安装带有ACL的kafka集群

  1. tar -zxvf kafka_2.11-0.11.0.2.tgz -C /app/svr/

  2. ln -s /app/svr/kafka_2.11-0.11.0.2/ /app/svr/kafka

  3. cd /app/svr/kafka

  4. vi config/server.properties

listeners=SASL_PLAINTEXT://0.0.0.0:9092
advertised.listeners=SASL_PLAINTEXT://cent1.steven:9092
log.dirs=/app/data/kafka-logs
auto.create.topics.enable=false
security.inter.broker.protocol=SASL_PLAINTEXT
sasl.enabled.mechanisms=PLAIN
sasl.mechanism.inter.broker.protocol=PLAIN
authorizer.class.name = kafka.security.auth.SimpleAclAuthorizer
super.users=User:kafka

  1. vi config/zookeeper.properties

dataDir=/app/data/zookeeper
authProvider.1=org.apache.zookeeper.server.auth.SASLAuthenticationProvider
maxClientCnxns=100
tickTime=2000
initLimit=10
syncLimit=5

  1. vi config/kafka_server_jaas.conf

KafkaServer {
org.apache.kafka.common.security.plain.PlainLoginModule required
username="kafka"
password="kafka-changeme"
user_kafka="kafka-changeme"
user_alice="alice-changeme"
user_bob="bob-changeme";
};
Client {
org.apache.kafka.common.security.plain.PlainLoginModule required
username="kafka"
password="kafka-changeme;
};

  1. vi config/kafka_zoo_jaas.conf

Server {
org.apache.kafka.common.security.plain.PlainLoginModule required
username="kafka"
password="kafka-changeme"
user_kafka="kafka-changeme";
};

  1. vi config/kafka_client_jaas.conf

KafkaClient {
org.apache.kafka.common.security.plain.PlainLoginModule required
username="alice"
password="alice-changeme";
};

  1. vi config/producer.properties

security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN

  1. vi config/consumer.properties

security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN

  1. vi bin/kafka-server-start.sh export KAFKA_OPTS before exec command

export KAFKA_OPTS=" -Djava.security.auth.login.config=/app/svr/kafka/config/kafka_server_jaas.conf"

  1. vi bin/zookeeper-server-start.sh export KAFKA_OPTS before exec command

export KAFKA_OPTS=" -Djava.security.auth.login.config=/app/svr/kafka/config/kafka_zoo_jaas.conf"

  1. vi bin/kafka-console-consumer.sh & bin/kafka-console-producer.sh export KAFKA_OPTS before exec command

export KAFKA_OPTS=" -Djava.security.auth.login.config=/app/svr/kafka/config/kafka_client_jaas.conf"

  1. bin/zookeeper-server-start.sh -daemon config/zookeeper.properties

  2. bin/kafka-server-start.sh -daemon config/server.properties

=======================================================

  1. bin/kafka-topics.sh --create --topic test --zookeeper cent1.steven:2181 --partitions 3 --replication-factor 1
  2. bin/kafka-topics.sh --list --zookeeper cent1.steven:2181
  3. vi config/kafka_admin_jaas.conf

Client {
org.apache.kafka.common.security.plain.PlainLoginModule required
username="kafka"
password="kafka-changeme";
};

  1. vi bin/kafka-acls.sh export KAFKA_OPTS before exec command

export KAFKA_OPTS=" -Djava.security.auth.login.config=/app/svr/kafka/config/kafka_admin_jaas.conf"

  1. bin/kafka-acls.sh --authorizer-properties zookeeper.connect=cent1.steven:2181 --add --allow-principal User:* --allow-host=* --operation All --topic test --group=*
  2. bin/kafka-acls.sh --authorizer-properties zookeeper.connect=cent1.steven:2181 --list --topic test
  3. bin/kafka-console-producer.sh --topic test --broker-list cent1.steven:9092 --producer.config config/producer.properties
  4. bin/kafka-console-consumer.sh --new-consumer --topic test --bootstrap-server cent1.steven:9092 --consumer.config config/consumer.properties
最后编辑于
©著作权归作者所有,转载或内容合作请联系作者
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。

推荐阅读更多精彩内容

  • Spring Cloud为开发人员提供了快速构建分布式系统中一些常见模式的工具(例如配置管理,服务发现,断路器,智...
    卡卡罗2017阅读 135,281评论 19 139
  • ** 今天看了一下kafka官网,尝试着在自己电脑上安装和配置,然后学一下官方document。** Introd...
    RainChang阅读 5,071评论 1 30
  • 本人陆陆续续接触了ELK的1.4,2.0,2.4,5.0,5.2版本,可以说前面使用当中一直没有太多感触,最近使用...
    三杯水Plus阅读 4,162评论 0 12
  • 环境: CentOS release 6.7 (Final)kafka_2.11-0.11.0.1.tgzzook...
    三更灯火阅读 664评论 0 0
  • 凝望 也许是一种享受 也许是一种刺激 也许是一种伤感 望着视线前曲解的文字 莫名的郁闷 行尸走肉般 颓废的苟活 对...
    灰色朦胧阅读 242评论 0 0