Skip to content

Commit 2d7f681

Browse files
ci: re-enable the Kafka auth test suite (fixes for Confluent Platform 8.x) (#37470)
## Summary Re-enables the Kafka auth test suite, disabled since #36405 (SS-115), and fixes the two breakages that accumulated while it was dark. ## What broke while the suite was disabled The Confluent Platform 7.9.4 → 8.2.0 bump (#36683) landed three weeks after the suite was skipped, and broke its setup in two ways nothing could catch: 1. **Schema registry basic auth returned 401 for everyone.** CP 8.x ships Jetty 12, which moved the JAAS login modules from `org.eclipse.jetty.jaas.spi` to `org.eclipse.jetty.security.jaas.spi`. Our `schema-registry.jaas.config` referenced the old class, so the login module never loaded and every request, correct credentials included, got 401. Verified directly: `curl -u materialize:sekurity` against the container → 401 before, 200 after the one-line class-path fix (wrong/missing creds still 401). 2. **Kafka mssl negative tests asserted TLS 1.2 alert text.** CP 8.x brokers negotiate TLS 1.3, where a missing/untrusted client certificate fails with `tlsv13 alert certificate required` (alert 116) instead of `ssl/tls alert bad certificate` (alert 42). The assertions now check only that the broker rejected the connection with a TLS alert. The exact wording is a function of TLS version and OpenSSL build that we do not control. This is the third exact-text loosening in this suite's history (#30501, #36232), so the loosening deliberately goes all the way rather than chasing the new strings. ## On the original SS-115 flake The `PEM routines:get_name:no start line` flake that got the suite disabled did not reproduce in local full-suite runs against current main images (reqwest 0.12) or against the reqwest 0.13.4 branch (#37469). Timeline evidence from SS-115 itself shows the flake continued after the reqwest 0.13 revert (#36241), so reqwest was likely misattributed. If it resurfaces, the `ci-regexp` in SS-115 will link it; the suite being enabled is what gives us the data to root-cause it. ## Why now Two in-flight workstreams change exactly the surface this suite covers: the reqwest 0.13 re-application (#37469) and the rdkafka → AWS-LC switch (#35941). Landing those with this suite dark is how auth/TLS regressions reach production unobserved. ## Test plan - [x] Full suite green locally against main images (all fixes applied) - [x] Repeated local runs to probe for the SS-115 flake: 8 consecutive local full-suite passes (5-run loop + 3 individual), plus 2 clean runs on the reqwest-0.12 main baseline. The PEM flake did not reproduce. - [ ] Kafka auth 1–3 green in this PR's CI (the un-skip makes them run here) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Jason Hernandez <7144515+jasonhernandez@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1 parent 584bb90 commit 2d7f681

4 files changed

Lines changed: 15 additions & 6 deletions

File tree

‎ci/test/pipeline.template.yml‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -444,7 +444,6 @@ steps:
444444
composition: kafka-auth
445445
agents:
446446
queue: hetzner-aarch64-8cpu-16gb
447-
skip: "https://linear.app/materializeinc/issue/SS-115"
448447

449448
- id: kafka-exactly-once
450449
label: Kafka exactly-once

‎test/kafka-auth/schema-registry.jaas.config‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,8 @@
77
// the Business Source License, use of this software will be governed
88
// by the Apache License, Version 2.0.
99

10+
// NOTE: Jetty 12 (Confluent Platform 8.x) moved the JAAS login modules from
11+
// org.eclipse.jetty.jaas.spi to org.eclipse.jetty.security.jaas.spi.
1012
SchemaRegistry {
11-
org.eclipse.jetty.jaas.spi.PropertyFileLoginModule required file="/etc/schema-registry/user.properties";
13+
org.eclipse.jetty.security.jaas.spi.PropertyFileLoginModule required file="/etc/schema-registry/user.properties";
1214
};

‎test/kafka-auth/test-kafka-mssl.td‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,15 +29,19 @@ banana
2929
BROKER 'kafka:9094',
3030
SSL CERTIFICATE AUTHORITY = '${ca-crt}'
3131
)
32-
contains:ssl/tls alert bad certificate
32+
# NOTE: the exact alert text varies with the negotiated TLS version and
33+
# OpenSSL build (TLS 1.2: "ssl/tls alert bad certificate", TLS 1.3:
34+
# "tlsv13 alert certificate required"), so assert only that the broker
35+
# rejected the connection with a TLS alert.
36+
contains:alert
3337

3438
! CREATE CONNECTION kafka_invalid TO KAFKA (
3539
BROKER 'kafka:9094',
3640
SSL CERTIFICATE '${kafka1-crt}',
3741
SSL KEY SECRET kafka1_key,
3842
SSL CERTIFICATE AUTHORITY '${ca-crt}'
3943
)
40-
contains:ssl/tls alert certificate unknown
44+
contains:alert
4145

4246
! CREATE CONNECTION kafka_invalid TO KAFKA (
4347
BROKER 'kafka:9094',

‎test/kafka-auth/test-kafka-sasl-mssl.td‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,11 @@ banana
3333
SASL PASSWORD SECRET password,
3434
SSL CERTIFICATE AUTHORITY = '${ca-crt}'
3535
)
36-
contains:ssl/tls alert bad certificate
36+
# NOTE: the exact alert text varies with the negotiated TLS version and
37+
# OpenSSL build (TLS 1.2: "ssl/tls alert bad certificate", TLS 1.3:
38+
# "tlsv13 alert certificate required"), so assert only that the broker
39+
# rejected the connection with a TLS alert.
40+
contains:alert
3741

3842
! CREATE CONNECTION kafka_invalid TO KAFKA (
3943
BROKER 'kafka:9097',
@@ -44,7 +48,7 @@ contains:ssl/tls alert bad certificate
4448
SSL KEY SECRET kafka1_key,
4549
SSL CERTIFICATE AUTHORITY '${ca-crt}'
4650
)
47-
contains:ssl/tls alert certificate unknown
51+
contains:alert
4852

4953
! CREATE CONNECTION kafka_invalid TO KAFKA (
5054
BROKER 'kafka:9097',

0 commit comments

Comments
 (0)