11.4 Security updates without downtime
Note the shape: enable both → migrate clients → migrate inter-broker → remove the old.
"Kafka deployments need regular maintenance to rotate secrets, apply security fixes, and update to the latest security protocols. Many of these are performed using rolling updates... Some tasks like updating SSL key stores and trust stores can be performed using DYNAMIC CONFIG UPDATES WITHOUT RESTARTING BROKERS."
PLAINTEXT → SASL_SSL (add a listener, migrate, remove)
- Add a new listener on a New port to each broker using the configs tool. “Use A single config update command to update
listenersAndadvertised.listenersto include the Old listener as well as the New listener, and provide all the configuration options for the new SASL_SSL listener With the listener prefix.” - Modify all client applications to use the new SASL_SSL listener.
- If inter-broker communication is being updated, perform a Rolling update of brokers with the new
inter.broker.listener.name. - Use the configs tool to Remove the old listener from
listenersandadvertised.listeners, and remove unused options of the old listener.
The key idea: two listeners coexist during the migration, so clients migrate at their own pace. No flag day.
PLAIN → SCRAM-SHA-256 (same listener port, five steps)
- Add all existing users to the SCRAM store using the configs tool.
- Set
sasl.enabled.mechanisms=PLAIN,SCRAM-SHA-256, configurelistener.name.<name>.scram-sha-256.sasl.jaas.config, and perform a Rolling update. - Modify all client applications:
sasl.mechanism=SCRAM-SHA-256and updatesasl.jaas.configto use SCRAM. - If the listener is used for inter-broker communication, Rolling update to set
sasl.mechanism.inter.broker.protocol=SCRAM-SHA-256. - Rolling update to Remove the PLAIN mechanism: set
sasl.enabled.mechanisms=SCRAM-SHA-256and removelistener.name.<name>.plain.sasl.jaas.configand any other PLAIN options.
Note the shape: enable both → migrate clients → migrate inter-broker → remove the old. Same pattern as the listener migration, one level down.
11.3 Authentication
KafkaPrincipal is established during authentication based on the protocol (e.g. User:Alice) and can be customized via principal.builder.class.
11.5 Encryption
That's a real operational cost of combining end-to-end encryption with compacted topics: key rotation becomes a maintenance window.