0Pricing
Apache Kafka & Stream Processing Fundamentals · レッスン

セキュリティ:認証と認可

データアクセスに対するクライアント認証と認可を含む、Kafkaの基本的なセキュリティ対策を実装します。

「セキュリティ:認証と認可」はCoddyKit上の無料Apache Kafka & Stream Processing Fundamentalsレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはApache Kafka & Stream Processing Fundamentals学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Apache Kafka & Stream Processing Fundamentalsコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Why Secure Kafka?

In today's data-driven world, securing your data is paramount. Kafka, often the backbone for critical data streams, needs robust security measures.

Without security, sensitive information could be exposed, data integrity compromised, and compliance regulations violated. This lesson covers the fundamental ways to protect your Kafka cluster.

Authentication: Who Are You?

Authentication is the process of verifying the identity of a client (like a producer or consumer) trying to connect to a Kafka broker.

Think of it like showing your ID at an airport. Kafka needs to confirm that you are who you claim to be before allowing any interaction. This prevents unauthorized users from even connecting.

Authorization: What Can You Do?

Once a client is authenticated (their identity is confirmed), authorization determines what actions they are permitted to perform.

This is like having a boarding pass after showing your ID. The pass dictates which gate you can access and which flight you can board. Kafka uses authorization to control access to specific topics, consumer groups, and other resources.

Kafka's Security Toolkit

Kafka offers several mechanisms to implement both authentication and authorization:

  • Authentication: Primarily handled by SASL (Simple Authentication and Security Layer) or SSL/TLS.
  • Authorization: Managed through Access Control Lists (ACLs), which define permissions for authenticated users on specific resources.

These layers work together to create a secure data streaming environment.

SASL/PLAIN Broker Setup

SASL (Simple Authentication and Security Layer) provides a framework for authentication. One common mechanism is SASL/PLAIN, which uses a simple username and password.

To enable SASL/PLAIN on a Kafka broker, you need to add security configurations to its server.properties file. Here's a basic example:

# server.properties
listeners=PLAINTEXT://:9092,SASL_PLAINTEXT://:9093
sasl.enabled.mechanisms=PLAIN
sasl.mechanism.inter.broker.protocol=PLAIN
authorizer.class.name=kafka.security.auth.SimpleAclAuthorizer
supers.users=User:admin

listener.name.sasl_plaintext.plain.sasl.jaas.config=
  org.apache.kafka.common.security.plain.PlainLoginModule required
  username="admin" password="admin-secret";

Client Authentication with SASL/PLAIN

Once the broker is configured for SASL/PLAIN, clients (producers or consumers) must provide valid credentials to connect. You specify these details in the client's configuration.

Try running this simple Java producer example, configured to use SASL/PLAIN:

import org.apache.kafka.clients.producer.*;
import java.util.Properties;

public class SecureProducer {
    public static void main(String[] args) {
        Properties props = new Properties();
        props.put("bootstrap.servers", "localhost:9093");
        props.put("key.serializer", "org.apache.kafka.common.serialization.StringSerializer");
        props.put("value.serializer", "org.apache.kafka.common.serialization.StringSerializer");

        // SASL_PLAINTEXT configuration
        props.put("security.protocol", "SASL_PLAINTEXT");
        props.put("sasl.mechanism", "PLAIN");
        props.put("sasl.jaas.config", 
            "org.apache.kafka.common.security.plain.PlainLoginModule required " +
            "username=\"admin\" password=\"admin-secret\";");

        Producer<String, String> producer = new KafkaProducer<>(props);
        try {
            for (int i = 0; i < 5; i++) {
                String message = "Hello Secure Kafka " + i;
                producer.send(new ProducerRecord<>("my-secure-topic", "key" + i, message));
                System.out.println("Sent: " + message);
            }
        } catch (Exception e) {
            e.printStackTrace();
        } finally {
            producer.close();
        }
    }
}

Authorization with Access Control Lists

After a client authenticates, Kafka uses Access Control Lists (ACLs) to decide if they are authorized to perform a specific action on a resource.

An ACL is a rule that specifies who (a user principal), from where (host), can do what (operation like READ, WRITE), on which resource (topic, group, broker).

Managing ACLs with the CLI

Kafka provides a command-line tool, kafka-acls.sh, to manage ACLs. You can grant or revoke permissions for users on various Kafka resources.

Here are some common commands:

  • Grant write access to a topic:
    kafka-acls.sh --authorizer-properties authorizer.properties --add --allow-principal User:admin --producer --topic my-secure-topic
  • Grant read access to a consumer group:
    kafka-acls.sh --authorizer-properties authorizer.properties --add --allow-principal User:consumerUser --consumer --group my-group
  • List all ACLs:
    kafka-acls.sh --authorizer-properties authorizer.properties --list --topic my-secure-topic

Security Checkpoint

You've learned about the fundamental security concepts in Kafka. Let's test your understanding!

Which of the following best describes the purpose of Authorization in Kafka?

Secure Streams: A Summary

Great job! You've covered the essentials of Kafka security.

  • Authentication verifies who a client is (e.g., via SASL/PLAIN).
  • Authorization determines what an authenticated client can do (e.g., via ACLs).
  • Implementing these measures protects your data streams from unauthorized access and ensures data integrity.

Securing your Kafka cluster is a critical step for any production deployment!

よくある質問

「セキュリティ:認証と認可」レッスンは無料ですか?

はい。「セキュリティ:認証と認可」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Apache Kafka & Stream Processing Fundamentalsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Apache Kafka & Stream Processing Fundamentalsコースには全4レッスンが含まれています。

「セキュリティ:認証と認可」で何を学びますか?

データアクセスに対するクライアント認証と認可を含む、Kafkaの基本的なセキュリティ対策を実装します。 ブラウザで直接実行するハンズオンコードでApache Kafka & Stream Processing Fundamentalsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Apache Kafka & Stream Processing Fundamentalsを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのApache Kafka & Stream Processing Fundamentalsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。

「セキュリティ:認証と認可」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このApache Kafka & Stream Processing Fundamentalsレッスンでコードを書いて実行できますか?

はい。すべてのApache Kafka & Stream Processing Fundamentalsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. Kafkaのコマンドラインツール
  2. JMXとツールによるKafkaの監視
  3. セキュリティ:認証と認可
  4. コンシューマーラグの追跡とアラート
← Apache Kafka & Stream Processing Fundamentalsに戻る