[ 
https://issues.apache.org/jira/browse/CAMEL-25413?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino reassigned CAMEL-25413:
----------------------------------------

    Assignee: Andrea Cosentino

> camel-kubernetes: trustCerts option misannotated as security=secret instead 
> of security=insecure:ssl
> ----------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25413
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25413
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-kubernetes
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>
> The trustCerts option in KubernetesConfiguration is annotated with security = 
> "secret" but it controls TLS certificate validation - when true, all 
> certificates are trusted without verification - not a secret value.
> The correct annotation is security = "insecure:ssl" with insecureValue = 
> "true". This way the security policy framework (enabled by camel.main.profile 
> = prod) will warn or fail when certificate validation is disabled in a 
> production deployment.
> This was introduced by the bulk migration in CAMEL-23250 which mechanically 
> converted secret = true to security = "secret" without differentiating 
> between actual secrets (passwords, tokens) and insecure configuration flags 
> (TLS bypass options).
> Same pattern as the fix applied to camel-hivemq ssl option in CAMEL-24999.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to