Skip to content

[improve][build] Upgrade Athenz to 1.12.42 - #25905

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-athenz-1.12.42
Jun 1, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-improve-athenz-1.12.42

Conversation

@lhotari

@lhotari lhotari commented May 31, 2026 •

Copy link
Copy Markdown
Member

Motivation

The Athenz client/server libraries (com.yahoo.athenz) used by the
pulsar-client-auth-athenz and pulsar-broker-auth-athenz authentication
plugins were pinned to 1.10.62, which is several years old. Upgrading to
1.12.42 picks up upstream bug fixes, dependency/security updates, and keeps
the integration on a maintained release line.

More importantly, this upgrade is a prerequisite for the javax.* →
jakarta.* migration
(PIP-472).
The old Athenz ZTS client (1.10.62) used Jersey and therefore dragged the
JAX-RS (javax.ws.rs) API onto the classpath transitively. JAX-RS is the
single largest migration surface in PIP-472 (~660 files), and a lingering
javax.ws.rs dependency pulled in by Athenz would be a conflicting problem for
the move to jakarta.ws.rs. Athenz 1.11.0 removed Jersey/JAX-RS from the
client in favor of Apache HttpClient5, so upgrading to 1.12.42 drops that
conflicting JAX-RS dependency — at which point it is no longer a blocker for the
PIP-472 implementation.

Modifications

  • Bump athenz in gradle/libs.versions.toml from 1.10.62 to 1.12.42.
    This single version ref governs all four Athenz artifacts used by Pulsar:
    athenz-zts-java-client, athenz-zpe-java-client, athenz-cert-refresher
    and athenz-auth-core.

No source changes are required. Every Athenz API used by Pulsar keeps an
identical signature in 1.12.42. The breaking changes introduced in Athenz
1.11.0 — the ZTS client is no longer shaded, Jersey/JAX-RS was replaced by
Apache HttpClient5, JDK 11+ is required, and athenz-zts-java-client-core plus
ZTSClient.setProperty()/getClientBuilder() were removed — do not affect
Pulsar: it uses none of the removed APIs/artifact and targets JDK 17/21.

No LICENSE/NOTICE changes are required. The Athenz auth modules are
standalone plugins and are not bundled in any Pulsar binary distribution
(server/shell), so the per-jar LICENSE.bin.txt accounting is unaffected by the
Athenz version change. The new transitive dependencies pulled in by 1.12.x
(e.g. Apache HttpClient5) are likewise not bundled.

Note

The ZTS client's HTTP transport changed internally from Jersey to Apache
HttpClient5 in the 1.11.x line. The public API is unchanged, but this is a
behavior-surface change; the existing unit tests mock ZTSClient, so a full
CI run (including any Athenz integration coverage) is the real end-to-end
check.

Verifying this change

This change is already covered by existing tests:

  • pulsar-client-auth-athenz — AuthenticationAthenzTest (8/8 pass against 1.12.42)
  • pulsar-broker-auth-athenz — AuthenticationProviderAthenzTest (4/4 pass against 1.12.42)

Both modules compile cleanly (compileJava + compileTestJava) and all 12 unit
tests pass locally against Athenz 1.12.42 with no deprecation/removal warnings.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

### Motivation

The Athenz client/server libraries (com.yahoo.athenz) used by the
pulsar-client-auth-athenz and pulsar-broker-auth-athenz auth plugins were
pinned to 1.10.62, which is several years old. Upgrading to 1.12.42 picks up
upstream bug fixes, dependency/security updates, and keeps the integration on a
maintained release line.

### Modifications

- Bump `athenz` in `gradle/libs.versions.toml` from 1.10.62 to 1.12.42. This
  governs athenz-zts-java-client, athenz-zpe-java-client, athenz-cert-refresher
  and athenz-auth-core via the shared version ref.

No source changes are required: every Athenz API used by Pulsar keeps an
identical signature in 1.12.42. The breaking changes introduced in Athenz 1.11.0
(unshaded ZTS client, Jersey/JAX-RS replaced by Apache HttpClient5, JDK 11+
required, removed athenz-zts-java-client-core artifact and
ZTSClient.setProperty()/getClientBuilder()) do not affect Pulsar, which uses none
of the removed APIs and targets JDK 17/21. Both auth modules compile cleanly and
all unit tests pass (pulsar-client-auth-athenz 8/8, pulsar-broker-auth-athenz
4/4).

No LICENSE/NOTICE changes are needed: the Athenz auth modules are standalone
plugins and are not bundled in any binary distribution, so the per-jar
LICENSE.bin.txt accounting is unaffected by the version change.

Assisted-by: Claude Code (Opus 4.8)
@nodece
nodece merged commit 14e228c into apache:master Jun 1, 2026
44 checks passed
lhotari added a commit to lhotari/pulsar that referenced this pull request Jun 1, 2026
….12.42 uses jakarta.xml.bind)

Motivation:
Earlier in this PR a temporary `runtimeOnly(libs.jaxb.api)` (javax.xml.bind:jaxb-api:2.3.1) was
added to pulsar-client-auth-athenz and pulsar-broker-auth-athenz to satisfy Athenz 1.10.62, whose
shaded jackson-module-jaxb-annotations referenced the legacy javax.xml.bind package (which the
jakarta.xml.bind-api 4.0.2 bump no longer ships).

master has since upgraded Athenz to 1.12.42 (apache#25905, 14e228c), which itself migrated to
jakarta.xml.bind: athenz-auth-core now pulls org.glassfish.jaxb:jaxb-runtime:4.0.8. The legacy
javax.xml.bind classes are therefore no longer needed on the Athenz runtime classpath, so the
workaround is obsolete.

Modifications:
- Remove `runtimeOnly(libs.jaxb.api)` from pulsar-client-auth-athenz and pulsar-broker-auth-athenz
  (both build files revert to their pre-PR state).
- De-Athenz the gradle/libs.versions.toml jaxb-api comment: the alias is retained because it is now
  used only by the tiered-storage offloaders (jclouds/Hadoop), which still reference legacy
  javax.xml.bind.
- Update pip/pip-472-notes.md (issue 2, the CI iteration log) to record the upstream resolution.

Verified: AuthenticationAthenzTest (8) and AuthenticationProviderAthenzTest (4) pass, and
javax.xml.bind:jaxb-api is no longer on the Athenz runtimeClasspath (only the jakarta stack:
jakarta.xml.bind-api 4.0.5 + org.glassfish.jaxb:jaxb-runtime 4.0.8).

Assisted-by: Claude Code (Opus 4.8)
@lhotari lhotari added this to the 5.0.0-M1 milestone Jun 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants