This is an automated email from the ASF dual-hosted git repository. github-merge-queue[bot] pushed a commit to branch gh-readonly-queue/dev/pr-12513-46b75fe8b92097b1d36c75e2df9e82f9d0ae73c1 in repository https://gitbox.apache.org/repos/asf/seatunnel.git
commit 89ce33300a20c2f64a56b9319b2b68c0a1f4b4f8 Author: kta1kri <[email protected]> AuthorDate: Tue Sep 29 02:51:22 2026 +0000 [Chart] Disable unauthenticated Zeta REST API v1 in the Kubernetes Helm chart defaults (#12513) --- .../seatunnel/conf/hazelcast-master.yaml | 5 ++++- .../seatunnel/conf/hazelcast-worker.yaml | 5 ++++- deploy/kubernetes/seatunnel/values.yaml | 16 ++++++++++++---- docs/en/getting-started/kubernetes/helm.md | 8 ++++++++ .../introduction/concepts/incompatible-changes.md | 22 ++++++++++++++++++++++ docs/zh/getting-started/kubernetes/helm.md | 7 +++++++ 6 files changed, 57 insertions(+), 6 deletions(-) diff --git a/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml b/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml index 3f1686cef8..7c9bed94fe 100644 --- a/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml +++ b/deploy/kubernetes/seatunnel/conf/hazelcast-master.yaml @@ -19,7 +19,10 @@ hazelcast: cluster-name: {{ include "seatunnel.fullname" . }} network: rest-api: - enabled: true + # Disabled by default to mirror the standalone config (config/hazelcast.yaml). + # The deprecated Zeta REST API v1 is served without authentication on the + # Hazelcast member port (5801); use REST API v2 on the Jetty port (8080) instead. + enabled: false endpoint-groups: CLUSTER_WRITE: enabled: true diff --git a/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml b/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml index 6d34ac29f2..44b4428dfa 100644 --- a/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml +++ b/deploy/kubernetes/seatunnel/conf/hazelcast-worker.yaml @@ -19,7 +19,10 @@ hazelcast: cluster-name: {{ include "seatunnel.fullname" . }} network: rest-api: - enabled: true + # Disabled by default to mirror the standalone config (config/hazelcast.yaml). + # The deprecated Zeta REST API v1 is served without authentication on the + # Hazelcast member port (5801); use REST API v2 on the Jetty port (8080) instead. + enabled: false endpoint-groups: CLUSTER_WRITE: enabled: true diff --git a/deploy/kubernetes/seatunnel/values.yaml b/deploy/kubernetes/seatunnel/values.yaml index 5bc253ab3f..d8c7cc387b 100644 --- a/deploy/kubernetes/seatunnel/values.yaml +++ b/deploy/kubernetes/seatunnel/values.yaml @@ -55,8 +55,12 @@ master: ## You can use annotations to attach arbitrary non-identifying metadata to objects. ## Clients such as tools and libraries can retrieve this metadata. annotations: - prometheus.io/path: /hazelcast/rest/instance/metrics - prometheus.io/port: "5801" + ## Zeta REST API v1 on the Hazelcast member port (5801) is disabled by default + ## (see conf/hazelcast-master.yaml), so scrape metrics from the REST API v2 / + ## Jetty listener (8080) instead. The /metrics and /openmetrics paths there return + ## the same Prometheus samples. See docs/en/engines/zeta/telemetry.md. + prometheus.io/path: /metrics + prometheus.io/port: "8080" prometheus.io/scrape: "true" prometheus.io/role: "seatunnel-master" ## Affinity is a group of affinity scheduling rules. If specified, the pod's scheduling constraints. @@ -115,8 +119,12 @@ worker: ## Clients such as tools and libraries can retrieve this metadata. ## Add enable prometheus scrape for metrics collection. annotations: - prometheus.io/path: /hazelcast/rest/instance/metrics - prometheus.io/port: "5801" + ## Zeta REST API v1 on the Hazelcast member port (5801) is disabled by default + ## (see conf/hazelcast-worker.yaml), so scrape metrics from the REST API v2 / + ## Jetty listener (8080) instead. The /metrics and /openmetrics paths there return + ## the same Prometheus samples. See docs/en/engines/zeta/telemetry.md. + prometheus.io/path: /metrics + prometheus.io/port: "8080" prometheus.io/scrape: "true" prometheus.io/role: "seatunnel-worker" ## Affinity is a group of affinity scheduling rules. If specified, the pod's scheduling constraints. diff --git a/docs/en/getting-started/kubernetes/helm.md b/docs/en/getting-started/kubernetes/helm.md index 3b263b6cc1..717411cfbb 100644 --- a/docs/en/getting-started/kubernetes/helm.md +++ b/docs/en/getting-started/kubernetes/helm.md @@ -91,6 +91,14 @@ curl http://127.0.0.1:8080/system-monitoring-information After that, submit jobs through [REST API V2](../../engines/zeta/rest-api-v2.md). +> **Note:** The Helm chart disables the deprecated Zeta REST API v1 on the Hazelcast member port +> (5801) by default (`hazelcast.network.rest-api.enabled: false`), matching the standalone +> `config/hazelcast.yaml`. Use REST API v2 on port 8080, the interface shown above. For the same +> reason the default Prometheus pod annotations scrape metrics from `8080/metrics`. If you must use +> REST API v1, set `rest-api.enabled: true` in a custom ConfigMap and restrict port 5801 with a +> `NetworkPolicy`. A `helm upgrade` updates the ConfigMap, but running pods keep the old +> configuration until they are restarted. + ## What's More For now, you have taken a quick look at SeaTunnel. See the connector documentation to find all supported sources and sinks. diff --git a/docs/en/introduction/concepts/incompatible-changes.md b/docs/en/introduction/concepts/incompatible-changes.md index 7df76f3208..3d1e871d57 100644 --- a/docs/en/introduction/concepts/incompatible-changes.md +++ b/docs/en/introduction/concepts/incompatible-changes.md @@ -5,6 +5,28 @@ You need to check this document before you upgrade to related version. ## dev +### Helm Chart: Zeta REST API v1 disabled by default + +- **Behavior change: the Kubernetes Helm chart no longer enables the unauthenticated Zeta REST API v1** + - **Affected component**: Helm chart `deploy/kubernetes/seatunnel` (`conf/hazelcast-master.yaml`, + `conf/hazelcast-worker.yaml`, `values.yaml`) + - **Description**: The chart previously set `hazelcast.network.rest-api.enabled: true`, exposing the + deprecated Zeta REST API v1 (including `submit-job`, `stop-job`, `encrypt-config`, logs and thread + dump) on the Hazelcast member port (5801) without authentication. It is now `false`, matching the + standalone `config/hazelcast.yaml` default and the v1 documentation. The default Prometheus pod + annotations are repointed from `5801` (`/hazelcast/rest/instance/metrics`) to the REST API v2 / + Jetty listener on `8080` (`/metrics`), which returns the same samples. + - **Impact**: Deployments that called REST API v1 on port 5801 must switch to REST API v2 on port + 8080. Prometheus setups that scraped `5801/hazelcast/rest/instance/metrics` directly (rather than + through the pod annotations) must update the target to `8080/metrics`. Job submission through the + Hazelcast client protocol and REST API v2 on 8080 are unaffected. Because the ConfigMap is mounted + with `subPath` and the Deployments carry no config checksum annotation, running pods keep the old + setting until restarted, so restart the master/worker pods after `helm upgrade`. + - **Migration Guide**: Use REST API v2 on port 8080 (the chart's documented interface). If Zeta REST + API v1 is genuinely required, set `rest-api.enabled: true` in a custom ConfigMap + (`existingConfigMap`) and restrict the member port (5801) with a `NetworkPolicy`. Restart the pods + after upgrading so the new configuration is applied. + ### Redis Authentication - Redis sources and sinks now authenticate as the configured nonblank `user` in both `SINGLE` and diff --git a/docs/zh/getting-started/kubernetes/helm.md b/docs/zh/getting-started/kubernetes/helm.md index b9f40b6678..e3bbf5dfd1 100644 --- a/docs/zh/getting-started/kubernetes/helm.md +++ b/docs/zh/getting-started/kubernetes/helm.md @@ -92,6 +92,13 @@ curl http://127.0.0.1:8080/system-monitoring-information 后面就可以使用 [REST API V2](../../engines/zeta/rest-api-v2.md) 提交任务了。 +> **注意:** Helm chart 默认关闭了 Hazelcast 成员端口(5801)上已废弃且无鉴权的 Zeta REST API v1 +> (`hazelcast.network.rest-api.enabled: false`),与单机版 `config/hazelcast.yaml` 保持一致。请使用 +> 8080 端口上的 REST API v2(即上文所示接口)。出于同样的原因,默认的 Prometheus 注解改为从 +> `8080/metrics` 采集指标。如果确实需要 REST API v1,请在自定义 ConfigMap 中设置 +> `rest-api.enabled: true`,并使用 `NetworkPolicy` 限制 5801 端口。`helm upgrade` 会更新 ConfigMap, +> 但正在运行的 Pod 需要重启后才会加载新配置。 + ## 下一步 到现在为止,您已经安装好 SeaTunnel 集群了,可以继续查看连接器文档,了解 SeaTunnel 支持哪些 source 和 sink。 如需手写 Kubernetes manifest 或了解生产部署建议,请查看 [分离集群模式](separated-cluster-mode.md) 和 [Kubernetes 运维](operations.md)。
