11. Securing Kafka
11.11 The security decision guide
Choosing a security protocol per listener
| Situation | Protocol |
|---|---|
| Internal, physically protected, non-sensitive | PLAINTEXT — rarely OK |
| Internal, need identity, network is trusted | SASL_PLAINTEXT — careful |
| Certificate-based identity, insecure network | SSL + ssl.client.auth |
| Any external / internet-facing listener | SASL_SSL — the default |
Choosing a SASL mechanism
| Situation | Mechanism |
|---|---|
| You already run Kerberos (AD / OpenLDAP) | GSSAPI |
| Want built-in, no extra servers, secure ZooKeeper | SCRAM-SHA-512 — good default |
| Have an OAuth 2.0 provider | OAUTHBEARER + custom callbacks — not the built-in |
| Must integrate an existing password store | PLAIN + custom server callback — never the built-in |
| Distributing credentials to many workers is hard | Delegation tokens |
Encryption — pick based on who you're defending against
| Adversary | Encryption |
|---|---|
| Network eavesdropper | TLS (SSL / SASL_SSL) |
| Someone who steals a disk | Whole-disk / volume encryption |
| Platform admin, cloud provider, heap dumps, broker logs | End-to-end encryption (serializer + KMS) |
Production hardening checklist
Authentication
SASL_SSL(orSSL) on every non-trivial listener; no barePLAINTEXT- Hostname verification enabled (never disabled)
- TLSv1.2/1.3 only; cipher suites restricted (≥256-bit)
connections.max.reauth.msset — or compromised credentials live forever- Certificate/keytab/token lifetimes short; rotation rehearsed
- Filesystem permissions on all key stores, trust stores, keytabs
- Passwords externalized (
ConfigProvider) or encrypted (password.encoder.secret);PASSWORDconfig type used
Authorization
authorizer.class.name=kafka.security.authorizer.AclAuthorizerallow.everyone.if.no.acl.found = falsesuper.usersempty — or minimal, understood to be unrevocable- Broker ACL:
Cluster:ClusterAction— brokers only - Least privilege; prefixed ACLs per department; group/role authorizer
- Service principals for long-running apps, not personal ones
- Deny-ACL incident procedure documented and practised
Encryption
- Disk/volume encryption on broker log dirs and ZooKeeper
dataDir - End-to-end encryption for PII/regulated data, plus signatures
- Kafka compression disabled if encrypting in the serializer
- Key encryption, if required, uses a hash as the Kafka key
Auditing
kafka.authorizer.logger+kafka.request.loggershipped to a log platform- Authentication-failure metrics alerted on
DEBUGenabled if a full allow-trail is required
ZooKeeper and platform
- ZK: TLS (3.5.0+) and/or SASL/GSSAPI — never DIGEST-MD5 in production
kerberos.removeHostFromPrincipal/removeRealmFromPrincipal= truezookeeper.set.acl = true- Network firewalls; restricted config-file access
- A written threat model covering external and insider threats
- Quotas configured (Ch. 3) to bound DoS
How the chapter's guarantees map to mechanisms
| Guarantee | Mechanisms |
|---|---|
| Client authenticity | SASL, or SSL with client auth; reauthentication to limit compromise exposure |
| Server authenticity | SSL with hostname validation, or mutual-auth SASL (Kerberos, SCRAM) |
| Data privacy | TLS in transit; disk/volume encryption at rest; end-to-end for fine-grained control against admins/cloud providers |
| Data integrity | TLS detects tampering; digital signatures in messages under end-to-end encryption |
| Access control | Customizable authorizer; built-in AclAuthorizer with fine-grained ACLs |
| Auditability | Authorizer logs + request logs; message-header audit metadata |
| Availability | Quotas + connection management against DoS; ZooKeeper secured with SSL, SASL, and ACLs |