[ 
https://issues.apache.org/jira/browse/CAMEL-24521?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino resolved CAMEL-24521.
--------------------------------------
    Fix Version/s: 4.23.0
       Resolution: Fixed

Fixed on main via https://github.com/apache/camel/pull/25809 (squash commit 
763b0f94), targeting 4.23.0.

_Claude Code on behalf of Andrea Cosentino_

> camel-google: Workload Identity Federation is documented for all components 
> but is not wired to any of them
> -----------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24521
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24521
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-google
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> The google-pubsub documentation advertises Workload Identity Federation for 
> every Google component and shows Java code that does not compile, because no 
> component exposes the options.
> h3. What the docs claim
> {{components/camel-google/camel-google-pubsub/src/main/docs/google-pubsub-component.adoc}}
>  has a "Workload Identity Federation (WIF)" section stating:
> {quote}All Google components support Workload Identity Federation{quote}
> and ending with:
> {quote}NOTE: Workload Identity Federation support is available in all Google 
> components (PubSub, Storage, BigQuery, Firestore, Sheets, Calendar, Drive, 
> Mail, Functions, Secret Manager, Vision, Vertex AI, Speech-to-Text, 
> Text-to-Speech) through the common GoogleCommonConfiguration interface.{quote}
> with these samples:
> {code:java}
> GooglePubsubEndpoint endpoint = 
> context.getEndpoint("google-pubsub:my-project:my-subscription", 
> GooglePubsubEndpoint.class);
> endpoint.setUseWorkloadIdentityFederation(true);
> endpoint.setWorkloadIdentityConfig("/path/to/wif-config.json");
> endpoint.setImpersonatedServiceAccount("[email protected]");
> {code}
> h3. What is actually implemented
> {{GoogleCommonConfiguration}} declares the three accessors as *default 
> methods returning false/null*:
> {code:java}
> default boolean isUseWorkloadIdentityFederation() { return false; }
> default String getWorkloadIdentityConfig() { return null; }
> default String getImpersonatedServiceAccount() { return null; }
> {code}
> No component overrides them and none declares a matching {{@UriParam}} field 
> - a grep over {{components/camel-google}} outside {{camel-google-common}} 
> finds no reference other than that one .adoc, and no {{components/*.json}} 
> catalog file lists the options. There are no setters either, so the 
> documented snippets do not compile ({{GooglePubsubEndpoint}} implements 
> {{GoogleCommonConfiguration}} directly and adds nothing).
> Consequently, in {{GoogleCredentialsHelper.getCredentials}} the branch 
> guarded by {{config.isUseWorkloadIdentityFederation()}} is never entered, 
> which makes unreachable:
> * explicit WIF via {{workloadIdentityConfig}} - the AWS / Azure / GitHub 
> Actions case the docs single out;
> * {{impersonatedServiceAccount}} - the impersonation wrapper is only applied 
> inside that branch.
> h3. What *does* work
> The "On GKE with Workload Identity: no configuration is needed" claim is 
> correct, but for a different reason than the docs give: the plain ADC 
> fallback at the end of {{getCredentials}} calls 
> {{GoogleCredentials.getApplicationDefault()}}, and ADC detects GKE Workload 
> Identity by itself. That path does not involve the WIF code at all.
> h3. Suggested resolution
> Either wire the three options up as real {{@UriParam}} options on the 
> component configurations (which is what CAMEL-17368 and CAMEL-17369 ask for, 
> for functions and storage), or correct the documentation to describe only the 
> ADC/GKE behaviour that is actually reachable. Right now a user following the 
> docs writes code that does not compile.
> Found during a source audit of the {{components/camel-google}} module family; 
> verified against main @ 9c30b32b69dc.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to