[
https://issues.apache.org/jira/browse/CAMEL-24498?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino updated CAMEL-24498:
-------------------------------------
Fix Version/s: 4.23.0
> camel-observability-services-starter - injected management defaults exceed
> the Spring Boot baseline
> ---------------------------------------------------------------------------------------------------
>
> Key: CAMEL-24498
> URL: https://issues.apache.org/jira/browse/CAMEL-24498
> Project: Camel
> Issue Type: Improvement
> Components: camel-spring-boot-starters
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> {{ObservabilityServicesEnvironmentPostProcessor}} injects a set of management
> defaults whenever the starter is on the classpath:
> {code:java}
> defaults.put("management.server.port", "9876");
> defaults.put("management.endpoints.web.exposure.include",
> "health,prometheus");
> ...
> defaults.put("camel.health.exposure-level", "full");
> defaults.put("management.endpoint.health.show-details", "always");
> defaults.put("management.endpoint.health.group.live.show-details", "always");
> defaults.put("management.endpoint.health.group.ready.show-details", "always");
> {code}
> (ObservabilityServicesEnvironmentPostProcessor:40-60)
> Three of these are broader than the Spring Boot defaults they replace:
> - {{management.server.port}} is set without a matching
> {{management.server.address}}, so the second listener binds all interfaces.
> Spring Boot has no default management port at all.
> - {{management.endpoint.health.show-details}} is {{always}} where Spring
> Boot's default is {{never}}.
> - {{camel.health.exposure-level}} is {{full}} where the Camel default is
> {{default}}.
> The property source is added with {{addLast}}, so user configuration wins -
> this is about what an operator gets when they add the starter and configure
> nothing.
> *Proposal*
> - Set {{management.server.address=127.0.0.1}} alongside the port so exposing
> the listener is a conscious step.
> - Default {{show-details}} to {{when-authorized}}, keeping {{always}} for the
> {{live}}/{{ready}} probe groups if the k8s probe flow needs it.
> - Leave {{camel.health.exposure-level}} at its default and document {{full}}
> as an opt-in.
> - Document the combination in the starter's docs.
> Note for the release notes: Kubernetes deployments whose kubelet probes or
> Prometheus scrapers reach the pod over the network would need to set
> {{management.server.address=0.0.0.0}} explicitly after this change. That is a
> deliberate behaviour change and should be called out in the upgrade guide.
> ----
> _This issue was drafted by Claude Code on behalf of Andrea Cosentino._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)