사용자 이름 · 비밀번호로 클라이언트와 브로커 사이를 인증한다. 비밀번호가 평문으로 오가므로 운영에서는 SASL_SSL 로 TLS 와 함께 쓴다[1]. 아래는 시험용 SASL_PLAINTEXT 구성이다. 인증 뒤의 권한은 Kafka ACL 설정 에서 준다.
KafkaServer 절의 username · password 는 브로커 사이 통신에 쓰고, user_<이름>="<비밀번호>" 가 접속을 허용할 클라이언트 계정 목록이다[1:1].
vi $KAFKA_HOME/config/kafka_server_jaas.conf
KafkaServer {
org.apache.kafka.common.security.plain.PlainLoginModule required
username="haedong"
password="${REDACTED}"
user_haedong="P@a88w0rd"
user_test="P@a88w0rd"
user_testuser="P@a88w0rd";
};
vi $KAFKA_HOME/config/server.properties
listeners=SASL_PLAINTEXT://HOST:9092
advertised.listeners=SASL_PLAINTEXT://HOST:9092
security.inter.broker.protocol=SASL_PLAINTEXT
sasl.mechanism.inter.broker.protocol=PLAIN
sasl.enabled.mechanisms=PLAIN
# KRaft 겸용 노드면 controller 리스너도 함께 둔다
#listeners=SASL_PLAINTEXT://HOST:9092,CONTROLLER://HOST:9093
#listener.security.protocol.map=CONTROLLER:PLAINTEXT,SASL_PLAINTEXT:SASL_PLAINTEXT
# 권한 (ACL) 을 쓸 때
authorizer.class.name=org.apache.kafka.metadata.authorizer.StandardAuthorizer
super.users=User:haedong
JAAS 파일 대신 server.properties 안에 바로 적을 수도 있다. 리스너 이름을 소문자로 붙인 키다.
listener.name.sasl_plaintext.plain.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \
username="haedong" password="${REDACTED}" user_haedong="P@a88w0rd" user_test="P@a88w0rd";
JAAS 파일은 JVM 인수로 넘긴다. kafka-server-start.sh 를 고치지 않고 KAFKA_OPTS 환경 변수를 쓴다[1:2].
export KAFKA_OPTS="-Djava.security.auth.login.config=$KAFKA_HOME/config/kafka_server_jaas.conf"
$KAFKA_HOME/bin/kafka-server-start.sh -daemon $KAFKA_HOME/config/server.properties
systemd 유닛이면 [Service] 절에 Environment="KAFKA_OPTS=-Djava.security.auth.login.config=/opt/kafka/config/kafka_server_jaas.conf" 를 넣는다.
계정마다 하나씩 만든다. test 사용자용.
vi $KAFKA_HOME/config/test.properties
security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN
sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="test" password="${REDACTED}";
$KAFKA_HOME/bin/kafka-console-producer.sh --bootstrap-server localhost:9092 --topic test --producer.config $KAFKA_HOME/config/test.properties
$KAFKA_HOME/bin/kafka-console-consumer.sh --bootstrap-server localhost:9092 --topic test --group test-group --consumer.config $KAFKA_HOME/config/test.properties
authorizer 를 켰으면 슈퍼유저 설정으로 권한을 준다. 관리용 admin.properties 는 Kafka ACL 설정 참조.
$KAFKA_HOME/bin/kafka-acls.sh --bootstrap-server localhost:9092 --command-config $KAFKA_HOME/config/admin.properties --add --allow-principal User:test --producer --topic test
$KAFKA_HOME/bin/kafka-acls.sh --bootstrap-server localhost:9092 --command-config $KAFKA_HOME/config/admin.properties --add --allow-principal User:test --consumer --topic test --group test-group
인증 정보 없이 붙으면 Authentication failed 로 끊긴다.
$KAFKA_HOME/bin/kafka-topics.sh --bootstrap-server localhost:9092 --list
# [Consumer clientId=..., groupId=...] Connection to node -1 terminated during authentication.
$KAFKA_HOME/bin/kafka-topics.sh --bootstrap-server localhost:9092 --list --command-config $KAFKA_HOME/config/test.properties
Kafka 4.3 — Authentication using SASL/PLAIN — 2026-09-20 확인. https://kafka.apache.org/43/security/authentication-using-sasl/ ↩︎ ↩︎ ↩︎