Skip to content

Fix #2970: require an explicit saslAuthType on kafka-source - #3069

Merged
oscerd merged 1 commit into
apache:mainfrom
oscerd:ci-issue-2970
Sep 29, 2026
Merged

oscerd merged 1 commit into
apache:mainfrom
oscerd:ci-issue-2970

Conversation

@oscerd

@oscerd oscerd commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Fixes #2970.

kafka-source shipped a plaintext, unauthenticated connection by default. This makes the choice explicit.

The problem

saslAuthType:
  type: string
  default: NONE
  enum: ["NONE", "PLAIN", "SCRAM_SHA_256", "SCRAM_SHA_512", "SSL", "OAUTH", "AWS_MSK_IAM", "KERBEROS"]

saslAuthType was not in required, so deploying with only topic and bootstrapServers connected to the broker in plaintext with no authentication — silently, and without the name saying so.

The catalog's convention for that posture is to state it in the name. Worth correcting one detail from the issue text while we are here: there is no plain kafka-not-secured-source or -sink. All six not-secured Kamelets are apicurio-registry variants, and they do not default saslAuthType — they omit it entirely and say "on an insecure broker" in the description. So there was no sibling to point users at either.

The change

     required:
       - topic
       - bootstrapServers
+      - saslAuthType
       saslAuthType:
         title: Authentication Type
-        description: Authentication type to use. Use NONE for no authentication, PLAIN or ...
+        description: Authentication type to use. This has no default and must be set explicitly. Use NONE for no authentication, which leaves the broker connection plaintext and unauthenticated, PLAIN or ...
         type: string
-        default: NONE

NONE stays available and behaves exactly as before. It just has to be asked for rather than inherited.

Breaking change

A deployment that relied on the implicit default now fails at startup, by name, instead of connecting insecurely. Verified on Camel 4.22.0 with camel run against the working tree:

Omitted:

Caused by: java.lang.IllegalArgumentException: Route template kafka-source the following mandatory parameters must be provided: saslAuthType
	at org.apache.camel.impl.DefaultModel.doAddRouteFromTemplate(DefaultModel.java:566)

Explicit saslAuthType: NONE: no validation error; the route starts and proceeds to the broker connection unchanged.

That is the intended shape of the break — a named, startup-time failure with an obvious fix, not a silent behaviour change and not an obscure unresolved-placeholder error.

What else had to move

Two in-tree consumers relied on the default:

  • tests/.../kafka/kafka-source-route.yaml omitted the property and would have broken. Now sets saslAuthType: 'NONE'. KafkaIT is green locally with the change:
    ✔ TEST SUCCESS: kafka-router-route-test
    ✔ TEST SUCCESS: kafka-source-route-test
    ✔ TEST SUCCESS: kafka-sink-route-test
    EXIT=0
    
  • kafka-source-description.adoc stated the default in two places ("which defaults to NONE, so out of the box the Kamelet connects to an unauthenticated broker" and "default NONE").

Both pipe templates — templates/pipes/camel-k/ and templates/pipes/core/ — already pass saslAuthType: "NONE" explicitly, so they needed nothing.

mvn clean install -DskipTests from the root is clean; the regenerated library/camel-kamelets copy is byte-identical to the canonical Kamelet.

Two things for reviewers

1. Scope. This is kafka-source only, which is what the issue covers. kafka-sink, kafka-batch-source and ceph-event-based-source have the identical shape — default: NONE, not in required — and are deliberately untouched here rather than quietly swept in. Happy to extend this PR or file it separately, whichever you prefer.

2. Upgrade guide. This repository has no upgrade guide. The note this change warrants belongs in apache/camel's docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc, which does carry Kamelet entries. That is a separate cross-repo PR — say the word and I will open it.


Claude Code on behalf of Andrea Cosentino

kafka-source declared:

    saslAuthType:
      type: string
      default: NONE
      enum: ["NONE", "PLAIN", ...]

and did not list it as required, so deploying the Kamelet with only
`topic` and `bootstrapServers` connected to the broker in plaintext with
no authentication, silently. The name does not say so: the catalog's
convention for that posture is to state it in the name, and the six
`not-secured` Kamelets do -- they omit `saslAuthType` entirely rather
than defaulting it.

Remove the default and make the property required, so the choice is
always explicit. `NONE` stays available and behaves exactly as before;
it just has to be asked for rather than inherited.

This is a breaking change for a deployment that relied on the implicit
default. Such a deployment now fails at startup, by name, instead of
connecting insecurely:

    IllegalArgumentException: Route template kafka-source the following
    mandatory parameters must be provided: saslAuthType

Verified on Camel 4.22.0 with `camel run` against the working tree:
omitting the property produces exactly that error at route-template
creation, while `saslAuthType: NONE` passes validation and proceeds to
the broker connection unchanged.

Also updated, because they relied on the default:

* The Citrus itest route `kafka/kafka-source-route.yaml` did not set the
  property and would have broken. KafkaIT is green with it set:
  kafka-router-route-test, kafka-source-route-test and
  kafka-sink-route-test all pass.
* `kafka-source-description.adoc` stated the default in two places.

Both pipe templates already pass `saslAuthType: "NONE"` explicitly and
needed no change.

Scoped to kafka-source, which is what this issue covers. kafka-sink,
kafka-batch-source and ceph-event-based-source have the identical shape
and are deliberately left alone here.

Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@oscerd
oscerd merged commit 5016cc4 into apache:main Sep 29, 2026
6 checks passed
@oscerd
oscerd deleted the ci-issue-2970 branch October 1, 2026 07:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

kafka-source defaults saslAuthType to NONE without the not-secured naming its siblings use

2 participants