Spring Cloud Vault/Zookeeper do not add property sources if context paths are the same
Maintainers usually reply within 1 day
@mp911de is already working on this.
Since Oct 8, 2024.
Assessment
This issue has not been assessed yet.
Description
Hello,
It seems that there is a bug or limitation in the Spring Boot + Spring Cloud project.
Problem description:
Precondition:
- There is a Zookeeper instance where configuration parameters are stored in the following paths:
- /config/application
- /config/${spring.application.name}
- There is a HashiCorp Vault instance where configuration parameters ("credentials") are stored in the following paths:
- /config/application
- /config/${spring.application.name}
Yes, you noticed correctly — the issue is that Zookeeper and Vault have the same paths.
How to reproduce:
Create a Spring Boot application (in my case, I used Spring Boot 2.7.18, but looking at the source code, the problem will occur in the latest version as well) and connect spring-cloud-starter-vault-config (in my case, version 3.1.4, but the same issue exists in the master branch) and spring-cloud-starter-zookeeper-config (in my case, version 3.1.5, it looks the same issue exists in the master branch).
When the application starts, only one configuration source will work, specifically the one listed first in spring.config.import.
For example, with the following configuration:
spring.config.import:
- "optional:zookeeper:"
- "optional:vault://"
The application will not have a Vault property source with the required paths.
In this case:
spring.config.import:
- "optional:vault://"
- "optional:zookeeper:"
The application will not have a Zookeeper property source with the required paths.
The issue relates to the *ConfigDataLoader classes.
For example, in spring-cloud-vault-config: the VaultConfigDataLoader (see here)
it creates a LeaseAwareVaultPropertySource with name() == path value. A similar approach is used for Zookeeper.
Then, when starting Spring Boot, in the class org.springframework.boot.context.config.ConfigDataEnvironment, all property sources are added to the property sources list, and here we encounter an issue: the method propertySources.addLast(propertySource); is used (see here).
However, the propertySources.addLast method removes the already added property source from the list based on the equals method, and the equals method in PropertySource is primitive and validates only by name.
So, for both the Vault property source and the Zookeeper property source, we end up with the same names, as they are equal to the path. Adding one removes the other.
Here are links to the source code:
https://github.com/spring-projects/spring-boot/blob/v3.3.4/spring-boot-project/spring-boot/src/main/java/org/springframework/boot/context/config/ConfigDataEnvironment.java#L357
https://github.com/spring-projects/spring-framework/blob/v6.1.13/spring-core/src/main/java/org/springframework/core/env/MutablePropertySources.java#L116
https://github.com/spring-projects/spring-framework/blob/v6.1.13/spring-core/src/main/java/org/springframework/core/env/PropertySource.java#L143
It seems that the simplest way to fix this would be to add a prefix when creating the Vault/Zookeeper property source so that not only the path is considered, but also some indicator of which configuration source it belongs to.
For example, for Vault, it could look like this:
String propertySourceName = "vault:" + accessor.getName();
LeaseAwareVaultPropertySource propertySource = new LeaseAwareVaultPropertySource(propertySourceName, secretLeaseContainer, secret, accessor.getPropertyTransformer());
Thanks, have a good day!
- Dominant language
- Java
- Stars
- 291
- Forks
- 152
- Avg merge
- 3h 34m
- Merged PRs (30d)
- 16
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from spring-cloud/spring-cloud-vault
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
spring-cloud/spring-cloud-vault#952 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
spring-cloud/spring-cloud-vault#958 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
spring-cloud/spring-cloud-vault#953 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
spring-cloud/spring-cloud-vault#942 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 48/100
spring-cloud/spring-cloud-vault#940 · 1 reaction ·
Maintainers usually reply within 1 day
All issues in spring-cloud/spring-cloud-vault
Similar issues
-
[BUG] 订单:会员凭订单号即可取消其他会员的待付款订单(取消接口不校验订单归属)Possibly taken @dadiyang claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
macrozheng/mall#1016 ·
-
[Bug] The producer summary counts an unreported client version as a second version and warns about a version mixPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
apache/rocketmq-dashboard#6110 ·
Maintainers usually reply within 4 days
-
Feature:Resolution
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
intellij-elixir/intellij-elixir#4396 ·
Maintainers usually reply within 1 day
-
Python 3.15 supportPossibly taken @amnesiaof claimed this today. OpenL: python L: python:uv
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
dependabot/dependabot-core#16524 · 1 comment ·
Maintainers usually reply within 1 day
-
`Processing lsp` never exits and leaves orphaned processesPossibly taken @overcast302 claimed this today. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
processing/processing4#1578 · 1 comment ·