Learn Labs
11. Securing Kafka

11.10 What actually breaks in production — Ch. 11 consolidated

Production failure catalog
0 rows
#SymptomRoot causeFix
1Anyone can read/write; no identity in logsPLAINTEXT listener → principal is User:ANONYMOUSSSL or SASL_SSL listener
2Clients on an SSL listener show as User:ANONYMOUSssl.client.auth=requested (not required) and the client has no key storeUse required if you need identity
3Man-in-the-middle possibleHostname verification disabled to "fix" a cert problem"Should NOT be disabled in production." Fix the SAN/CN, or use client.dns.lookup (Ch. 5)
4TLS handshake failures appear overnightCertificates expiredRotate before expiry; broker stores are dynamically updatable via configs tool / Admin API
5Inter-broker TLS fails after enabling client authBroker trust store lacks the client CA (or the broker CA)"Broker trust stores should include the CA of the broker certificates AS WELL AS the CA of the client certificates"
6Throughput drops 20–30% after enabling SSLZero-copy is not supported for SSLExpected. Consider where encryption is truly needed (Ch. 10 §7.2)
7Broker network threads saturated; clients can't connectTLS handshake DoS — handshakes run on network threadsConnection quotas/limits + connection.failed.authentication.delay.ms
8Private keys readable by other usersKey stores are plain files on diskFilesystem permissions on all key/trust stores and keytabs
9Kerberos auth fails intermittentlyForward/reverse DNS mismatchrdns=false in client krb5.conf; secure DNS is a requirement
10All clients fail to authenticate at onceKDC or DNS outage (or DoS)"It is NECESSARY to monitor the availability of these services"
11Kerberos replay detection breaks / auth fails after clock driftClock skew beyond configured variabilitySecure, monitored NTP — clock sync is part of the security perimeter
12Adding one user requires restarting every brokerSASL/PLAIN's built-in JAAS password storeCustom server callback handler → external password server
13Passwords visible in logsConfig not declared as PASSWORD typeUse ConfigDef PASSWORD type; externalize/encrypt
14Password rotation causes an outageServer accepts only one password at a timeCallback that accepts old and new for an overlap window + reauthentication
15Credentials stolen off the wireSASL/PLAIN or SASL/SCRAM over SASL_PLAINTEXTAlways SASL_SSL — PLAIN sends clear text; SCRAM exposes hashed keys during handshake
16SCRAM credentials stolen from ZooKeeperZooKeeper not SSL-enabled / disk not encryptedBoth are stated requirements for production SCRAM
17A deleted user keeps workingExisting connections survive user deletionconnections.max.reauth.ms; Deny ACL for immediate effect
18Compromised user still active after removalNo reauth interval; SSL renegotiation is not supported so SSL connections never re-verifyDeny ACL — "the quickest way to disable access" — plus reauth config
19Compromised super user can't be revoked quicklysuper.users cannot be denied and requires a broker restart to changeDon't use super.users in production; grant explicit ACLs
20super.users list parsed wronglyUsed commas; DNs contain commasSemicolon-separated
21Adding an ACL unexpectedly revoked others' accessallow.everyone.if.no.acl.found=true, and a new prefix/wildcard ACL made no.acl.found falseDon't use it in production
22New topics silently world-accessibleSame configSame fix
23OAuth "works" in staging but is insecureBuilt-in OAUTHBEARER uses unsecured JWTs and does not validate tokensCustom login + server validator callbacks against a real OAuth server
24Connections outlive their OAuth tokensNo reauthenticationconnections.max.reauth.ms + token revocation
25A delegation token was used to mint more tokensIt can't be"Clients authenticated using delegation tokens CANNOT create other delegation tokens"
26All delegation tokens brokeMaster key rotated — requires restarting all brokers and deleting existing tokensPlan the rotation: delete tokens → update key on all brokers → restart → recreate
27Idempotent producer fails authorizationMissing Cluster:IdempotentWrite (non-transactional only)Grant it
28Transactional producer fails authorizationMissing TransactionalId:Write and/or Group:ReadGrant both (Ch. 8)
29Consumer can fetch but not join a groupHas Topic:Read but not Group:ReadGrant Group:Read
30A client was granted unintended broker powersCluster:ClusterAction granted to a non-broker"Should ONLY be granted to brokers"
31Unmanageable ACL sprawlPer-resource literal ACLs at scalePrefixed ACLs by department + group/role principals via a custom authorizer
32Departing employee's credentials still power a serviceApplication used a personal principal"Long-running applications can be configured with SERVICE credentials"
33A reused principal name inherits old accessPrincipal reuse"Reuse of principals must be AVOIDED"
34No record of who accessed whatGrants log at DEBUG, only denials at INFOEnable DEBUG on kafka.authorizer.logger if you need a full trail
35Sensitive data found in a broker heap dumpTLS + disk encryption don't cover broker memoryEnd-to-end encryption (serializer/deserializer + KMS)
36Cloud provider / platform admin could read customer dataBroker sees plaintextEnd-to-end encryption — "brokers never see the unencrypted contents"
37Compression gives no benefit and adds CPUCompressing after encryption (high-entropy data)Compress before encrypting; disable Kafka compression
38Partitioning and compaction break after encrypting keysEncrypted keys aren't hash-stableMessage key = secure hash of the original; encrypted key in header/payload via a producer interceptor
39Key rotation needs a maintenance windowCompacted topics retain old-key messages indefinitely; re-encryption requires producers and consumers offlinePlan it; keep old keys available for the retention period
40ZooKeeper ACLs written by one broker exclude othersFull Kerberos principals differ per brokerkerberos.removeHostFromPrincipal=true + kerberos.removeRealmFromPrincipal=true
41Unexpected ZooKeeper access grantedZK with SASL and SSL client auth associates multiple principals; any may grantUnderstand the model; audit ZK ACLs
42Anyone can read Kafka metadata from ZooKeeperzookeeper.set.acl not enabledEnable it — metadata becomes broker-writable only; sensitive paths (SCRAM) are not world-readable
43DIGEST-MD5 used in productionIt has "known security vulnerabilities"Kerberos or TLS mutual auth
44Flag-day protocol migration caused an outageChanged the listener protocol in placeAdd a new listener on a new port, migrate clients, then remove the old