12-14-2017 06:00 AM
Does kafka2.2.0 in CDH 5.11.2 support ACL's on topics?? Can we use AD Users and groups for this ACL's? Do we have any documents for this? We have kerberos enables.
12-14-2017 11:05 AM
Kafka 2.2 uses sentry to provide authorization for kafka topics:
If you are using kerberos, you can add the sentry service and then follow the documentation for configuring kafka privileges.
12-15-2017 02:38 AM
We did try going with that approach but in our streaming cluster, we have only kafka and zookeeper services. When tried adding sentry, it was asking for hdfs service also to be presnt to add sentry. Not sure why hdfs is required for sentry to be available!!! I tried adding ACL's from command line, ACL's were created but that did not work.
12-28-2017 03:21 AM
Had to go with sentry and hdfs. Sentry is tightly coupled with hdfs and has a mandatory config "HDFS Service" so you need to have hdfs. you can configure hdfs and sentry and stop hdfs once sentry is completely configured