Kafka Config to Strimzi

Turn a server.properties into Strimzi resources, splitting the settings the operator owns from the ones that belong in spec.kafka.config. An operator-owned key in the config block is rejected rather than merged, which is the part worth knowing before applying anything.

The output is two KafkaNodePool resources and one Kafka resource, which is the shape current Strimzi wants. The disk and retention calculator on this site sizes the storage figure.

Paste below, or drop a file anywhere on this panel

Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.

The answer appears here

Paste on the left and press Convert. Nothing leaves this tab.

Examples

Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.

Broker config as a Kafka CR

server.properties translated into the Strimzi resource, with what Strimzi manages itself

num.partitions=6
min.insync.replicas=2
log.retention.hours=168

Settings Strimzi refuses

Listener and storage settings the operator owns, which cannot be set in config

listeners=PLAINTEXT://:9092
log.dirs=/var/lib/kafka
num.partitions=12

Common mistakes

These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

  1. Setting listeners in the Kafka CR config

    Strimzi owns listeners, storage and rack. Settings it manages are rejected or overwritten.

    Instead:Use the CR's own listeners section.

  2. Expecting the operator to keep your topic settings

    Topics are separate KafkaTopic resources. Broker defaults do not retroactively change existing topics.

    Instead:Manage topics as their own resources.

  3. Migrating certificates by copying files

    Strimzi generates and rotates its own CA and certificates. Hand-placed files are replaced.

    Instead:Let the operator manage them, or supply a custom CA the documented way.

Half of a server.properties does not belong in spec.kafka.config

The Strimzi operator generates listeners, storage, authorization and certificates from the resource. Putting one of those settings in the config block is rejected, not merged, so knowing which is which is most of the conversion.

The operator owns anything it generates

listeners, advertised.listeners and everything under listener. come from spec.kafka.listeners. log.dirs comes from spec.kafka.storage. authorizer.class.name and super.users come from spec.kafka.authorization. Every ssl. and sasl. setting comes from the listener definitions, because the operator runs its own CA and issues the certificates. broker.id is assigned per pod. Supply any of these in spec.kafka.config and the operator refuses the resource, which is better than silently overriding you but only if you know why.

# rejected in spec.kafka.config
listeners             -> spec.kafka.listeners
log.dirs              -> spec.kafka.storage
authorizer.class.name -> spec.kafka.authorization
super.users           -> spec.kafka.authorization.superUsers
ssl.keystore.location -> managed by the operator's CA
broker.id             -> assigned per pod

Node pools are the current shape

Recent Strimzi models brokers and controllers as KafkaNodePool resources with a roles list, alongside one Kafka resource carrying the shared configuration, and it wants the node-pools and kraft annotations enabled. The output here is two pools and one Kafka resource for that reason: a single Kafka resource with a replicas field is the older ZooKeeper-era shape.

Internal topic replication factors have to fit the broker count

The operator creates __consumer_offsets and __transaction_state using the replication factors in spec.kafka.config. If those exceed the broker count the topics cannot be created, and the cluster comes up looking healthy until the first consumer group tries to commit. The replication factor of an existing internal topic cannot be raised afterwards without a reassignment, so this is much cheaper to get right before first start.

Certificates are issued and rotated for you

Strimzi runs a CA and gives every broker and every KafkaUser a certificate, renewing them on a schedule. That is why no ssl. path belongs in the config: a keystore location you supply would be generated over. To bring your own CA you replace the operator's CA Secrets rather than configuring paths, which is a different operation from what a properties file expresses.

What this does not carry across

Listener and storage values in the output are working defaults rather than translations of yours, because those are structured fields with no properties equivalent to derive from: a listener in Strimzi has a name, a type and an authentication block, not a URL. Everything the operator does not own is copied into spec.kafka.config verbatim, and everything it does own is listed at the bottom with the field that replaces it.

More kafka tools

Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Quota Generator Byte rates are per broker, not per cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka ACL Generator The grant you forgot is on another resource type Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Producer Config Generator No password field, on purpose Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka ACL Permission Matrix Viewer DENY beats every ALLOW Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka JAAS Config Decoder The line that stops SASL working Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf Binary Decoder Works without the .proto Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka SASL JAAS Generator One login module, four syntaxes Kafka CLI Command Builder kcat is librdkafka, not Kafka

Elsewhere on the site