使用 ACL 进行授权
在 Kafka 代理上实施访问控制列表(ACL),为生产者和消费者定义细粒度权限
使用 ACL 进行授权 是 CoddyKit 上的免费 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
What are Kafka ACLs?
In our last lesson, we learned about authenticating with Kafka using SASL. But authentication just verifies who you are.
Authorization determines what you are allowed to do. This is where Access Control Lists (ACLs) come in.
Kafka ACLs provide fine-grained permissions, letting you control which users (or principals) can perform specific actions on Kafka resources.
The Core of Kafka Authorization
Authorization in Kafka revolves around three key concepts:
- Principal: The authenticated user or client attempting an action (e.g.,
User:Alice,User:ProducerApp). - Operation: The action being attempted (e.g.,
READ,WRITE,CREATE,DELETE). - Resource: The Kafka entity the operation is performed on (e.g., a specific topic, a consumer group).
ACLs define which principals can perform which operations on which resources.
Different Types of Kafka Resources
Kafka allows you to set permissions on several types of resources:
- Topic: For producing messages to or consuming from specific topics.
- Group: For managing consumer group memberships and offset commits.
- Cluster: For cluster-wide operations like describing brokers or creating topics.
- TransactionalId: For using Kafka transactions.
- DelegationToken: For managing delegation tokens (advanced).
Most common are Topic, Group, and Cluster resources.
ACL Syntax with `kafka-acls.sh`
ACLs are typically managed using the kafka-acls.sh command-line tool. You'll specify the principal, operation, and resource.
Here's a basic structure:
kafka-acls.sh --authorizer-properties ... \
--add --allow-principal 'User:Alice' \
--operation Read --topic 'my-topic'This grants User:Alice permission to Read from my-topic.
ACLs for a Kafka Producer
A Kafka producer needs permissions to:
- Write messages: To a specific topic.
- Describe the cluster: To discover broker metadata.
Example commands to grant these permissions for a producer named User:ProducerApp on topic orders:
kafka-acls.sh --add --allow-principal 'User:ProducerApp' --operation Write --topic 'orders' --authorizer-properties ...
kafka-acls.sh --add --allow-principal 'User:ProducerApp' --operation Describe --cluster --authorizer-properties ...Spring Producer & ACLs
This Spring Boot producer sends a message to my-secured-topic. For it to work, the principal associated with this application (e.g., User:my-producer via SASL) must have the necessary ACLs configured on the Kafka broker.
Specifically, it needs WRITE permission on the topic and DESCRIBE permission on the cluster resource.
import org.springframework.boot.CommandLineRunner;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.kafka.core.KafkaTemplate;
import org.springframework.context.annotation.Bean;
@SpringBootApplication
public class KafkaProducerAclApp {
public static void main(String[] args) {
SpringApplication.run(KafkaProducerAclApp.class, args);
}
@Bean
public CommandLineRunner runner(KafkaTemplate<String, String> kafkaTemplate) {
return args -> {
String topic = "my-secured-topic";
String message = "Hello from secured producer!";
kafkaTemplate.send(topic, message);
System.out.println("Sent message: '" + message + "' to topic: '" + topic + "'");
System.out.println("Check Kafka broker logs for successful message receipt.");
};
}
}ACLs for a Kafka Consumer
A Kafka consumer needs permissions to:
- Read messages: From a specific topic.
- Read from its consumer group: To manage offsets and join the group.
- Describe the cluster: Like producers, for metadata.
Example commands for User:ConsumerApp on topic payments and group payment-processors:
kafka-acls.sh --add --allow-principal 'User:ConsumerApp' --operation Read --topic 'payments' --authorizer-properties ...
kafka-acls.sh --add --allow-principal 'User:ConsumerApp' --operation Read --group 'payment-processors' --authorizer-properties ...
kafka-acls.sh --add --allow-principal 'User:ConsumerApp' --operation Describe --cluster --authorizer-properties ...Spring Consumer & ACLs
This Spring Boot consumer listens to my-secured-topic as part of my-secured-group. Its associated principal (e.g., User:my-consumer) needs specific ACLs.
It requires READ permission on the topic, READ permission on the consumer group, and DESCRIBE permission on the cluster resource.
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.kafka.annotation.KafkaListener;
@SpringBootApplication
public class KafkaConsumerAclApp {
public static void main(String[] args) {
SpringApplication.run(KafkaConsumerAclApp.class, args);
}
@KafkaListener(topics = "my-secured-topic", groupId = "my-secured-group")
public void listen(String message) {
System.out.println("Received secured message: " + message);
}
}Listing & Revoking ACLs
It's important to manage ACLs effectively. You can list all ACLs or specific ones:
kafka-acls.sh --list --topic 'my-topic' --authorizer-properties ...To remove an ACL, use the --remove flag instead of --add, specifying the exact ACL you wish to revoke:
kafka-acls.sh --remove --allow-principal 'User:Alice' --operation Read --topic 'my-topic' --authorizer-properties ...Regularly review and remove unnecessary permissions for security best practices.
ACLs Quick Check
Which of the following permissions are typically required for a Kafka consumer to successfully read messages from a topic and join a consumer group?
Recap: Securing with ACLs
Great job! You've learned how Kafka's authorization works using Access Control Lists (ACLs).
- ACLs define who (principal) can do what (operation) on where (resource).
- Key resources include topics, consumer groups, and the cluster itself.
- You use
kafka-acls.shto manage these permissions on the broker. - Spring Boot Kafka applications implicitly rely on these ACLs being in place for their authenticated principals.
Next, we'll explore how to encrypt data in transit using SSL/TLS.
用 AI 导师学习 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 48
常见问题解答
「使用 ACL 进行授权」课时是免费的吗?
是的 — 「使用 ACL 进行授权」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 课程的其余内容,请升级到 CoddyKit PRO。 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 课程共包含 4 节课。
「使用 ACL 进行授权」这节课中我会学到什么?
在 Kafka 代理上实施访问控制列表(ACL),为生产者和消费者定义细粒度权限 你通过在浏览器中直接运行的动手代码来练习 Advanced Spring Boot 4: Event-Driven Architecture (Kafka),全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。
「使用 ACL 进行授权」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 课中编写并运行代码吗?
能。每节 Advanced Spring Boot 4: Event-Driven Architecture (Kafka) 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。