Repository navigation
[improve][build] Upgrade Athenz to 1.12.42 - #25905
Merged
Merged
Conversation
### Motivation The Athenz client/server libraries (com.yahoo.athenz) used by the pulsar-client-auth-athenz and pulsar-broker-auth-athenz auth plugins were pinned to 1.10.62, which is several years old. Upgrading to 1.12.42 picks up upstream bug fixes, dependency/security updates, and keeps the integration on a maintained release line. ### Modifications - Bump `athenz` in `gradle/libs.versions.toml` from 1.10.62 to 1.12.42. This governs athenz-zts-java-client, athenz-zpe-java-client, athenz-cert-refresher and athenz-auth-core via the shared version ref. No source changes are required: every Athenz API used by Pulsar keeps an identical signature in 1.12.42. The breaking changes introduced in Athenz 1.11.0 (unshaded ZTS client, Jersey/JAX-RS replaced by Apache HttpClient5, JDK 11+ required, removed athenz-zts-java-client-core artifact and ZTSClient.setProperty()/getClientBuilder()) do not affect Pulsar, which uses none of the removed APIs and targets JDK 17/21. Both auth modules compile cleanly and all unit tests pass (pulsar-client-auth-athenz 8/8, pulsar-broker-auth-athenz 4/4). No LICENSE/NOTICE changes are needed: the Athenz auth modules are standalone plugins and are not bundled in any binary distribution, so the per-jar LICENSE.bin.txt accounting is unaffected by the version change. Assisted-by: Claude Code (Opus 4.8)
nodece
approved these changes
May 31, 2026
dao-jun
approved these changes
Jun 1, 2026
lhotari
added a commit
to lhotari/pulsar
that referenced
this pull request
Jun 1, 2026
….12.42 uses jakarta.xml.bind) Motivation: Earlier in this PR a temporary `runtimeOnly(libs.jaxb.api)` (javax.xml.bind:jaxb-api:2.3.1) was added to pulsar-client-auth-athenz and pulsar-broker-auth-athenz to satisfy Athenz 1.10.62, whose shaded jackson-module-jaxb-annotations referenced the legacy javax.xml.bind package (which the jakarta.xml.bind-api 4.0.2 bump no longer ships). master has since upgraded Athenz to 1.12.42 (apache#25905, 14e228c), which itself migrated to jakarta.xml.bind: athenz-auth-core now pulls org.glassfish.jaxb:jaxb-runtime:4.0.8. The legacy javax.xml.bind classes are therefore no longer needed on the Athenz runtime classpath, so the workaround is obsolete. Modifications: - Remove `runtimeOnly(libs.jaxb.api)` from pulsar-client-auth-athenz and pulsar-broker-auth-athenz (both build files revert to their pre-PR state). - De-Athenz the gradle/libs.versions.toml jaxb-api comment: the alias is retained because it is now used only by the tiered-storage offloaders (jclouds/Hadoop), which still reference legacy javax.xml.bind. - Update pip/pip-472-notes.md (issue 2, the CI iteration log) to record the upstream resolution. Verified: AuthenticationAthenzTest (8) and AuthenticationProviderAthenzTest (4) pass, and javax.xml.bind:jaxb-api is no longer on the Athenz runtimeClasspath (only the jakarta stack: jakarta.xml.bind-api 4.0.5 + org.glassfish.jaxb:jaxb-runtime 4.0.8). Assisted-by: Claude Code (Opus 4.8)
2 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The Athenz client/server libraries (
com.yahoo.athenz) used by thepulsar-client-auth-athenzandpulsar-broker-auth-athenzauthenticationplugins were pinned to 1.10.62, which is several years old. Upgrading to
1.12.42 picks up upstream bug fixes, dependency/security updates, and keeps
the integration on a maintained release line.
More importantly, this upgrade is a prerequisite for the
javax.*→jakarta.*migration (PIP-472).The old Athenz ZTS client (1.10.62) used Jersey and therefore dragged the
JAX-RS (
javax.ws.rs) API onto the classpath transitively. JAX-RS is thesingle largest migration surface in PIP-472 (~660 files), and a lingering
javax.ws.rsdependency pulled in by Athenz would be a conflicting problem forthe move to
jakarta.ws.rs. Athenz 1.11.0 removed Jersey/JAX-RS from theclient in favor of Apache HttpClient5, so upgrading to 1.12.42 drops that
conflicting JAX-RS dependency — at which point it is no longer a blocker for the
PIP-472 implementation.
Modifications
athenzingradle/libs.versions.tomlfrom1.10.62to1.12.42.This single version ref governs all four Athenz artifacts used by Pulsar:
athenz-zts-java-client,athenz-zpe-java-client,athenz-cert-refresherand
athenz-auth-core.No source changes are required. Every Athenz API used by Pulsar keeps an
identical signature in 1.12.42. The breaking changes introduced in Athenz
1.11.0 — the ZTS client is no longer shaded, Jersey/JAX-RS was replaced by
Apache HttpClient5, JDK 11+ is required, and
athenz-zts-java-client-coreplusZTSClient.setProperty()/getClientBuilder()were removed — do not affectPulsar: it uses none of the removed APIs/artifact and targets JDK 17/21.
No LICENSE/NOTICE changes are required. The Athenz auth modules are
standalone plugins and are not bundled in any Pulsar binary distribution
(server/shell), so the per-jar
LICENSE.bin.txtaccounting is unaffected by theAthenz version change. The new transitive dependencies pulled in by 1.12.x
(e.g. Apache HttpClient5) are likewise not bundled.
Note
The ZTS client's HTTP transport changed internally from Jersey to Apache
HttpClient5 in the 1.11.x line. The public API is unchanged, but this is a
behavior-surface change; the existing unit tests mock
ZTSClient, so a fullCI run (including any Athenz integration coverage) is the real end-to-end
check.
Verifying this change
This change is already covered by existing tests:
pulsar-client-auth-athenz—AuthenticationAthenzTest(8/8 pass against 1.12.42)pulsar-broker-auth-athenz—AuthenticationProviderAthenzTest(4/4 pass against 1.12.42)Both modules compile cleanly (
compileJava+compileTestJava) and all 12 unittests pass locally against Athenz 1.12.42 with no deprecation/removal warnings.
Does this pull request potentially affect one of the following parts: