[ 
https://issues.apache.org/jira/browse/CAMEL-24733?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen updated CAMEL-24733:
--------------------------------
    Fix Version/s: 4.23.0

> camel-spiffe - add integration tests against a real SPIRE agent
> ---------------------------------------------------------------
>
>                 Key: CAMEL-24733
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24733
>             Project: Camel
>          Issue Type: Test
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> h2. Problem
> {{camel-spiffe}} has *no integration tests and no test-infra module*:
> {noformat}
> camel-spiffe ITs: (none)                   test-infra: NONE
> camel-opa    ITs: OpaIT, OpaBearerTokenIT  test-infra: camel-test-infra-opa
> {noformat}
> Everything is unit-tested against a mocked {{WorkloadApiClient}} / 
> {{X509Source}}. That means {{SpiffeSSLContextParameters}} - the class that 
> builds the mTLS {{SSLContext}} and decides which peers are accepted, and so 
> the most security-critical code in the component - has never run against a 
> real Workload API.
> The gaps that mocks structurally cannot cover:
> * the {{X509Source}} lifecycle against a live endpoint (lazy creation, the 
> {{initTimeout}} bound, close-on-shutdown, cache invalidation on restart)
> * whether the {{SSLContextDecorator}} wrapping actually preserves 
> {{clientAuthentication}} / {{cipherSuites}} / {{secureSocketProtocols}} on a 
> real handshake - a defect of exactly this kind was found by review during 
> CAMEL-24571 and fixed without a test that would catch a regression
> * whether {{acceptedSpiffeIds}} really rejects a peer outside the allow-list, 
> and {{acceptAnySpiffeId}} really accepts one inside the trust domain
> * SVID rotation
> h2. Proposal
> Add {{test-infra/camel-test-infra-spiffe}} running a SPIRE server plus agent, 
> mirroring {{camel-test-infra-opa}}, and ITs that:
> * fetch an X509-SVID and a JWT-SVID from the real Workload API
> * validate a JWT-SVID, and reject one minted for another audience
> * complete a real mTLS handshake through {{SpiffeSSLContextParameters}}, 
> asserting both that an allow-listed peer connects and that a non-allow-listed 
> one is refused
> Note the image constraint from the Camel guidelines: prefer {{mirror.gcr.io}} 
> or {{quay.io}} over Docker Hub, and check {{amd64}}/{{ppc64le}}/{{s390x}} 
> availability - {{camel-opa}} had to set {{skipITs.ppc64le}} and 
> {{skipITs.s390x}} for the same reason.
> h2. Scope
> {{main}} only. Test-only, plus a new test-infra module.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to