Lesson 22 / 25

Security: TLS, SASL and ACLs

Encrypt traffic, authenticate clients and authorise access per topic.

Three questions

Secure Kafka by answering: Is the connection private? Use TLS to encrypt traffic between clients and brokers and among brokers. Who is connecting? Use authentication: mutual TLS (client certificates) or SASL (SCRAM, OAUTHBEARER, GSSAPI/Kerberos). What may they do? Use ACLs (or your managed service's equivalent) to grant least-privilege access, for example allow the billing service to read sales.order.placed.v1 and join group billing, and nothing else. Never expose brokers directly to the internet, keep credentials in a secrets manager, and encrypt disks at rest if data is sensitive.

ACLs for one service (illustrative)

Grants the billing user read access to one topic and membership of one group. Requires an authorizer to be enabled on the cluster.

kafka-acls.sh --bootstrap-server broker1:9093 --command-config admin.properties \
  --add --allow-principal User:billing --operation Read --topic sales.order.placed.v1
kafka-acls.sh --bootstrap-server broker1:9093 --command-config admin.properties \
  --add --allow-principal User:billing --operation Read --group billing

Quick check: Which provides least-privilege access to topics?

  • Opening the broker port to the internet
  • One shared admin user for all services
  • Disabling authentication
  • ACLs granting only needed operations on specific topics
Answer

ACLs granting only needed operations on specific topics — Per-principal, per-resource permissions limit what any one service can do.