[ 
https://issues.apache.org/jira/browse/CAMEL-24776?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino resolved CAMEL-24776.
--------------------------------------
    Resolution: Fixed

Fixed on main via https://github.com/apache/camel/pull/26520 (4.23.0) and 
backported to camel-4.22.x via https://github.com/apache/camel/pull/26527 
(4.22.1). camel-4.18.x is not affected (it predates the CAMEL-23073 regression).

_Claude Code on behalf of oscerd_

> camel-jbang run does not auto-load camel-kubernetes for secret property 
> functions
> ---------------------------------------------------------------------------------
>
>                 Key: CAMEL-24776
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24776
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-jbang
>    Affects Versions: 4.22.0
>         Environment: Standalone reproduction: macOS, Java 26.0.1, native 
> Camel JBang 4.22.0; no application-specific runtime patch, Kubernetes 
> cluster, or message broker required.
> Original integration environment: Linux aarch64 on Kubernetes, OpenJDK 
> 25.0.4, Camel 4.22.0. The Secret-reference-as-username failure was also 
> observed there. Explicitly adding camel-kubernetes resolved the Secret and 
> allowed successful Artemis sends in that Java 25 runtime. The Java 26 version 
> above refers only to the separate macOS reproduction, not the Kubernetes 
> runtime.
>            Reporter: Serdar Gökay
>            Assignee: Andrea Cosentino
>            Priority: Minor
>             Fix For: 4.22.1, 4.23.0
>
>
> h2. Problem
> Camel JBang 4.22.0 run resolves {{secret:probe/user}} to the literal string 
> probe/user when camel-kubernetes is not explicitly included. Adding 
> --dep=camel-kubernetes makes the same placeholder resolve correctly.
> This causes misleading downstream authentication failures when Secret 
> placeholders supply connection-factory credentials. No broker or Kubernetes 
> cluster is needed for the reproduction below.
> h2. Reproduction
> Create probe.yaml in a disposable directory:
> {code:yaml}
> - route:
>     id: secret-probe
>     from:
>       uri: timer:probe
>       parameters:
>         repeatCount: 1
>         delay: 100
>       steps:
>         - log:
>             message: "PROBE_RESULT={{secret:probe/user}}"
> {code}
> Create a non-sensitive local Secret fixture:
> {code:bash}
> mkdir -p fixtures/probe
> printf '%s' 'fixture-user' > fixtures/probe/user
> {code}
> Create application.properties (replace the absolute path with your fixture 
> directory):
> {code:properties}
> camel.main.name=secret-probe
> camel.main.durationMaxMessages=1
> camel.main.shutdownTimeout=1
> camel.kubernetes-config.mount-path-secrets=/absolute/path/to/probe/fixtures
> camel.kubernetes-config.client-enabled=false
> {code}
> Run without an explicit dependency:
> {code:bash}
> jbang -Dcamel.jbang.version=4.22.0 camel@apache/camel run probe.yaml
> {code}
> Actual: PROBE_RESULT=probe/user
> Expected: PROBE_RESULT=fixture-user
> Control case / workaround:
> {code:bash}
> jbang -Dcamel.jbang.version=4.22.0 camel@apache/camel run probe.yaml 
> --dep=camel-kubernetes
> {code}
> The control case outputs PROBE_RESULT=fixture-user. An initial run without 
> the dependency also reproduced the literal result before fixture 
> configuration was added. The fixture is only needed to demonstrate successful 
> resolution.
> h2. Export comparison
> Without an explicit dependency, export includes camel-kubernetes in the 
> generated POM:
> {code:bash}
> jbang -Dcamel.jbang.version=4.22.0 camel@apache/camel export probe.yaml 
> --runtime=camel-main --gav=local:secret-probe:1.0 --dir=out
> {code}
> POM generation was verified; the exported application was not built or run.
> h2. Suspected cause
> In DependencyDownloaderPropertiesFunctionResolver, the special dependency 
> download for secret/configmap is invoked only when export is true. Normal run 
> falls through to the default function resolver. With no registered secret 
> function, the property parser can interpret the text after the colon as an 
> ordinary property's default value.
> Commit 
> [f1d57f874e670de9ccdbc3440747203188f2eef7|https://github.com/apache/camel/commit/f1d57f874e670de9ccdbc3440747203188f2eef7]
>  (CAMEL-23073) moved previously unconditional download logic behind the 
> export condition while introducing transform stubs. This is source-based 
> regression attribution; a pre-change release was not tested.
> [Version-pinned resolver 
> source|https://github.com/apache/camel/blob/camel-4.22.0/dsl/camel-kamelet-main/src/main/java/org/apache/camel/main/download/DependencyDownloaderPropertiesFunctionResolver.java]
> [Version-pinned parser 
> source|https://github.com/apache/camel/blob/camel-4.22.0/core/camel-base/src/main/java/org/apache/camel/component/properties/DefaultPropertiesParser.java]
> The same conditional structure was observed on main and camel-4.22.x on 
> 2026-09-16. Configmap shares the code path but was not independently tested.
> h2. Suggested fix / regression coverage
> Restore property-function dependency discovery for normal run while 
> preserving transform stubs and export dependency inclusion. A regression test 
> can use the mounted fixture above and assert the resolved value without an 
> explicit Kubernetes dependency.
> Projects can currently work around this by explicitly adding camel-kubernetes 
> to camel.jbang.dependencies (preserving existing entries).
> Reported with assistance from OpenAI Codex; the reproduction and control case 
> were executed against native Camel 4.22.0.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to