Reply
Contributor
Posts: 41
Registered: ‎10-04-2017
Accepted Solution

Does kafka2.2.0 in CDH 5.11.2 support ACL's on topics??

Hi,

 

Does kafka2.2.0 in CDH 5.11.2 support ACL's on topics?? Can we use AD Users and groups for this ACL's? Do we have any documents for this? We have kerberos enables.

Highlighted
Cloudera Employee
Posts: 203
Registered: ‎01-09-2014

Re: Does kafka2.2.0 in CDH 5.11.2 support ACL's on topics??

Kafka 2.2 uses sentry to provide authorization for kafka topics:

 

https://www.cloudera.com/documentation/kafka/2-2-x/topics/kafka_security.html#using_kafka_with_sentr...

 

If you are using kerberos, you can add the sentry service and then follow the documentation for configuring kafka privileges.

 

-pd

Contributor
Posts: 41
Registered: ‎10-04-2017

Re: Does kafka2.2.0 in CDH 5.11.2 support ACL's on topics??

Hi @pdvorak

 

We did try going with that approach but in our streaming cluster, we have only kafka and zookeeper services. When tried adding sentry, it was asking for hdfs service also to be presnt to add sentry. Not sure why hdfs is required for sentry to be available!!! I tried adding ACL's from command line, ACL's were created but that did not work.

Contributor
Posts: 41
Registered: ‎10-04-2017

Re: Does kafka2.2.0 in CDH 5.11.2 support ACL's on topics??

Had to go with sentry and hdfs. Sentry is tightly coupled with hdfs and has a mandatory config "HDFS Service" so you need to have hdfs. you can configure hdfs and sentry and stop hdfs once sentry is completely configured

Announcements