Skip to content

feat: replace KUBERNETES_M2M_ENABLED with M2M_AUTH_MODE - #213

Merged
alsergs merged 9 commits into
mainfrom
feat/m2m-auth-mode
Oct 8, 2026
Merged

alsergs merged 9 commits into
mainfrom
feat/m2m-auth-mode

Conversation

@TaurMorchant

@TaurMorchant TaurMorchant commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Part of Netcracker/qubership-core-infra#428.

Replaces the boolean KUBERNETES_M2M_ENABLED with M2M_AUTH_MODE in the Java M2M, DBaaS, and MaaS clients:

Mode Token DBaaS and MaaS address
legacy (default, the former false) Legacy M2M token dbaas-agent, maas-agent
hybrid (the former true) Kubernetes token, then the legacy token after a token error or a 401 api.dbaas.address, maas.internal.address, or the agent when not set
k8s Kubernetes token only The direct address only; client creation fails without it
  • M2MAuthMode.readFromEnv() in k8s-utils is the single parser. An unsupported value fails the service at startup.
  • An empty address counts as not set.
  • The MaaS client, which has no framework config, reads maas.internal.address from a system property or MicroProfile Config, then from the MAAS_INTERNAL_ADDRESS environment variable, so Spring services get the address from their chart.
  • In k8s, keycloakTokenSupplier of M2MClient is optional.

Breaking API, without deprecation:

Before After
M2MClient.isK8sM2mEnabled() M2MAuthMode.readFromEnv()
M2MClientBuilder.k8sM2mEnabled(boolean) M2MClientBuilder.mode(M2MAuthMode)
new M2MInterceptor(boolean, ...) new M2MInterceptor(M2MAuthMode, ...)
Env.apiUrl(boolean) Env.apiUrl(M2MAuthMode)

Covers the direct address when the Kubernetes token is accepted, the
uncached target after a failed fallback, and the built client reading
KUBERNETES_M2M_ENABLED, so the switch to M2M_AUTH_MODE can be checked
against the current behavior.
The boolean flag could not express a cluster that uses only Kubernetes
tokens: with KUBERNETES_M2M_ENABLED=true the M2M client still fell back
to the legacy token and the DBaaS and MaaS clients to their agents, and
any value other than true silently meant false.

M2M_AUTH_MODE takes legacy (the default and the former false), hybrid
(the former true), or k8s, which sends only the Kubernetes token, never
falls back, and does not need keycloakTokenSupplier. An unsupported
value, true and false included, throws IllegalArgumentException when a
client is built, so a misconfigured service fails at startup. In k8s
mode the DBaaS and MaaS clients require api.dbaas.address and
maas.internal.address and throw IllegalStateException at creation
without them.

M2MClientBuilder.k8sM2mEnabled(boolean), M2MClient.isK8sM2mEnabled(),
the boolean M2MInterceptor constructors, and Env.apiUrl(boolean) move
to M2MAuthMode. The feature is unreleased, so there is no deprecation.

Refs: Netcracker/qubership-core-infra#428
@github-actions github-actions Bot added the enhancement New feature or request label Sep 30, 2026
…IllegalStateException

M2MClientBuilder.build now throws IllegalStateException instead of
NullPointerException when keycloakTokenSupplier is missing outside k8s
mode, and M2MAuthMode.ENV becomes M2M_AUTH_MODE_ENV. Also trims the
new documentation and drops the CHANGELOG entry.

Refs: Netcracker/qubership-core-infra#428
An empty api.dbaas.address in Spring passed the k8s check and became the
DBaaS URL, and an empty maas.internal.address failed URL parsing with
IllegalArgumentException even in legacy mode. Now k8s rejects an empty
address and hybrid falls back to the agent.

Part of Netcracker/qubership-core-infra#428.
…ybrid mode

The hybrid path fell back only on IllegalStateException and
IllegalArgumentException. A token file that exists but cannot be read
surfaces as a RuntimeException, so the request failed instead of using the
legacy token.

Part of Netcracker/qubership-core-infra#428.
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Oct 2, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@alsergs
alsergs marked this pull request as ready for review October 7, 2026 22:54
@alsergs
alsergs requested a review from lis0x90 as a code owner October 7, 2026 22:54
@alsergs
alsergs merged commit 75b5496 into main Oct 8, 2026
8 checks passed
@alsergs
alsergs deleted the feat/m2m-auth-mode branch October 8, 2026 09:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working documentation Improvements or additions to documentation enhancement New feature or request refactor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Refactor KUBERNETES_M2M_ENABLED property logic

4 participants