[ 
https://issues.apache.org/jira/browse/CAMEL-24571?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino reassigned CAMEL-24571:
----------------------------------------

    Assignee: Andrea Cosentino

> camel-spiffe: provide an SSLContextParameters backed by the SPIFFE Workload 
> API (rotating mTLS)
> -----------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24571
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24571
>             Project: Camel
>          Issue Type: New Feature
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> Follow-up to CAMEL-23305 (camel-spiffe, first increment shipped in 4.23.0, 
> which delivered the fetchX509Svid / fetchJwtSvid / validateJwtSvid producer 
> operations). This issue tracks the second increment: a Camel 
> SSLContextParameters backed by the SPIFFE Workload API, so any Camel 
> component that accepts sslContextParameters (camel-http, camel-netty-http, 
> camel-jetty, camel-vertx-http, camel-kafka, ...) can obtain zero-trust mTLS 
> with automatic SVID rotation.
> h3. Approach
> * Add a dependency on io.spiffe:java-spiffe-provider (same 
> ${java-spiffe-version} = 0.8.17 already used for java-spiffe-core; 
> Apache-2.0; confirmed on Maven Central) - the SSL companion library.
> * Introduce org.apache.camel.component.spiffe.SpiffeSSLContextParameters 
> extends org.apache.camel.support.jsse.SSLContextParameters, overriding 
> createSSLContext(CamelContext) to build the SSLContext from a live 
> io.spiffe.workloadapi.X509Source (via 
> io.spiffe.provider.SpiffeSslContextFactory / SpiffeKeyManager + 
> SpiffeTrustManager) instead of from keystores. createSSLContext(CamelContext) 
> is public and non-final on core/camel-api 
> .../support/jsse/SSLContextParameters.java (around line 251), so a subclass 
> is the idiomatic drop-in: users set sslContextParameters=#spiffeSsl on any 
> component and get rotating SPIFFE mTLS.
> h3. Options
> * spiffeSocketPath - reuse the component semantics; default from the 
> SPIFFE_ENDPOINT_SOCKET env var.
> * acceptedSpiffeIds - comma-separated allow-list of peer SPIFFE IDs the 
> TrustManager accepts; OR acceptAnySpiffeId=true to accept any SVID validated 
> against the trust bundle without pinning a specific ID.
> h3. Lifecycle (the design-heavy part)
> The X509Source is a long-lived, auto-updating resource that MUST be closed. 
> Create the DefaultX509Source lazily on first createSSLContext and register it 
> for shutdown with the CamelContext (camelContext.addService(...) / a 
> ShutdownableService) so it is closed on context stop and never leaked; cache 
> the built SSLContext/source to avoid re-creating on a started context (cf. 
> the vertexai doStart-on-started-context lesson). Alternatively reuse 
> io.spiffe.provider.X509SourceManager for a shared JVM-wide source.
> h3. Tests and docs
> * Unit-test the option plumbing with a mocked X509Source. An integration test 
> against a SPIRE agent is optional/manual (no emulator in CI) - gate it 
> accordingly.
> * Extend spiffe-component.adoc with an 'mTLS via SSLContextParameters' 
> section and an example wiring #spiffeSsl into camel-http / camel-netty-http.
> Feasibility confirmed: java-spiffe-provider 0.8.17 is on Maven Central 
> (Apache-2.0) and the SSLContextParameters extension point exists and is 
> non-final.
> _Filed by Claude Code on behalf of Andrea Cosentino (@oscerd)._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to