FA-0738CybersecurityDevOps, Cloud & Infrastructure

Kafka Security with Kerberos

TLS, SASL/GSSAPI and access-control labs

Introduction

Why this course

Learn to configure and test Kafka encryption, authentication and access controls in a guided lab. The course combines TLS certificates, Kerberos principals and keytabs, broker/client configuration and ACL demonstrations.

Current Kafka exercises use a compatible KRaft-based environment. ZooKeeper security is covered separately for understanding legacy Kafka deployments.

Learning outcomes

Learning outcomes

  • Distinguish transport encryption, authentication and authorisation in Kafka.
  • Configure and test TLS for brokers and clients, including certificate trust and client authentication.
  • Use Kerberos/GSSAPI principals and keytabs with Kafka SASL configuration.
  • Apply and test Kafka ACLs for selected client operations.
  • Explain ZooKeeper security considerations for legacy deployments and identify cluster-security dependencies.
Prerequisites

Prerequisites

  • Basic Kafka producer/consumer and cluster knowledge.
  • Linux command-line skills and familiarity with service configuration.
  • Access to the designated Kafka and Kerberos lab environment.
Training outline

3 modules

·
01Day 1 — Kafka Setup and TLS6 topics
  • Kafka security overview and lab structure.
  • Set up a compatible Kafka environment and verify console producer/consumer operation.
  • Contrast KRaft setup with the ZooKeeper-based legacy architecture.
  • TLS encryption, certificate authorities, broker certificates and client trust.
  • Create a lab CA and configure broker/client TLS; verify hostname and trust behaviour.
  • Configure certificate-based client authentication and test connections.
02Day 2 — Kerberos and SASL Authentication5 topics
  • SASL mechanisms and the role of GSSAPI/Kerberos.
  • Prepare the lab Kerberos service and relevant naming/configuration dependencies.
  • Create broker and client principals and keytabs.
  • Configure Kafka broker and client JAAS/SASL settings and test authenticated production/consumption.
  • Distinguish SASL authentication from TLS transport encryption; use a compatible SASL_SSL configuration in the combined lab.
03Day 3 — Authorisation and Cluster Security6 topics
  • Kafka ACL resources, principals and operations.
  • Configure the appropriate KRaft authorizer and demonstrate allowed and denied client operations.
  • Legacy ZooKeeper security: principals, Kerberos configuration, znodes and ACLs.
  • Discuss ZooKeeper privileged users and legacy security-migration tooling in version context.
  • Cluster security review: client, inter-broker and controller communication, credential handling and configuration checks.
  • Review practical results and troubleshoot selected authentication/authorisation failures.

A programme built around your team.

Share your training goals and requirements.

Kafka Security with Kerberos
FA-0738

Share your requirements for this programme.

Training enquiry

Kafka Security with Kerberos