# Security: TLS, SASL and ACLs — Apache Kafka: Event Streaming from Basics to Production

Source: https://www.geekswithgeeks.com/en/kafka/ops-security

> Encrypt traffic, authenticate clients and authorise access per topic.

## Three questions

Secure Kafka by answering: **Is the connection private?** Use **TLS** to encrypt traffic between clients and brokers and among brokers. **Who is connecting?** Use **authentication**: mutual TLS (client certificates) or **SASL** (SCRAM, OAUTHBEARER, GSSAPI/Kerberos). **What may they do?** Use **ACLs** (or your managed service's equivalent) to grant least-privilege access, for example allow the `billing` service to **read** `sales.order.placed.v1` and join group `billing`, and nothing else. Never expose brokers directly to the internet, keep credentials in a secrets manager, and encrypt disks at rest if data is sensitive.

## ACLs for one service (illustrative)

Grants the `billing` user read access to one topic and membership of one group. Requires an authorizer to be enabled on the cluster.

```bash
kafka-acls.sh --bootstrap-server broker1:9093 --command-config admin.properties \
  --add --allow-principal User:billing --operation Read --topic sales.order.placed.v1
kafka-acls.sh --bootstrap-server broker1:9093 --command-config admin.properties \
  --add --allow-principal User:billing --operation Read --group billing
```

**Quiz:** Which provides least-privilege access to topics?

- [ ] Opening the broker port to the internet
- [ ] One shared admin user for all services
- [ ] Disabling authentication
- [x] ACLs granting only needed operations on specific topics

*Answer:* ACLs granting only needed operations on specific topics. Per-principal, per-resource permissions limit what any one service can do.
