Securing a Kafka Cluster

Every cluster so far in this chapter used PLAINTEXT listeners: anyone who could reach port 9092 could read every order, write fake ones and delete topics. Kafka 129 's security has three layers, configured per listener: encryption (TLS), authentication (SASL or a client certificate establishes a principal) and authorization (ACLs say what that principal may do). A listener's security protocol combines the first two: PLAINTEXT, SSL (TLS, optionally with client certificates), SASL_PLAINTEXT and SASL_SSL. This section builds all three layers into one Kafka 4.3.1 broker, l3-kafka-sec (demos/ch06/compose/secure.yaml).

Subsections