SASLによる認証
SASL(Simple Authentication and Security Layer)を使用してKafkaブローカーで認証するよう、Spring BootのKafkaクライアントを設定します。
「SASLによる認証」はCoddyKit上の無料Advanced Spring Boot 4: Event-Driven Architecture (Kafka)レッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはAdvanced Spring Boot 4: Event-Driven Architecture (Kafka)学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Advanced Spring Boot 4: Event-Driven Architecture (Kafka)コースには全4レッスンが含まれています。
このレッスンの一部はまだ翻訳されておらず、英語で表示されています。
What is SASL?
Welcome to securing your Kafka applications! Today, we'll dive into SASL, which stands for Simple Authentication and Security Layer.
SASL is a framework for authentication and data security in network protocols. For Kafka, it's how your clients (like Spring Boot apps) prove their identity to the Kafka brokers.
Why Authenticate with Kafka?
Imagine a bank: you wouldn't want just anyone accessing your accounts. Similarly, in an event-driven system, you need to control who can send or receive messages from your Kafka topics.
- Prevent Unauthorized Access: Ensure only trusted applications can interact with your Kafka cluster.
- Data Integrity: Protect your data streams from malicious or accidental interference.
- Compliance: Meet security requirements for sensitive data processing.
SASL Mechanisms for Kafka
SASL itself is a framework, and it uses specific 'mechanisms' to perform authentication. Common ones for Kafka include:
- PLAIN: Sends username/password in plaintext (but often over SSL for encryption). Simple, but less secure.
- SCRAM: (Salted Challenge Response Authentication Mechanism) A more robust, challenge-response mechanism that doesn't send the password directly. Examples: SCRAM-SHA-256, SCRAM-SHA-512.
- GSSAPI (Kerberos): Enterprise-grade authentication, often used in large corporate environments.
Broker-Side Setup (Conceptual)
Before clients can authenticate, your Kafka brokers must be configured to accept SASL connections. This usually involves:
- Enabling a SASL listener in
server.properties. - Configuring a JAAS (Java Authentication and Authorization Service) file for the broker.
- Defining valid users and their credentials.
While we won't configure the broker here, it's crucial to remember both sides need setup!
Spring Boot Client Properties
For your Spring Boot Kafka client, you'll add security properties to your application.properties or application.yml file. These tell your application how to connect securely.
The main properties are spring.kafka.properties.security.protocol and spring.kafka.properties.sasl.mechanism.
Using SASL_PLAINTEXT
SASL_PLAINTEXT is one of the simplest ways to enable SASL. It sends credentials directly. Often used with SSL (SASL_SSL) to encrypt the connection, making the plaintext credentials secure in transit.
It's good for quick setups or testing, but for production, consider more robust mechanisms like SCRAM.
Here's how you'd configure it in your application.properties:
spring.kafka.producer.properties.sasl.mechanism=PLAIN
spring.kafka.producer.properties.security.protocol=SASL_PLAINTEXT
spring.kafka.producer.properties.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="user" password="password";SASL_PLAINTEXT Producer Example
This Spring Boot producer sends a simple message using SASL_PLAINTEXT. Remember, the JAAS config would be in application.properties, not directly in code.
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.kafka.core.KafkaTemplate;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.CommandLineRunner;
@SpringBootApplication
public class SaslProducerApplication implements CommandLineRunner {
@Autowired
private KafkaTemplate<String, String> kafkaTemplate;
public static void main(String[] args) {
SpringApplication.run(SaslProducerApplication.class, args);
}
@Override
public void run(String... args) throws Exception {
System.out.println("Sending message...");
kafkaTemplate.send("my-sasl-topic", "Hello from SASL!");
System.out.println("Message sent with SASL_PLAINTEXT.");
}
}Combining SASL with SSL
For production environments, you almost always want to combine SASL authentication with SSL/TLS encryption. This is known as SASL_SSL.
- Authentication (SASL): Verifies the identity of the client.
- Encryption (SSL/TLS): Encrypts all data transmitted between the client and the broker, protecting it from eavesdropping.
This provides both identity verification and secure communication, a strong combination for robust security.
Configuring SASL_SSL
When using SASL_SSL, you'll need to specify SSL properties in addition to SASL ones. This includes details about your truststore (to trust the broker's certificate) and potentially a keystore (if the client also needs to authenticate itself with a certificate).
Example application.properties for SASL_SSL (with PLAIN mechanism):
spring.kafka.consumer.properties.security.protocol=SASL_SSL
spring.kafka.consumer.properties.sasl.mechanism=PLAIN
spring.kafka.consumer.properties.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="user" password="password";
spring.kafka.consumer.properties.ssl.truststore.location=file:/path/to/client.truststore.jks
spring.kafka.consumer.properties.ssl.truststore.password=truststore_passwordQuick Check
Which of the following is generally considered the most secure SASL mechanism for production environments, especially when combined with SSL?
Recap & Next Steps
Great job! In this lesson, you learned about:
- What SASL is and why it's vital for Kafka security.
- Different SASL mechanisms like PLAIN and SCRAM.
- How to configure Spring Boot Kafka clients for
SASL_PLAINTEXTandSASL_SSL.
Remember, securing your Kafka applications is a multi-layered approach. Next, we'll explore how to enforce Authorization with ACLs to control what authenticated users can actually do!
よくある質問
「SASLによる認証」レッスンは無料ですか?
はい。「SASLによる認証」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Advanced Spring Boot 4: Event-Driven Architecture (Kafka)コースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Advanced Spring Boot 4: Event-Driven Architecture (Kafka)コースには全4レッスンが含まれています。
「SASLによる認証」で何を学びますか?
SASL(Simple Authentication and Security Layer)を使用してKafkaブローカーで認証するよう、Spring BootのKafkaクライアントを設定します。 ブラウザで直接実行するハンズオンコードでAdvanced Spring Boot 4: Event-Driven Architecture (Kafka)を演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。
Advanced Spring Boot 4: Event-Driven Architecture (Kafka)を始めるのに経験は必要ですか?
事前経験は必要ありません。CoddyKitのAdvanced Spring Boot 4: Event-Driven Architecture (Kafka)は初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。
「SASLによる認証」レッスンにはどのくらい時間がかかりますか?
ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。
このAdvanced Spring Boot 4: Event-Driven Architecture (Kafka)レッスンでコードを書いて実行できますか?
はい。すべてのAdvanced Spring Boot 4: Event-Driven Architecture (Kafka)レッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。