Skip to content

fix(actions): pass the MSK IAM oauth_cb to the actions pod - #731

Merged
max-datahub merged 1 commit into
masterfrom
mm/actions-kafka-iam-oauth-cb
Oct 1, 2026
Merged

max-datahub merged 1 commit into
masterfrom
mm/actions-kafka-iam-oauth-cb

Conversation

@max-datahub

Copy link
Copy Markdown
Contributor

Summary

With global.kafka.iam.enabled: true, the actions pod receives KAFKA_PROPERTIES_SECURITY_PROTOCOL=SASL_SSL, KAFKA_PROPERTIES_SASL_MECHANISM=OAUTHBEARER and KAFKA_PROPERTIES_SASL_OAUTHBEARER_METHOD=default, but no token callback. librdkafka then has no way to get an MSK IAM token. This PR adds KAFKA_PROPERTIES_OAUTH_CB=datahub_actions.utils.kafka_msk_iam:oauth_cb, which points at the callback shipped in the actions image.

This pairs with datahub-project/datahub#20104, which makes the actions Kafka event source read KAFKA_PROPERTIES_*. On actions images from before that change, the variable is ignored and harmless.

The rest of the Kafka auth wiring already matches what the chart gives its other Kafka consumers: springKafkaConfigurationOverrides and credentialsAndCertsSecrets.secureEnv, including secret-backed values. The only gap was the IAM callback.

Render (global.kafka.iam.enabled: true, awsRegion: us-west-2)

-    helm.sh/chart: acryl-datahub-actions-0.3.11
+    helm.sh/chart: acryl-datahub-actions-0.3.12
             - name: KAFKA_PROPERTIES_SASL_OAUTHBEARER_METHOD
               value: default
+            - name: KAFKA_PROPERTIES_OAUTH_CB
+              value: "datahub_actions.utils.kafka_msk_iam:oauth_cb"

With IAM disabled, KAFKA_PROPERTIES_OAUTH_CB is not rendered.

Chart versions: acryl-datahub-actions 0.3.11 → 0.3.12, datahub 1.1.5 → 1.1.6.

Checklist

  • The PR conforms to DataHub's Contributing Guideline (particularly Commit Message Format)
  • Links to related issues (if applicable)
  • Tests for the changes have been added/updated (if applicable)
  • Docs related to the changes have been added/updated (if applicable)

🤖 Generated with Claude Code

With global.kafka.iam.enabled the actions pod gets SASL_SSL, OAUTHBEARER and
sasl.oauthbearer.method=default, but no token callback, so librdkafka has no
way to obtain an MSK IAM token. Set KAFKA_PROPERTIES_OAUTH_CB to the callback
shipped in the actions image (datahub_actions.utils.kafka_msk_iam:oauth_cb).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@max-datahub
max-datahub merged commit ad3a434 into master Oct 1, 2026
2 checks passed
@max-datahub
max-datahub deleted the mm/actions-kafka-iam-oauth-cb branch October 1, 2026 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants