Kafka Security Best Practices: SSL, SASL, ACLs & Enterprise Governance
Apache Kafka often sits at the center of an enterprise event-driven architecture. Applications may publish and consume sensitive information such as customer events, payment transactions, order updates, audit events, operational telemetry and business data. A production Kafka platform therefore needs more than high throughput and fault tolerance. It also needs a clear security model. A practical Kafka security architecture should answer four fundamental questions: 1. Encryption — Can someone read Kafka traffic in transit? 2. Authentication — Who is connecting to Kafka? 3. Authorization — What is that identity allowed to do? 4. Governance — How is access controlled, reviewed, monitored and audited over time? Apache Kafka supports encrypted communication using SSL/TLS, client authentication using SSL or SASL, and authorization for operations performed against Kafka resources. Current Kafka documentation lists GSSAPI/Kerberos, PLAIN, SCRAM-SHA-256, SCRAM-SHA-512 and OAUTHBEA...