Kafka ACL Generator

The kafka-acls.sh commands an activity really needs, with the reason for each grant above it. The grants people miss are on resource types they were not thinking about.

What is it allowed to do
Resources

A prefixed ACL covers topics that do not exist yet, which is convenient and is also how a service quietly gains access to a topic nobody meant to grant.

From 3.0 the broker grants IDEMPOTENT_WRITE implicitly to anyone with topic WRITE, so emitting it is unnecessary noise on a current cluster.

grant-acls.sh

updates as you type

    Common mistakes

    These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

    1. Granting on the topic and forgetting the group

      A consumer needs READ on the topic AND READ on its consumer group. With only the first it fails to join, and the error names the group.

      Instead:Grant both. A producer with transactions also needs WRITE on the transactional id.

    2. Using LITERAL where PREFIXED was meant

      A literal ACL covers exactly one name. A service writing to a topic per tenant needs a prefixed pattern or an ACL per topic forever.

      Instead:Use PREFIXED for anything with a naming convention.

    3. Leaving host as *

      The default permits the principal from anywhere on the network. It is the cheapest tightening available and is almost never applied.

      Instead:Restrict host where the client network is known.

    Why a Kafka ACL is almost never one grant

    Every activity touches more resource types than it sounds like, and the authorization error names the resource the client tried rather than the permission it was missing.

    A producer needs DESCRIBE, not just WRITE

    The producer fetches topic metadata before it can send anything, so WRITE alone fails at startup with an authorization error naming the topic. That reads as though the topic does not exist, which sends people to check the topic list rather than the ACL. Both operations, always.

    A consumer needs the group, and the group is a separate resource type

    READ on the topic is not enough: the consumer group is its own resource, and a consumer without READ on it fails when joining the group. This is the single most common Kafka ACL mistake. The error mentions the group id in a way that looks like a configuration typo, so the fix people try first is changing group.id, which creates a new group with the same problem.

    A transactional producer needs a third resource type

    TransactionalId is neither a topic nor a group, and it needs WRITE and DESCRIBE. Without it initTransactions blocks and then fails, after the producer has already connected successfully, which makes it look like a broker or a network problem rather than a permission. Nothing in a topic-shaped mental model of Kafka authorization includes this.

    Streams needs a prefix on its own application.id

    A Streams application creates changelog and repartition topics at runtime, named after its application.id, so it needs CREATE, WRITE, READ and DELETE on that prefix rather than on a topic that exists. That makes application.id a security boundary as well as an identity: a generic one grants access to a prefix another team may already be using, and a specific one does not.

    Two things that look like security and are not

    Restricting by --allow-host is weaker than it appears: a request arriving through a load balancer, a proxy or a VPC endpoint presents that hop's address, so the rule either blocks legitimate traffic or matches something unintended. And --deny-principal wins over every allow, which makes an accidental deny very hard to diagnose, because the principal has an allow ACL that visibly exists and does not work. Grant narrowly rather than denying broadly. Neither is used by this generator.

    What this cannot see

    It does not know your cluster's authorizer, whether allow.everyone.if.no.acl.found is set, or what the principal already has. It cannot tell you whether your mTLS principal mapping shortens the distinguished name the way your ACL assumes, which is where mTLS authorization usually goes wrong. Run the --list command at the end of the output to see what was actually granted, and treat that rather than this page as the truth.

    More kafka tools

    Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Quota Generator Byte rates are per broker, not per cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Producer Config Generator No password field, on purpose Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka ACL Permission Matrix Viewer DENY beats every ALLOW Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Config to Strimzi Half of it belongs elsewhere Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka JAAS Config Decoder The line that stops SASL working Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf Binary Decoder Works without the .proto Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka SASL JAAS Generator One login module, four syntaxes Kafka CLI Command Builder kcat is librdkafka, not Kafka

    Elsewhere on the site