[
https://issues.apache.org/jira/browse/CAMEL-24571?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino reassigned CAMEL-24571:
----------------------------------------
Assignee: Andrea Cosentino
> camel-spiffe: provide an SSLContextParameters backed by the SPIFFE Workload
> API (rotating mTLS)
> -----------------------------------------------------------------------------------------------
>
> Key: CAMEL-24571
> URL: https://issues.apache.org/jira/browse/CAMEL-24571
> Project: Camel
> Issue Type: New Feature
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
>
> Follow-up to CAMEL-23305 (camel-spiffe, first increment shipped in 4.23.0,
> which delivered the fetchX509Svid / fetchJwtSvid / validateJwtSvid producer
> operations). This issue tracks the second increment: a Camel
> SSLContextParameters backed by the SPIFFE Workload API, so any Camel
> component that accepts sslContextParameters (camel-http, camel-netty-http,
> camel-jetty, camel-vertx-http, camel-kafka, ...) can obtain zero-trust mTLS
> with automatic SVID rotation.
> h3. Approach
> * Add a dependency on io.spiffe:java-spiffe-provider (same
> ${java-spiffe-version} = 0.8.17 already used for java-spiffe-core;
> Apache-2.0; confirmed on Maven Central) - the SSL companion library.
> * Introduce org.apache.camel.component.spiffe.SpiffeSSLContextParameters
> extends org.apache.camel.support.jsse.SSLContextParameters, overriding
> createSSLContext(CamelContext) to build the SSLContext from a live
> io.spiffe.workloadapi.X509Source (via
> io.spiffe.provider.SpiffeSslContextFactory / SpiffeKeyManager +
> SpiffeTrustManager) instead of from keystores. createSSLContext(CamelContext)
> is public and non-final on core/camel-api
> .../support/jsse/SSLContextParameters.java (around line 251), so a subclass
> is the idiomatic drop-in: users set sslContextParameters=#spiffeSsl on any
> component and get rotating SPIFFE mTLS.
> h3. Options
> * spiffeSocketPath - reuse the component semantics; default from the
> SPIFFE_ENDPOINT_SOCKET env var.
> * acceptedSpiffeIds - comma-separated allow-list of peer SPIFFE IDs the
> TrustManager accepts; OR acceptAnySpiffeId=true to accept any SVID validated
> against the trust bundle without pinning a specific ID.
> h3. Lifecycle (the design-heavy part)
> The X509Source is a long-lived, auto-updating resource that MUST be closed.
> Create the DefaultX509Source lazily on first createSSLContext and register it
> for shutdown with the CamelContext (camelContext.addService(...) / a
> ShutdownableService) so it is closed on context stop and never leaked; cache
> the built SSLContext/source to avoid re-creating on a started context (cf.
> the vertexai doStart-on-started-context lesson). Alternatively reuse
> io.spiffe.provider.X509SourceManager for a shared JVM-wide source.
> h3. Tests and docs
> * Unit-test the option plumbing with a mocked X509Source. An integration test
> against a SPIRE agent is optional/manual (no emulator in CI) - gate it
> accordingly.
> * Extend spiffe-component.adoc with an 'mTLS via SSLContextParameters'
> section and an example wiring #spiffeSsl into camel-http / camel-netty-http.
> Feasibility confirmed: java-spiffe-provider 0.8.17 is on Maven Central
> (Apache-2.0) and the SSLContextParameters extension point exists and is
> non-final.
> _Filed by Claude Code on behalf of Andrea Cosentino (@oscerd)._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)