Advanced Spring Boot 4: Event-Driven Architecture (Kafka) · Leçon

Authentification avec SASL

Configurez les clients Kafka Spring Boot pour s’authentifier auprès des courtiers Kafka à l’aide de SASL (couche simple d’authentification et de sécurité).

Leçon 1 sur 411 étapes

Authentification avec SASL est une leçon Advanced Spring Boot 4: Event-Driven Architecture (Kafka) gratuite sur CoddyKit. Ceci est la leçon 1 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage Advanced Spring Boot 4: Event-Driven Architecture (Kafka), et ta progression se synchronise sur le web et l'application CoddyKit. Le cours Advanced Spring Boot 4: Event-Driven Architecture (Kafka) comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

What is SASL?

Welcome to securing your Kafka applications! Today, we'll dive into SASL, which stands for Simple Authentication and Security Layer.

SASL is a framework for authentication and data security in network protocols. For Kafka, it's how your clients (like Spring Boot apps) prove their identity to the Kafka brokers.

Why Authenticate with Kafka?

Imagine a bank: you wouldn't want just anyone accessing your accounts. Similarly, in an event-driven system, you need to control who can send or receive messages from your Kafka topics.

  • Prevent Unauthorized Access: Ensure only trusted applications can interact with your Kafka cluster.
  • Data Integrity: Protect your data streams from malicious or accidental interference.
  • Compliance: Meet security requirements for sensitive data processing.

SASL Mechanisms for Kafka

SASL itself is a framework, and it uses specific 'mechanisms' to perform authentication. Common ones for Kafka include:

  • PLAIN: Sends username/password in plaintext (but often over SSL for encryption). Simple, but less secure.
  • SCRAM: (Salted Challenge Response Authentication Mechanism) A more robust, challenge-response mechanism that doesn't send the password directly. Examples: SCRAM-SHA-256, SCRAM-SHA-512.
  • GSSAPI (Kerberos): Enterprise-grade authentication, often used in large corporate environments.

Broker-Side Setup (Conceptual)

Before clients can authenticate, your Kafka brokers must be configured to accept SASL connections. This usually involves:

  • Enabling a SASL listener in server.properties.
  • Configuring a JAAS (Java Authentication and Authorization Service) file for the broker.
  • Defining valid users and their credentials.

While we won't configure the broker here, it's crucial to remember both sides need setup!

Spring Boot Client Properties

For your Spring Boot Kafka client, you'll add security properties to your application.properties or application.yml file. These tell your application how to connect securely.

The main properties are spring.kafka.properties.security.protocol and spring.kafka.properties.sasl.mechanism.

Using SASL_PLAINTEXT

SASL_PLAINTEXT is one of the simplest ways to enable SASL. It sends credentials directly. Often used with SSL (SASL_SSL) to encrypt the connection, making the plaintext credentials secure in transit.

It's good for quick setups or testing, but for production, consider more robust mechanisms like SCRAM.

Here's how you'd configure it in your application.properties:

spring.kafka.producer.properties.sasl.mechanism=PLAIN
spring.kafka.producer.properties.security.protocol=SASL_PLAINTEXT
spring.kafka.producer.properties.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="user" password="password";

SASL_PLAINTEXT Producer Example

This Spring Boot producer sends a simple message using SASL_PLAINTEXT. Remember, the JAAS config would be in application.properties, not directly in code.

import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.kafka.core.KafkaTemplate;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.CommandLineRunner;

@SpringBootApplication
public class SaslProducerApplication implements CommandLineRunner {

    @Autowired
    private KafkaTemplate<String, String> kafkaTemplate;

    public static void main(String[] args) {
        SpringApplication.run(SaslProducerApplication.class, args);
    }

    @Override
    public void run(String... args) throws Exception {
        System.out.println("Sending message...");
        kafkaTemplate.send("my-sasl-topic", "Hello from SASL!");
        System.out.println("Message sent with SASL_PLAINTEXT.");
    }
}

Combining SASL with SSL

For production environments, you almost always want to combine SASL authentication with SSL/TLS encryption. This is known as SASL_SSL.

  • Authentication (SASL): Verifies the identity of the client.
  • Encryption (SSL/TLS): Encrypts all data transmitted between the client and the broker, protecting it from eavesdropping.

This provides both identity verification and secure communication, a strong combination for robust security.

Configuring SASL_SSL

When using SASL_SSL, you'll need to specify SSL properties in addition to SASL ones. This includes details about your truststore (to trust the broker's certificate) and potentially a keystore (if the client also needs to authenticate itself with a certificate).

Example application.properties for SASL_SSL (with PLAIN mechanism):

spring.kafka.consumer.properties.security.protocol=SASL_SSL
spring.kafka.consumer.properties.sasl.mechanism=PLAIN
spring.kafka.consumer.properties.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="user" password="password";
spring.kafka.consumer.properties.ssl.truststore.location=file:/path/to/client.truststore.jks
spring.kafka.consumer.properties.ssl.truststore.password=truststore_password

Quick Check

Which of the following is generally considered the most secure SASL mechanism for production environments, especially when combined with SSL?

Recap & Next Steps

Great job! In this lesson, you learned about:

  • What SASL is and why it's vital for Kafka security.
  • Different SASL mechanisms like PLAIN and SCRAM.
  • How to configure Spring Boot Kafka clients for SASL_PLAINTEXT and SASL_SSL.

Remember, securing your Kafka applications is a multi-layered approach. Next, we'll explore how to enforce Authorization with ACLs to control what authenticated users can actually do!

Gratuit pour commencer

Apprends Advanced Spring Boot 4: Event-Driven Architecture (Kafka) avec un tuteur IA — gratuit

Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.

Cours
12
Leçons
48

Questions Fréquemment Posées

La leçon « Authentification avec SASL » est-elle gratuite ?

Oui — le texte complet de « Authentification avec SASL » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours Advanced Spring Boot 4: Event-Driven Architecture (Kafka), passe à CoddyKit PRO. Le cours Advanced Spring Boot 4: Event-Driven Architecture (Kafka) comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Authentification avec SASL » ?

Configurez les clients Kafka Spring Boot pour s’authentifier auprès des courtiers Kafka à l’aide de SASL (couche simple d’authentification et de sécurité). Tu pratiques Advanced Spring Boot 4: Event-Driven Architecture (Kafka) avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer Advanced Spring Boot 4: Event-Driven Architecture (Kafka) ?

Aucune expérience préalable n'est requise. Advanced Spring Boot 4: Event-Driven Architecture (Kafka) sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 1 sur 4.

Combien de temps prend la leçon « Authentification avec SASL » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon Advanced Spring Boot 4: Event-Driven Architecture (Kafka) ?

Oui. Chaque leçon Advanced Spring Boot 4: Event-Driven Architecture (Kafka) inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. Authentification avec SASL
  2. Autorisation avec les listes de contrôle d’accès
  3. Chiffrement avec SSL/TLS
  4. Auditer et sécuriser l’accès à Schema Registry
← Retour à Advanced Spring Boot 4: Event-Driven Architecture (Kafka)