Conversation
Signed-off-by: Craig Perkins <craig5008@gmail.com>
PR Reviewer Guide 🔍(Review updated until commit f272084)Here are some key observations to aid the review process:
|
PR Code Suggestions ✨Latest suggestions up to f272084
Previous suggestionsSuggestions up to commit 6ff2165
|
Signed-off-by: Craig Perkins <cwperx@amazon.com>
Signed-off-by: Craig Perkins <cwperx@amazon.com>
PR Code Analyzer ❗AI-powered 'Code-Diff-Analyzer' found issues on commit f272084. ⛔ Hard block: Issues at High severity or above will block this PR from merging.
The table above displays the top 10 most important findings. Pull Requests Author(s): Please update your Pull Request according to the report above. Repository Maintainer(s): You can Thanks. |
|
Persistent review updated to latest commit f272084 |
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #6475 +/- ##
==========================================
+ Coverage 75.99% 76.02% +0.03%
==========================================
Files 467 468 +1
Lines 31175 31241 +66
Branches 4692 4698 +6
==========================================
+ Hits 23691 23751 +60
- Misses 5306 5315 +9
+ Partials 2178 2175 -3
🚀 New features to boost your workflow:
|
Fixes #4004
Summary
plugins.security.dynamic_config.secrets.*secure-setting namespace${keystore:<alias>}ReloadablePluginsoPOST /_nodes/reload_secure_settingsrefreshes secrets and rebuilds the active security configurationmain, retaining upstream setting upgraders and secure-settings reload supportIntegration-test fix
The original integration failures were caused by
DynamicConfigSecrets.resolve()rebuilding every setting as a scalar. That converted a list-valued JWTsigning_keyinto one literal list string, which prevented authentication backends from initializing and caused broad401failures.The resolver now preserves the original
Settingsrepresentation and rewrites only exact keystore references. List-valued settings are read withgetAsList()and written withputList(). New regression coverage verifies unchanged structured settings and keystore references inside lists.Example
Add secrets to each node:
Reference them from
config.ymlor the corresponding security-index configuration:After changing the values on disk, reload them across the cluster:
Validation
./gradlew spotlessApplyDynamicConfigSecretsTestsandDynamicConfigModelV7TestsJwtAuthenticationTests, andLdapAuthenticationTest:integrationTestsuite exceeded the 30-minute local command limit without producing a result; CI is the full cross-platform verificationCheck List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.