Fix #2970: require an explicit saslAuthType on kafka-source - #3069
Merged
Merged
Conversation
kafka-source declared:
saslAuthType:
type: string
default: NONE
enum: ["NONE", "PLAIN", ...]
and did not list it as required, so deploying the Kamelet with only
`topic` and `bootstrapServers` connected to the broker in plaintext with
no authentication, silently. The name does not say so: the catalog's
convention for that posture is to state it in the name, and the six
`not-secured` Kamelets do -- they omit `saslAuthType` entirely rather
than defaulting it.
Remove the default and make the property required, so the choice is
always explicit. `NONE` stays available and behaves exactly as before;
it just has to be asked for rather than inherited.
This is a breaking change for a deployment that relied on the implicit
default. Such a deployment now fails at startup, by name, instead of
connecting insecurely:
IllegalArgumentException: Route template kafka-source the following
mandatory parameters must be provided: saslAuthType
Verified on Camel 4.22.0 with `camel run` against the working tree:
omitting the property produces exactly that error at route-template
creation, while `saslAuthType: NONE` passes validation and proceeds to
the broker connection unchanged.
Also updated, because they relied on the default:
* The Citrus itest route `kafka/kafka-source-route.yaml` did not set the
property and would have broken. KafkaIT is green with it set:
kafka-router-route-test, kafka-source-route-test and
kafka-sink-route-test all pass.
* `kafka-source-description.adoc` stated the default in two places.
Both pipe templates already pass `saslAuthType: "NONE"` explicitly and
needed no change.
Scoped to kafka-source, which is what this issue covers. kafka-sink,
kafka-batch-source and ceph-event-based-source have the identical shape
and are deliberately left alone here.
Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
davsclaus
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2970.
kafka-sourceshipped a plaintext, unauthenticated connection by default. This makes the choice explicit.The problem
saslAuthTypewas not inrequired, so deploying with onlytopicandbootstrapServersconnected to the broker in plaintext with no authentication — silently, and without the name saying so.The catalog's convention for that posture is to state it in the name. Worth correcting one detail from the issue text while we are here: there is no plain
kafka-not-secured-sourceor-sink. All sixnot-securedKamelets are apicurio-registry variants, and they do not defaultsaslAuthType— they omit it entirely and say "on an insecure broker" in the description. So there was no sibling to point users at either.The change
required: - topic - bootstrapServers + - saslAuthTypesaslAuthType: title: Authentication Type - description: Authentication type to use. Use NONE for no authentication, PLAIN or ... + description: Authentication type to use. This has no default and must be set explicitly. Use NONE for no authentication, which leaves the broker connection plaintext and unauthenticated, PLAIN or ... type: string - default: NONENONEstays available and behaves exactly as before. It just has to be asked for rather than inherited.Breaking change
A deployment that relied on the implicit default now fails at startup, by name, instead of connecting insecurely. Verified on Camel 4.22.0 with
camel runagainst the working tree:Omitted:
Explicit
saslAuthType: NONE: no validation error; the route starts and proceeds to the broker connection unchanged.That is the intended shape of the break — a named, startup-time failure with an obvious fix, not a silent behaviour change and not an obscure unresolved-placeholder error.
What else had to move
Two in-tree consumers relied on the default:
tests/.../kafka/kafka-source-route.yamlomitted the property and would have broken. Now setssaslAuthType: 'NONE'.KafkaITis green locally with the change:kafka-source-description.adocstated the default in two places ("which defaults toNONE, so out of the box the Kamelet connects to an unauthenticated broker" and "defaultNONE").Both pipe templates —
templates/pipes/camel-k/andtemplates/pipes/core/— already passsaslAuthType: "NONE"explicitly, so they needed nothing.mvn clean install -DskipTestsfrom the root is clean; the regeneratedlibrary/camel-kameletscopy is byte-identical to the canonical Kamelet.Two things for reviewers
1. Scope. This is
kafka-sourceonly, which is what the issue covers.kafka-sink,kafka-batch-sourceandceph-event-based-sourcehave the identical shape —default: NONE, not inrequired— and are deliberately untouched here rather than quietly swept in. Happy to extend this PR or file it separately, whichever you prefer.2. Upgrade guide. This repository has no upgrade guide. The note this change warrants belongs in
apache/camel'sdocs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc, which does carry Kamelet entries. That is a separate cross-repo PR — say the word and I will open it.Claude Code on behalf of Andrea Cosentino