oscerd opened a new pull request, #3069:
URL: https://github.com/apache/camel-kamelets/pull/3069

   Fixes #2970.
   
   `kafka-source` shipped a plaintext, unauthenticated connection by default. 
This makes the choice explicit.
   
   ## The problem
   
   ```yaml
   saslAuthType:
     type: string
     default: NONE
     enum: ["NONE", "PLAIN", "SCRAM_SHA_256", "SCRAM_SHA_512", "SSL", "OAUTH", 
"AWS_MSK_IAM", "KERBEROS"]
   ```
   
   `saslAuthType` was not in `required`, so deploying with only `topic` and 
`bootstrapServers` connected to the broker in plaintext with no authentication 
— silently, and without the name saying so.
   
   The catalog's convention for that posture is to state it in the name. Worth 
correcting one detail from the issue text while we are here: there is **no** 
plain `kafka-not-secured-source` or `-sink`. All six `not-secured` Kamelets are 
apicurio-registry variants, and they do not default `saslAuthType` — they omit 
it entirely and say "on an insecure broker" in the description. So there was no 
sibling to point users at either.
   
   ## The change
   
   ```diff
        required:
          - topic
          - bootstrapServers
   +      - saslAuthType
   ```
   ```diff
          saslAuthType:
            title: Authentication Type
   -        description: Authentication type to use. Use NONE for no 
authentication, PLAIN or ...
   +        description: Authentication type to use. This has no default and 
must be set explicitly. Use NONE for no authentication, which leaves the broker 
connection plaintext and unauthenticated, PLAIN or ...
            type: string
   -        default: NONE
   ```
   
   `NONE` stays available and behaves exactly as before. It just has to be 
asked for rather than inherited.
   
   ## Breaking change
   
   A deployment that relied on the implicit default now fails at startup, by 
name, instead of connecting insecurely. Verified on Camel 4.22.0 with `camel 
run` against the working tree:
   
   **Omitted:**
   ```
   Caused by: java.lang.IllegalArgumentException: Route template kafka-source 
the following mandatory parameters must be provided: saslAuthType
        at 
org.apache.camel.impl.DefaultModel.doAddRouteFromTemplate(DefaultModel.java:566)
   ```
   
   **Explicit `saslAuthType: NONE`:** no validation error; the route starts and 
proceeds to the broker connection unchanged.
   
   That is the intended shape of the break — a named, startup-time failure with 
an obvious fix, not a silent behaviour change and not an obscure 
unresolved-placeholder error.
   
   ## What else had to move
   
   Two in-tree consumers relied on the default:
   
   - **`tests/.../kafka/kafka-source-route.yaml`** omitted the property and 
would have broken. Now sets `saslAuthType: 'NONE'`. `KafkaIT` is green locally 
with the change:
     ```
     ✔ TEST SUCCESS: kafka-router-route-test
     ✔ TEST SUCCESS: kafka-source-route-test
     ✔ TEST SUCCESS: kafka-sink-route-test
     EXIT=0
     ```
   - **`kafka-source-description.adoc`** stated the default in two places 
("which defaults to `NONE`, so out of the box the Kamelet connects to an 
unauthenticated broker" and "default `NONE`").
   
   Both pipe templates — `templates/pipes/camel-k/` and `templates/pipes/core/` 
— already pass `saslAuthType: "NONE"` explicitly, so they needed nothing.
   
   `mvn clean install -DskipTests` from the root is clean; the regenerated 
`library/camel-kamelets` copy is byte-identical to the canonical Kamelet.
   
   ## Two things for reviewers
   
   **1. Scope.** This is `kafka-source` only, which is what the issue covers. 
`kafka-sink`, `kafka-batch-source` and `ceph-event-based-source` have the 
identical shape — `default: NONE`, not in `required` — and are deliberately 
untouched here rather than quietly swept in. Happy to extend this PR or file it 
separately, whichever you prefer.
   
   **2. Upgrade guide.** This repository has no upgrade guide. The note this 
change warrants belongs in `apache/camel`'s 
`docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc`, which 
does carry Kamelet entries. That is a separate cross-repo PR — say the word and 
I will open it.
   
   ---
   _Claude Code on behalf of Andrea Cosentino_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to