12.0 Two warnings before you run anything
And later, more bluntly: "Older console consumers can potentially DAMAGE THE CLUSTER by interacting with the cluster or ZooKeeper in incorrect ways."
⚠️ AUTHORIZING ADMIN OPERATIONS
"While Apache Kafka implements authentication and authorization to control topic operations, DEFAULT CONFIGURATIONS DO NOT RESTRICT THE USE OF THESE TOOLS. This means that these CLI tools can be used WITHOUT ANY AUTHENTICATION REQUIRED, which will allow operations such as topic changes to be executed WITH NO SECURITY CHECK OR AUDIT. ALWAYS ENSURE THAT ACCESS TO THIS TOOLING ON YOUR DEPLOYMENTS IS RESTRICTED TO ADMINISTRATORS ONLY to prevent unauthorized changes."
(Cross-reference Ch. 11: ACLs govern the protocol, but tools that write directly to ZooKeeper bypass the authorizer entirely. Shell access to a broker host is admin access.)
⚠️ CHECK THE VERSION
*"Many of the command-line tools have a dependency on the version of Kafka running to operate correctly. This includes some commands that may store data in ZooKeeper rather than connecting to the brokers themselves. For this reason, it is important to make sure the version of the tools you are using MATCHES the version of the brokers in the cluster.
The safest approach is to RUN THE TOOLS ON THE KAFKA BROKERS THEMSELVES, using the deployed version."*
And later, more bluntly: "Older console consumers can potentially DAMAGE THE CLUSTER by interacting with the cluster or ZooKeeper in incorrect ways."