Skip to content

Use secureClientPort instead of clientPort #480

Description

@maltesander

Currently for TLS and authentication we use the clientPort instead of secureClientPort due to a bug in ZooKeeper (https://issues.apache.org/jira/browse/ZOOKEEPER-4276).

Once this is fixed and we should switch from clientPort to secureClientPort and remove the portUnification property (allows plaintext and secured communication via the same port).

The necessary steps are documented in the code (see rust/crd/src/lib.rs)

Since this does not work in versions 3.8.0 or lower, it will be a little more work to differentiate between zookeeper versions with and without that bug.

Relates to PR #479.

This is currently blocked by stackabletech/tokio-zookeeper#57

The tokio-zookeeper client currently does not support TLS communication and therefore the operator can not manage znodes etc.

Tasks

Activity

  1. sbernauer commented on Mar 11, 2024

    @sbernauer
    Member

    Good news, ZOOKEEPER-4276 was fixed and will be released in 3.10.0 🥳

  2. lfrancke commented on Nov 19, 2025

    @lfrancke
    Member

    As ZK 3.10.0 is not released yet (and we do not know when/if it will) the scope of this is to see if the patch applies on 3.9.x

    Reading the comments I doubt this will be the case. Please spend at moste one day on trying to get the patch to apply and if that doesn't work raise it for discussion and a decision on how to continue.

  3. moved this to Selected for Development in Stackable End-to-End Coordinationon Nov 19, 2025
  4. moved this from Selected for Development to In Progress in Stackable End-to-End Coordinationon Dec 4, 2025
  5. moved this to Development: Track in Stackable Engineeringon Dec 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions