Kafka Cluster 에 보안 설정이 돼 있는 경우 Mirror maker 에서 연결하기 위한 매뉴얼이다. 클러스터 별칭(S · T)을 접두사로 붙여 소스 · 타깃 각각의 인증 정보를 준다. 클라이언트 설정 키 이름은 4.x 에서도 같다[1].
아래는
SASL_PLAINTEXT— 비밀번호가 평문으로 오간다. 운영에서는SASL_SSL로 TLS 와 함께 쓴다[1:1]. 브로커 쪽 설정은 SASL PLAIN 인증 을 볼 것.
vim config/mm2.properties
아래 항목을 추가한다.
S.security.protocol=SASL_PLAINTEXT
S.sasl.mechanism=PLAIN
S.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \
username="admin" \
password="${REDACTED}";
T.security.protocol=SASL_PLAINTEXT
T.sasl.mechanism=PLAIN
T.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \
username="admin" \
password="${REDACTED}";
# Licensed to the Apache Software Foundation (ASF) under A or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# see org.apache.kafka.clients.consumer.ConsumerConfig for more details
# Sample MirrorMaker 2.0 top-level configuration file
# Run with ./bin/connect-mirror-maker.sh connect-mirror-maker.properties
# specify any number of cluster aliases
clusters = S, T
# connection information for each cluster
# This is a comma separated host:port pairs for each cluster
# for e.g. "A_host1:9092, A_host2:9092, A_host3:9092"
#A.bootstrap.servers = A_host1:9092, A_host2:9092, A_host3:9092
#B.bootstrap.servers = B_host1:9092, B_host2:9092, B_host3:9092
S.bootstrap.servers = 192.168.103.151:9092, 192.168.103.152:9092, 192.168.103.153:9092
T.bootstrap.servers = 192.168.103.154:9092, 192.168.103.155:9092, 192.168.103.156:9092
# enable and configure individual replication flows
S->T.enabled = true
# regex which defines which topics gets replicated. For eg "foo-.*"
S->T.topics = igkim.*
T->S.enabled =
T->S.topics =
# Setting replication factor of newly created remote topics
replication.factor=2
S.producer.max.request.size=102400000
T.producer.max.request.size=102400000
S.security.protocol=SASL_PLAINTEXT
S.sasl.mechanism=PLAIN
S.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \
username="admin" \
password="${REDACTED}";
T.security.protocol=SASL_PLAINTEXT
T.sasl.mechanism=PLAIN
T.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \
username="admin" \
password="${REDACTED}";
############################# Internal Topic Settings #############################
# The replication factor for mm2 internal topics "heartbeats", "B.checkpoints.internal" and
# "mm2-offset-syncs.B.internal"
# For anything other than development testing, a value greater than 1 is recommended to ensure availability such as 3.
checkpoints.topic.replication.factor=2
heartbeats.topic.replication.factor=2
offset-syncs.topic.replication.factor=2
# The replication factor for connect internal topics "mm2-configs.B.internal", "mm2-offsets.B.internal" and
# "mm2-status.B.internal"
# For anything other than development testing, a value greater than 1 is recommended to ensure availability such as 3.
offset.storage.replication.factor=2
status.storage.replication.factor=2
config.storage.replication.factor=2
# customize as needed
# replication.policy.separator = _
# sync.topic.acls.enabled = false
# emit.heartbeats.interval.seconds = 5
bin/connect-mirror-maker.sh -daemon config/mm2.properties
latest · earliest 는 컨슈밍하는 컨슈머의 group id 가 존재하지 않을 경우 reset 의 시작점을 말하는 것이다.kafka-console-producer.sh --bootstrap-server localhost:9092 --topic mm2-offsets.TEST.internal \
--property "parse.key=true" \
--property "key.separator=%"
["MirrorSourceConnector",{"cluster":"TEST","partition":0,"topic":"SEV_MES_NASLOG_SPC"}]%{"offset":719488292}
--broker-list 는 Kafka 3.0 에서 없어졌다. --bootstrap-server 를 쓴다.
Kafka 4.3 — Authentication using SASL — 2026-09-20 확인. https://kafka.apache.org/43/security/authentication-using-sasl/ ↩︎ ↩︎