0Pricing
Apache Kafka & Stream Processing Fundamentals · Lektion

Sicherheit: Authentifizierung und Autorisierung

Implementieren Sie grundlegende Sicherheitsmaßnahmen in Kafka, darunter die Authentifizierung von Clients und die Autorisierung des Datenzugriffs.

Sicherheit: Authentifizierung und Autorisierung ist eine kostenlose Apache Kafka & Stream Processing Fundamentals-Lektion auf CoddyKit. Dies ist Lektion 3 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Apache Kafka & Stream Processing Fundamentals-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Apache Kafka & Stream Processing Fundamentals-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

Why Secure Kafka?

In today's data-driven world, securing your data is paramount. Kafka, often the backbone for critical data streams, needs robust security measures.

Without security, sensitive information could be exposed, data integrity compromised, and compliance regulations violated. This lesson covers the fundamental ways to protect your Kafka cluster.

Authentication: Who Are You?

Authentication is the process of verifying the identity of a client (like a producer or consumer) trying to connect to a Kafka broker.

Think of it like showing your ID at an airport. Kafka needs to confirm that you are who you claim to be before allowing any interaction. This prevents unauthorized users from even connecting.

Authorization: What Can You Do?

Once a client is authenticated (their identity is confirmed), authorization determines what actions they are permitted to perform.

This is like having a boarding pass after showing your ID. The pass dictates which gate you can access and which flight you can board. Kafka uses authorization to control access to specific topics, consumer groups, and other resources.

Kafka's Security Toolkit

Kafka offers several mechanisms to implement both authentication and authorization:

  • Authentication: Primarily handled by SASL (Simple Authentication and Security Layer) or SSL/TLS.
  • Authorization: Managed through Access Control Lists (ACLs), which define permissions for authenticated users on specific resources.

These layers work together to create a secure data streaming environment.

SASL/PLAIN Broker Setup

SASL (Simple Authentication and Security Layer) provides a framework for authentication. One common mechanism is SASL/PLAIN, which uses a simple username and password.

To enable SASL/PLAIN on a Kafka broker, you need to add security configurations to its server.properties file. Here's a basic example:

# server.properties
listeners=PLAINTEXT://:9092,SASL_PLAINTEXT://:9093
sasl.enabled.mechanisms=PLAIN
sasl.mechanism.inter.broker.protocol=PLAIN
authorizer.class.name=kafka.security.auth.SimpleAclAuthorizer
supers.users=User:admin

listener.name.sasl_plaintext.plain.sasl.jaas.config=
  org.apache.kafka.common.security.plain.PlainLoginModule required
  username="admin" password="admin-secret";

Client Authentication with SASL/PLAIN

Once the broker is configured for SASL/PLAIN, clients (producers or consumers) must provide valid credentials to connect. You specify these details in the client's configuration.

Try running this simple Java producer example, configured to use SASL/PLAIN:

import org.apache.kafka.clients.producer.*;
import java.util.Properties;

public class SecureProducer {
    public static void main(String[] args) {
        Properties props = new Properties();
        props.put("bootstrap.servers", "localhost:9093");
        props.put("key.serializer", "org.apache.kafka.common.serialization.StringSerializer");
        props.put("value.serializer", "org.apache.kafka.common.serialization.StringSerializer");

        // SASL_PLAINTEXT configuration
        props.put("security.protocol", "SASL_PLAINTEXT");
        props.put("sasl.mechanism", "PLAIN");
        props.put("sasl.jaas.config", 
            "org.apache.kafka.common.security.plain.PlainLoginModule required " +
            "username=\"admin\" password=\"admin-secret\";");

        Producer<String, String> producer = new KafkaProducer<>(props);
        try {
            for (int i = 0; i < 5; i++) {
                String message = "Hello Secure Kafka " + i;
                producer.send(new ProducerRecord<>("my-secure-topic", "key" + i, message));
                System.out.println("Sent: " + message);
            }
        } catch (Exception e) {
            e.printStackTrace();
        } finally {
            producer.close();
        }
    }
}

Authorization with Access Control Lists

After a client authenticates, Kafka uses Access Control Lists (ACLs) to decide if they are authorized to perform a specific action on a resource.

An ACL is a rule that specifies who (a user principal), from where (host), can do what (operation like READ, WRITE), on which resource (topic, group, broker).

Managing ACLs with the CLI

Kafka provides a command-line tool, kafka-acls.sh, to manage ACLs. You can grant or revoke permissions for users on various Kafka resources.

Here are some common commands:

  • Grant write access to a topic:
    kafka-acls.sh --authorizer-properties authorizer.properties --add --allow-principal User:admin --producer --topic my-secure-topic
  • Grant read access to a consumer group:
    kafka-acls.sh --authorizer-properties authorizer.properties --add --allow-principal User:consumerUser --consumer --group my-group
  • List all ACLs:
    kafka-acls.sh --authorizer-properties authorizer.properties --list --topic my-secure-topic

Security Checkpoint

You've learned about the fundamental security concepts in Kafka. Let's test your understanding!

Which of the following best describes the purpose of Authorization in Kafka?

Secure Streams: A Summary

Great job! You've covered the essentials of Kafka security.

  • Authentication verifies who a client is (e.g., via SASL/PLAIN).
  • Authorization determines what an authenticated client can do (e.g., via ACLs).
  • Implementing these measures protects your data streams from unauthorized access and ensures data integrity.

Securing your Kafka cluster is a critical step for any production deployment!

Häufig gestellte Fragen

Ist die Lektion „Sicherheit: Authentifizierung und Autorisierung“ kostenlos?

Ja — der vollständige Text von „Sicherheit: Authentifizierung und Autorisierung“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Apache Kafka & Stream Processing Fundamentals-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Apache Kafka & Stream Processing Fundamentals-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Sicherheit: Authentifizierung und Autorisierung“?

Implementieren Sie grundlegende Sicherheitsmaßnahmen in Kafka, darunter die Authentifizierung von Clients und die Autorisierung des Datenzugriffs. Du übst Apache Kafka & Stream Processing Fundamentals mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um Apache Kafka & Stream Processing Fundamentals zu starten?

Keine Vorkenntnisse erforderlich. Apache Kafka & Stream Processing Fundamentals auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 3 von 4.

Wie lange dauert die Lektion „Sicherheit: Authentifizierung und Autorisierung“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser Apache Kafka & Stream Processing Fundamentals-Lektion Code schreiben und ausführen?

Ja. Jede Apache Kafka & Stream Processing Fundamentals-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Befehlszeilenwerkzeuge für Kafka
  2. Kafka mit JMX und Werkzeugen überwachen
  3. Sicherheit: Authentifizierung und Autorisierung
  4. Consumer-Lag verfolgen und Alarme einrichten
← Zurück zu Apache Kafka & Stream Processing Fundamentals