Skip to content

fix(OMN-14974): create TLS context for managed Kafka - #2487

Merged
jonahgabriel merged 1 commit into
devfrom
jonah/omn-14974-msk-default-ssl-context
Jul 27, 2026
Merged

jonahgabriel merged 1 commit into
devfrom
jonah/omn-14974-msk-default-ssl-context

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • create an ssl.SSLContext for both SSL and SASL_SSL, even when the system trust store is used
  • preserve the existing custom-CA behavior
  • add regression coverage for the exact MSK IAM configuration used in staging

Why

The exact candidate runtime reached both staging MSK brokers but all three new pods exited before SASL/IAM authentication. aiokafka rejects an SSL transport without an explicit ssl_context; the shared auth helper only created one when KAFKA_SSL_CA_FILE was set. The staging configuration correctly uses SASL_SSL + AWS_MSK_IAM + the system trust store, so the helper must construct the default context.

Verification

  • RED before source fix: test_msk_iam_builds_default_aiokafka_ssl_context failed with KeyError: ssl_context
  • GREEN after source fix: 126 focused Kafka/MSK tests passed
  • governed pre-push impacted suite: 8,681 passed, 26 skipped
  • Ruff format/check, strict mypy, scoped pre-commit: pass

Live evidence and rollout

  • staging target: managed MSK, 2 brokers, SASL_SSL, AWS_MSK_IAM
  • failure occurs before IAM authentication with ValueError: ssl_context is mandatory
  • Redpanda StatefulSet/PVC and the prior immutable runtime digest remain available until the corrected image passes live workflow proof

Ticket: OMN-14974

Evidence-Ticket: OMN-14974
Evidence-Source: OCC#5063
Evidence-Commit: 36b8166796fc6c96700fd3ee52fb05c4516c4415

Evidence-Source: OCC#5063
Evidence-Commit: 36b8166796fc6c96700fd3ee52fb05c4516c4415
Evidence-Head: 40ceacf

@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 58 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 4a963f29-7beb-4792-8fd2-2689fc8d08df

📥 Commits

Reviewing files that changed from the base of the PR and between 6e5ce53 and 40ceacf.

📒 Files selected for processing (2)
  • src/omnibase_infra/event_bus/kafka_auth.py
  • tests/unit/event_bus/test_msk_auth_direct_clients.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-14974-msk-default-ssl-context

Comment @coderabbitai help to get the list of available commands.

jonahgabriel added a commit to OmniNode-ai/onex_change_control that referenced this pull request Jul 27, 2026
Land OCC evidence companion for OMN-14974 / omnibase_infra#2487.
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Hostile Reviewer — DEGRADED (informational)

Blocking findings (critical): 0
Total findings: 0
Models succeeded: none

Note: All reviewer models failed or were unavailable. Degraded results are informational during the pilot phase (OMN-8468/OMN-8524) and do not block merge. Error: all review endpoints [192.168.86.201:8000 192.168.86.201:8001 ] unreachable — preflight short-circuit (no models available)


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

@jonahgabriel
jonahgabriel merged commit 96528fb into dev Jul 27, 2026
155 of 164 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-14974-msk-default-ssl-context branch July 27, 2026 00:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant