SIGN IN SIGN UP

security/audit: report misconfigured auth from client init

_misconfigured was set only when create_internal_topic() failed, because
that is the one configuration step whose errors reach the kafka client's
mitigate_error(). That step runs only when the local topic table has no
audit topic yet, so reporting a misconfigured authorization raced with
topic table recovery at startup. Every other step, _client.connect()
included, reports its error to do_configure().

Set the flag in do_configure() when any configuration step fails, and
clear it there once every step succeeds. While the flag is set,
audit_log_manager warns on every audit event and applies
audit_log_reject_policy to it.

Covered by audit_log_test.test_no_auth_enabled, which waits for the
rejection warning after removing authentication from a listener.

Signed-off-by: Oren Leiman <oren.leiman@redpanda.com>
O
Oren Leiman committed
ffa89e374a082f1d821ef86cd43c2fa55d3d5cab
Parent: 26db9cc