Andrea Cosentino created CAMEL-25413:
----------------------------------------

             Summary: camel-kubernetes: trustCerts option misannotated as 
security=secret instead of security=insecure:ssl
                 Key: CAMEL-25413
                 URL: https://issues.apache.org/jira/browse/CAMEL-25413
             Project: Camel
          Issue Type: Bug
          Components: camel-kubernetes
            Reporter: Andrea Cosentino


The trustCerts option in KubernetesConfiguration is annotated with security = 
"secret" but it controls TLS certificate validation - when true, all 
certificates are trusted without verification - not a secret value.

The correct annotation is security = "insecure:ssl" with insecureValue = 
"true". This way the security policy framework (enabled by camel.main.profile = 
prod) will warn or fail when certificate validation is disabled in a production 
deployment.

This was introduced by the bulk migration in CAMEL-23250 which mechanically 
converted secret = true to security = "secret" without differentiating between 
actual secrets (passwords, tokens) and insecure configuration flags (TLS bypass 
options).

Same pattern as the fix applied to camel-hivemq ssl option in CAMEL-24999.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to