Otorisasi dengan ACL
Terapkan Access Control List (ACL) pada broker Kafka untuk menetapkan izin terperinci bagi producer dan consumer.
Otorisasi dengan ACL adalah pelajaran Advanced Spring Boot 4: Event-Driven Architecture (Kafka) gratis di CoddyKit. Ini adalah pelajaran 2 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Advanced Spring Boot 4: Event-Driven Architecture (Kafka), dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Advanced Spring Boot 4: Event-Driven Architecture (Kafka) mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
What are Kafka ACLs?
In our last lesson, we learned about authenticating with Kafka using SASL. But authentication just verifies who you are.
Authorization determines what you are allowed to do. This is where Access Control Lists (ACLs) come in.
Kafka ACLs provide fine-grained permissions, letting you control which users (or principals) can perform specific actions on Kafka resources.
The Core of Kafka Authorization
Authorization in Kafka revolves around three key concepts:
- Principal: The authenticated user or client attempting an action (e.g.,
User:Alice,User:ProducerApp). - Operation: The action being attempted (e.g.,
READ,WRITE,CREATE,DELETE). - Resource: The Kafka entity the operation is performed on (e.g., a specific topic, a consumer group).
ACLs define which principals can perform which operations on which resources.
Different Types of Kafka Resources
Kafka allows you to set permissions on several types of resources:
- Topic: For producing messages to or consuming from specific topics.
- Group: For managing consumer group memberships and offset commits.
- Cluster: For cluster-wide operations like describing brokers or creating topics.
- TransactionalId: For using Kafka transactions.
- DelegationToken: For managing delegation tokens (advanced).
Most common are Topic, Group, and Cluster resources.
ACL Syntax with `kafka-acls.sh`
ACLs are typically managed using the kafka-acls.sh command-line tool. You'll specify the principal, operation, and resource.
Here's a basic structure:
kafka-acls.sh --authorizer-properties ... \
--add --allow-principal 'User:Alice' \
--operation Read --topic 'my-topic'This grants User:Alice permission to Read from my-topic.
ACLs for a Kafka Producer
A Kafka producer needs permissions to:
- Write messages: To a specific topic.
- Describe the cluster: To discover broker metadata.
Example commands to grant these permissions for a producer named User:ProducerApp on topic orders:
kafka-acls.sh --add --allow-principal 'User:ProducerApp' --operation Write --topic 'orders' --authorizer-properties ...
kafka-acls.sh --add --allow-principal 'User:ProducerApp' --operation Describe --cluster --authorizer-properties ...Spring Producer & ACLs
This Spring Boot producer sends a message to my-secured-topic. For it to work, the principal associated with this application (e.g., User:my-producer via SASL) must have the necessary ACLs configured on the Kafka broker.
Specifically, it needs WRITE permission on the topic and DESCRIBE permission on the cluster resource.
import org.springframework.boot.CommandLineRunner;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.kafka.core.KafkaTemplate;
import org.springframework.context.annotation.Bean;
@SpringBootApplication
public class KafkaProducerAclApp {
public static void main(String[] args) {
SpringApplication.run(KafkaProducerAclApp.class, args);
}
@Bean
public CommandLineRunner runner(KafkaTemplate<String, String> kafkaTemplate) {
return args -> {
String topic = "my-secured-topic";
String message = "Hello from secured producer!";
kafkaTemplate.send(topic, message);
System.out.println("Sent message: '" + message + "' to topic: '" + topic + "'");
System.out.println("Check Kafka broker logs for successful message receipt.");
};
}
}ACLs for a Kafka Consumer
A Kafka consumer needs permissions to:
- Read messages: From a specific topic.
- Read from its consumer group: To manage offsets and join the group.
- Describe the cluster: Like producers, for metadata.
Example commands for User:ConsumerApp on topic payments and group payment-processors:
kafka-acls.sh --add --allow-principal 'User:ConsumerApp' --operation Read --topic 'payments' --authorizer-properties ...
kafka-acls.sh --add --allow-principal 'User:ConsumerApp' --operation Read --group 'payment-processors' --authorizer-properties ...
kafka-acls.sh --add --allow-principal 'User:ConsumerApp' --operation Describe --cluster --authorizer-properties ...Spring Consumer & ACLs
This Spring Boot consumer listens to my-secured-topic as part of my-secured-group. Its associated principal (e.g., User:my-consumer) needs specific ACLs.
It requires READ permission on the topic, READ permission on the consumer group, and DESCRIBE permission on the cluster resource.
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.kafka.annotation.KafkaListener;
@SpringBootApplication
public class KafkaConsumerAclApp {
public static void main(String[] args) {
SpringApplication.run(KafkaConsumerAclApp.class, args);
}
@KafkaListener(topics = "my-secured-topic", groupId = "my-secured-group")
public void listen(String message) {
System.out.println("Received secured message: " + message);
}
}Listing & Revoking ACLs
It's important to manage ACLs effectively. You can list all ACLs or specific ones:
kafka-acls.sh --list --topic 'my-topic' --authorizer-properties ...To remove an ACL, use the --remove flag instead of --add, specifying the exact ACL you wish to revoke:
kafka-acls.sh --remove --allow-principal 'User:Alice' --operation Read --topic 'my-topic' --authorizer-properties ...Regularly review and remove unnecessary permissions for security best practices.
ACLs Quick Check
Which of the following permissions are typically required for a Kafka consumer to successfully read messages from a topic and join a consumer group?
Recap: Securing with ACLs
Great job! You've learned how Kafka's authorization works using Access Control Lists (ACLs).
- ACLs define who (principal) can do what (operation) on where (resource).
- Key resources include topics, consumer groups, and the cluster itself.
- You use
kafka-acls.shto manage these permissions on the broker. - Spring Boot Kafka applications implicitly rely on these ACLs being in place for their authenticated principals.
Next, we'll explore how to encrypt data in transit using SSL/TLS.
Belajar Advanced Spring Boot 4: Event-Driven Architecture (Kafka) dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 12
- Pelajaran
- 48
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Otorisasi dengan ACL” gratis?
Ya — teks lengkap “Otorisasi dengan ACL” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Advanced Spring Boot 4: Event-Driven Architecture (Kafka), upgrade ke CoddyKit PRO. Kursus Advanced Spring Boot 4: Event-Driven Architecture (Kafka) mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Otorisasi dengan ACL”?
Terapkan Access Control List (ACL) pada broker Kafka untuk menetapkan izin terperinci bagi producer dan consumer. Kamu berlatih Advanced Spring Boot 4: Event-Driven Architecture (Kafka) dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai Advanced Spring Boot 4: Event-Driven Architecture (Kafka)?
Tidak diperlukan pengalaman sebelumnya. Advanced Spring Boot 4: Event-Driven Architecture (Kafka) di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 2 dari 4.
Berapa lama pelajaran “Otorisasi dengan ACL” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran Advanced Spring Boot 4: Event-Driven Architecture (Kafka) ini?
Ya. Setiap pelajaran Advanced Spring Boot 4: Event-Driven Architecture (Kafka) menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Autentikasi dengan SASL
- Otorisasi dengan ACL
- Enkripsi dengan SSL/TLS
- Mengaudit dan Mengamankan Akses Schema Registry