Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release for new solr-operator with latest ZooKeeper dependency #657

Open
akash-apple opened this issue Nov 17, 2023 · 4 comments
Open

Release for new solr-operator with latest ZooKeeper dependency #657

akash-apple opened this issue Nov 17, 2023 · 4 comments
Labels
dependency upgrades Upgrading dependencies of the Operator, such as Kubernetes, Kubebuilder, Zookeeper-Operator, etc. zookeeper Related to Zookeeper or the Zookeeper Operator

Comments

@akash-apple
Copy link

Hey team,
Latest released solr-operator (https://artifacthub.io/packages/helm/apache-solr/solr-operator) v0.8.0 has a dependency on ZooKeeper operator (https://artifacthub.io/packages/helm/banzaicloud-stable/zookeeper-operator) v0.2.15 which in turn depends on older ZooKeeper version exposing log4j 1.x usage for Solr.

Latest ZooKeeper version v0.3.0 mitigated this issue by upgrading underlying ZooKeeper deps. This issue is created to request release of new solr-operator chart that depends on updated ZooKeeper to remediate log4j exposure for downstream Ranger/Solr users.

@HoustonPutman
Copy link
Contributor

I'm not sure where banzaicloud's zookeeper operator comes from, but the one that Solr relies on is https://github.com/pravega/zookeeper-operator. The latest release of the is 0.2.15

The log4j 1.x CVEs were addressed in Zookeeper 3.7.1, which the 0.2.15 version of the Zookeeper Operator uses.

@HoustonPutman HoustonPutman added zookeeper Related to Zookeeper or the Zookeeper Operator dependency upgrades Upgrading dependencies of the Operator, such as Kubernetes, Kubebuilder, Zookeeper-Operator, etc. labels Nov 28, 2023
@aloosnetmatch
Copy link

Hi.

It looks like the project https://github.com/pravega/zookeeper-operator
is still active, but not much work is done on the project.

The last release was 0.2.15 , released this Apr 4, 2023.

Current status seems to be:
pravega/zookeeper-operator#617

Our zookeeper-operator image seems to have 364 outdated packages at the moment.

Wondering if we should switch to a more actively maintained zookeeper operator solution.
Or does the Solr-operator project has already plans for this?

@janhoy
Copy link
Contributor

janhoy commented Jan 23, 2025

I’ve given up on them. It’s dead. Turn off zk operator and instead deploy zk independently with a helm chart. I propose #600

@HoustonPutman
Copy link
Contributor

I agree. Let's push for a 1.0 release with this as the big change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependency upgrades Upgrading dependencies of the Operator, such as Kubernetes, Kubebuilder, Zookeeper-Operator, etc. zookeeper Related to Zookeeper or the Zookeeper Operator
Projects
None yet
Development

No branches or pull requests

4 participants