Skip to content

fix(kafka-connect): apply connector state transition alongside config update - #826

Merged
fhussonnois merged 1 commit into
mainfrom
fix/gh-821
Sep 26, 2026
Merged

fhussonnois merged 1 commit into
mainfrom
fix/gh-821

Conversation

@fhussonnois

Copy link
Copy Markdown
Member

Fixes #821

Problem

When a single jikkou apply changed both a KafkaConnector's config and its spec.state, KafkaConnectorChangeHandler only sent PUT /connectors/{name}/config. That endpoint never changes a connector's target state, but the ChangeResponse covered the whole ResourceChange, so the state change was reported as applied and jikkou exited 0 while the connector stayed RUNNING.

Fix

updateConnector now sends the config update and the state transition together, ordered by the target state:

Target state Order
PAUSED / STOPPED pause/stop, then PUT /config (tasks never run with the new config)
RUNNING PUT /config, then resume (the connector resumes with the new config)

Both calls run sequentially in a single future, so a failure in the first step skips the second and the change is reported as an error.

Also in this method:

  • A target state of UNASSIGNED, RESTARTING or FAILED now returns an error instead of being silently dropped (no ChangeResponse at all).
  • case REPLACE returns Stream.empty() instead of null.

Tests

New cases in KafkaConnectorChangeHandlerTest (all failed before the fix):

  • config + PAUSED: pause then config update (InOrder)
  • config + STOPPED: stop then config update
  • config + RUNNING: config update then resume
  • pause fails: error reported, config update not sent
  • FAILED target state: error reported, no API call

./mvnw test -pl providers/jikkou-provider-kafka-connect is green; spotless:check passes.

@github-actions

Copy link
Copy Markdown
Contributor

Security Scan Results

Vulnerabilities detected:


Report Summary

┌───────────────────────────────────────────────────┬───────┬─────────────────┬─────────┐
│                      Target                       │ Type  │ Vulnerabilities │ Secrets │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ cli/pom.xml                                       │  pom  │        2        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ core/pom.xml                                      │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ docs/go.mod                                       │ gomod │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ extension-rest-client/pom.xml                     │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ pom.xml                                           │  pom  │       10        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ processor/pom.xml                                 │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-aiven/pom.xml           │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-aws/pom.xml             │  pom  │        1        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-confluent/pom.xml       │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-core/pom.xml            │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-iceberg/pom.xml         │  pom  │        5        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-kafka-connect/pom.xml   │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-kafka/pom.xml           │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ providers/jikkou-provider-schema-registry/pom.xml │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ resource-generator/pom.xml                        │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ server/jikkou-api-client/pom.xml                  │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ server/jikkou-api-data/pom.xml                    │  pom  │        0        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ server/jikkou-api-server/pom.xml                  │  pom  │        2        │    -    │
├───────────────────────────────────────────────────┼───────┼─────────────────┼─────────┤
│ template-jinja/pom.xml                            │  pom  │        0        │    -    │
└───────────────────────────────────────────────────┴───────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.70/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


cli/pom.xml (pom)
=================
Total: 2 (HIGH: 1, CRITICAL: 1)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │ HIGH     │        │ 5.3.4             │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

pom.xml (pom)
=============
Total: 10 (HIGH: 5, CRITICAL: 5)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5    │ CVE-2026-54399 │ HIGH     │        │ 5.4               │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5: Apache           │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via excessive HTTP   │
│                                              │                │          │        │                   │                             │ headers                                                     │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54399                  │
├──────────────────────────────────────────────┼────────────────┤          │        ├───────────────────┤                             ├─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │          │        │ 5.3.4             │                             │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        ├───────────────────┤                             │                                                             │
│                                              │                │          │        │ 5.4               │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
│                                              │                │          │        │                   │                             │                                                             │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.bouncycastle:bcprov-jdk18on              │ CVE-2026-8763  │ CRITICAL │        │ 1.84              │ 1.85                        │ org.bouncycastle/bcprov-jdk15on:                            │
│                                              │                │          │        │                   │                             │ org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java:    │
│                                              │                │          │        │                   │                             │ Name Constraints bypass via trailing dot...                 │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-8763                   │
│                                              ├────────────────┼──────────┤        │                   │                             ├─────────────────────────────────────────────────────────────┤
│                                              │ CVE-2026-13506 │ HIGH     │        │                   │                             │ bouncycastle: Bouncy Castle for Java: Denial of Service via │
│                                              │                │          │        │                   │                             │ lazy ASN.1 sequence...                                      │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-13506                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

providers/jikkou-provider-aws/pom.xml (pom)
===========================================
Total: 1 (HIGH: 0, CRITICAL: 1)

┌────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬───────────────────────────────────────────────────────┐
│        Library         │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                         Title                         │
├────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼───────────────────────────────────────────────────────┤
│ io.netty:netty-handler │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via │
│                        │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...     │
│                        │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595            │
└────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴───────────────────────────────────────────────────────┘

providers/jikkou-provider-iceberg/pom.xml (pom)
===============================================
Total: 5 (HIGH: 3, CRITICAL: 2)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5    │ CVE-2026-54399 │ HIGH     │        │ 5.4               │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5: Apache           │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via excessive HTTP   │
│                                              │                │          │        │                   │                             │ headers                                                     │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54399                  │
├──────────────────────────────────────────────┼────────────────┤          │        │                   │                             ├─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │          │        │                   │                             │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.bouncycastle:bcprov-jdk18on              │ CVE-2026-8763  │ CRITICAL │        │ 1.84              │ 1.85                        │ org.bouncycastle/bcprov-jdk15on:                            │
│                                              │                │          │        │                   │                             │ org.bouncycastle/bcpkix-jdk15on: Bouncy Castle for Java:    │
│                                              │                │          │        │                   │                             │ Name Constraints bypass via trailing dot...                 │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-8763                   │
│                                              ├────────────────┼──────────┤        │                   │                             ├─────────────────────────────────────────────────────────────┤
│                                              │ CVE-2026-13506 │ HIGH     │        │                   │                             │ bouncycastle: Bouncy Castle for Java: Denial of Service via │
│                                              │                │          │        │                   │                             │ lazy ASN.1 sequence...                                      │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-13506                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

server/jikkou-api-server/pom.xml (pom)
======================================
Total: 2 (HIGH: 1, CRITICAL: 1)

┌──────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬─────────────────────────────┬─────────────────────────────────────────────────────────────┐
│                   Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version        │                            Title                            │
├──────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ io.netty:netty-handler                       │ CVE-2026-75595 │ CRITICAL │ fixed  │ 4.2.16.Final      │ 4.2.17.Final, 4.1.137.Final │ io.netty/netty-handler: Netty: SNI Routing Bypass via       │
│                                              │                │          │        │                   │                             │ Fragmented TLS ClientHello Causing Fallback to...           │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-75595                  │
├──────────────────────────────────────────────┼────────────────┼──────────┤        ├───────────────────┼─────────────────────────────┼─────────────────────────────────────────────────────────────┤
│ org.apache.httpcomponents.core5:httpcore5-h2 │ CVE-2026-54428 │ HIGH     │        │ 5.3.4             │ 5.4.3, 5.5-beta2            │ org.apache.httpcomponents.core5/httpcore5-h2: Apache        │
│                                              │                │          │        │                   │                             │ HttpComponents Core: Denial of Service via oversized HTTP/2 │
│                                              │                │          │        │                   │                             │ HPACK header...                                             │
│                                              │                │          │        │                   │                             │ https://avd.aquasec.com/nvd/cve-2026-54428                  │
└──────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴─────────────────────────────┴─────────────────────────────────────────────────────────────┘

Scanned by Trivy

… update

When an update changed both a connector's config and its spec.state, only
PUT /connectors/{name}/config was sent. That endpoint never changes the
target state, yet the whole change was reported as applied.

The handler now sends both: it pauses or stops the connector before
updating its config, and resumes it after the new config is applied. A
failure in either step is reported as an error. Non-actionable target
states (UNASSIGNED, RESTARTING, FAILED) now return an error instead of
being silently dropped.

Fixes #821
@sonarqubecloud

Copy link
Copy Markdown

@fhussonnois
fhussonnois merged commit 488e97d into main Sep 26, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

KafkaConnector state transition is silently dropped when the apply also changes config

1 participant