[ 
https://issues.apache.org/jira/browse/CAMEL-24738?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18118285#comment-18118285
 ] 

Andrea Cosentino commented on CAMEL-24738:
------------------------------------------

Fixed via https://github.com/apache/camel/pull/26664 (squash commit 
1f762d21591e06b5ccb067b80a981234ee6c824a), merged to main for 4.23.0. camel-opa 
is new in 4.23.0, so no backport is needed.

_Claude Code on behalf of acosentino_

> camel-opa - make a failOpen decision observable
> -----------------------------------------------
>
>                 Key: CAMEL-24738
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24738
>             Project: Camel
>          Issue Type: Improvement
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>             Fix For: 4.23.0
>
>
> h2. Problem
> When {{failOpen=true}} and the policy cannot be evaluated, {{camel-opa}} lets 
> the exchange through and records it only as a log line:
> {code:java}
> LOG.warn("Policy {} could not be evaluated, allowing the exchange to proceed 
> because failOpen is"
>          + " enabled. Reason: {}", policyPath, e.getMessage());
> {code}
> "This route is currently allowing traffic that was never authorized" is 
> precisely the condition an operator wants to alert on, and a WARN in the 
> application log is the weakest possible channel for it - easy to lose in 
> volume, and invisible to metrics-based monitoring.
> h2. Proposal
> Surface it through a channel monitoring can consume. Options, roughly in 
> order of cost:
> # Set a header (e.g. {{CamelOpaDecisionFailedOpen=true}}) alongside the 
> existing decision headers, so a route can branch on it and an operator can 
> assert it is never set in production. Cheapest, and consistent with how the 
> component already reports decisions.
> # Register the condition on the health check added in CAMEL-24644, so a route 
> that is failing open shows DEGRADED rather than UP.
> # Emit a Camel event.
> Option 1 alone would already be a large improvement and pairs with the 
> existing {{CamelOpaDecision}} headers; the {{DECISION}} header is already set 
> to {{null}} on that path, so a route cannot currently distinguish "allowed by 
> policy" from "allowed because the PDP was down" without inspecting logs.
> h2. Scope
> {{main}} only. Additive; {{failOpen}} remains {{false}} by default and marked 
> {{insecure:dev}}.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to