. It is 
now `false`, matching the
+    standalone `config/hazelcast.yaml` default and the v1 documentation. The 
default Prometheus pod
+    annotations are repointed from `5801` (`/hazelcast/rest/instance/metrics`) 
to the REST API v2 /
+    Jetty listener on `8080` (`/metrics`), which returns the same samples.
+  - **Impact**: Deployments that called REST API v1 on port 5801 must switch 
to REST API v2 on port
+    8080. Prometheus setups that scraped 
`5801/hazelcast/rest/instance/metrics` directly (rather than
+    through the pod annotations) must update the target to `8080/metrics`. Job 
submission through the
+    Hazelcast client protocol and REST API v2 on 8080 are unaffected. Because 
the ConfigMap is mounted
+    with `subPath` and the Deployments carry no config checksum annotation, 
running pods keep the old
+    setting until restarted, so restart the master/worker pods after `helm 
upgrade`.
+  - **Migration Guide**: Use REST API v2 on port 8080 (the chart's documented 
interface). If Zeta REST
+    API v1 is genuinely required, set `rest-api.enabled: true` in a custom 
ConfigMap
+    (`existingConfigMap`) and restrict the member port (5801) with a 
`NetworkPolicy`. Restart the pods
+    after upgrading so the new configuration is applied.
+
 ### Redis Authentication
 
 - Redis sources and sinks now authenticate as the configured nonblank `user` 
in both `SINGLE` and
diff --git a/docs/zh/getting-started/kubernetes/helm.md 
b/docs/zh/getting-started/kubernetes/helm.md
index b9f40b6678..e3bbf5dfd1 100644
--- a/docs/zh/getting-started/kubernetes/helm.md
+++ b/docs/zh/getting-started/kubernetes/helm.md
@@ -92,6 +92,13 @@ curl http://127.0.0.1:8080/system-monitoring-information
 
 后面就可以使用 [REST API V2](../../engines/zeta/rest-api-v2.md) 提交任务了。
 
+> **注意:** Helm chart 默认关闭了 Hazelcast 成员端口(5801)上已废弃且无鉴权的 Zeta REST API v1
+> (`hazelcast.network.rest-api.enabled: false`),与单机版 `config/hazelcast.yaml` 
保持一致。请使用
+> 8080 端口上的 REST API v2(即上文所示接口)。出于同样的原因,默认的 Prometheus 注解改为从
+> `8080/metrics` 采集指标。如果确实需要 REST API v1,请在自定义 ConfigMap 中设置
+> `rest-api.enabled: true`,并使用 `NetworkPolicy` 限制 5801 端口。`helm upgrade` 会更新 
ConfigMap,
+> 但正在运行的 Pod 需要重启后才会加载新配置。
+
 ## 下一步
 到现在为止,您已经安装好 SeaTunnel 集群了,可以继续查看连接器文档,了解 SeaTunnel 支持哪些 source 和 sink。
 如需手写 Kubernetes manifest 或了解生产部署建议,请查看 [分离集群模式](separated-cluster-mode.md) 和 
[Kubernetes 运维](operations.md)。

Reply via email to