Skip to content
LakeBench
ProblemsCommunityPricing
Sign inStart practicing
Back
  1. Home
  2. Interview prep
  3. Kafka security basics

Kafka · Operations & Scenarios

Kafka security basics

Mediumkafka-54
securitytls-encryptionauthenticationauthorizationacls

Question

How do you secure a Kafka cluster?

Solution

Securing an Apache Kafka cluster requires implementing TLS encryption for data in transit, configuring authentication through SASL mechanisms or mutual TLS (mTLS), and enforcing granular authorization using Access Control Lists (ACLs). Broker data volumes must be encrypted at rest using OS or cloud KMS storage encryption, while cluster networking should isolate internal inter-broker replication traffic from external client traffic using separate listeners.

Network listeners and encryption in transit

Exposing a single unencrypted port creates severe security vulnerabilities. Production brokers configure distinct listeners bound to separate network interfaces:

Listener 1 (Internal): SSL on port 9091 for inter-broker replication
Listener 2 (External): SASL_SSL on port 9092 for client applications

A clear security boundary emerges from this listener layout:

  • Inter-broker replication traffic runs over encrypted internal virtual private cloud subnets.
  • External client connections require TLS encryption in transit to prevent packet sniffing and credential interception.

Client authentication methods

Kafka verifies client identity using two primary standards:

  • Mutual TLS (mTLS): The client and broker exchange X.509 digital certificates to verify identity. It provides strong cryptographic security but adds operational complexity around certificate rotation.
  • SASL mechanisms: SASL/SCRAM stores salted password hashes directly inside Kafka; SASL/OAUTHBEARER validates JSON Web Tokens against enterprise identity providers; SASL/GSSAPI integrates with enterprise Kerberos infrastructure.

Granular authorization and storage encryption

Authentication identifies who a client is; authorization determines what they can do. Kafka ACLs enforce fine-grained permissions:

  • Restrict producers to write-only permissions on specific topics (such as orders).
  • Restrict consumers to read-only permissions on topics and limit offset commits to specific consumer group names.
  • At the physical storage layer, configure volume encryption using cloud KMS keys or Linux LUKS to encrypt raw log segment files at rest on disk.
PreviousNext