x-itm commented on issue #20385:
URL: https://github.com/apache/druid/issues/20385#issuecomment-5746401240

   Regarding the `KubernetesClusterDockerTest` timeout: since the coordinator 
JVM successfully registered in ZooKeeper at 21s (`Node [...] of role 
[coordinator] detected`) yet the kubelet never marked the pod `Ready` within 
the 300s window, this points to an unready Pod condition rather than an 
application failure. Because the Deployment lacks an explicit readiness probe, 
the kubelet relies solely on container lifecycle state; under tight resource 
constraints (`DRUID_XMX=128m` plus loaded extensions like s3, kafka, and 
postgres), transient container restarts or k3s node pressure will leave the pod 
status stuck at `Ready=False` even while the JVM is healthy.
   
   For the Sonatype OSS Index HTTP 402 (`Guide credits insufficient`), the 
unescaped backtick fallback script triggers a second scan that matches 
`elasticache-java-cluster-client-1.2.4.jar` against memcached CPEs. Adding 
explicit error handling for API credit exhaustion (HTTP 402) rather than 
falling back to an uncredentialed scan will prevent these persistent CVE false 
positives from turning the cron job red daily.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to