Andrea Cosentino created CAMEL-25413:
----------------------------------------
Summary: camel-kubernetes: trustCerts option misannotated as
security=secret instead of security=insecure:ssl
Key: CAMEL-25413
URL: https://issues.apache.org/jira/browse/CAMEL-25413
Project: Camel
Issue Type: Bug
Components: camel-kubernetes
Reporter: Andrea Cosentino
The trustCerts option in KubernetesConfiguration is annotated with security =
"secret" but it controls TLS certificate validation - when true, all
certificates are trusted without verification - not a secret value.
The correct annotation is security = "insecure:ssl" with insecureValue =
"true". This way the security policy framework (enabled by camel.main.profile =
prod) will warn or fail when certificate validation is disabled in a production
deployment.
This was introduced by the bulk migration in CAMEL-23250 which mechanically
converted secret = true to security = "secret" without differentiating between
actual secrets (passwords, tokens) and insecure configuration flags (TLS bypass
options).
Same pattern as the fix applied to camel-hivemq ssl option in CAMEL-24999.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)