Kafka Producer Config Generator

A producer .properties file, with the four durability settings set together rather than offered separately. No password field: credentials are referenced from a mounted secret.

Connection
Durability

This choice sets acks, enable.idempotence, retries and max.in.flight together, because they only mean anything read as a group.

Batching and timeouts

Off keeps the file short. On protects against a default changing under you, which 3.0 and 4.0 both did.

Security

No password field, on purpose. The output references a mounted secret through Kafka's own FileConfigProvider and the commands to create it are in the notes.

producer.properties

updates as you type

    Common mistakes

    These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

    1. Putting the password in the generated file

      This generator deliberately has no password field, because a credential in a config file leaks into version control, process listings and logs.

      Instead:Reference a config provider, or supply the credential at runtime.

    2. Using acks=1 for anything that matters

      The leader acknowledges before replicating, so a leader failure right after the ack loses the write with no error.

      Instead:acks=all with min.insync.replicas=2 on RF 3.

    3. Setting retries high with in-flight requests unbounded

      A retried batch can land after a later one, silently reordering records within a partition.

      Instead:Enable idempotence, which handles it, or set max.in.flight.requests.per.connection=1.

    The four settings that are one decision

    A producer config is mostly durability, and durability is not four independent switches even though it looks like four settings.

    acks, idempotence, retries and in-flight move together

    acks=all without idempotence still duplicates on a retry. Idempotence requires acks=all, a retry count above zero and at most five requests in flight, and the client refuses to start if any of those disagree. Exposing them as four fields is how incoherent configs get generated, so this form asks what matters instead and sets all four. Kafka 3.0 turned idempotence on by default, which changed acks from 1 to all at the same time, so the same file behaves differently on a 2.x client.

    delivery.timeout.ms is the real bound on retrying

    retries defaults to Integer.MAX_VALUE, so it is not what stops a batch retrying: delivery.timeout.ms is. It caps the total time from send() to success or final failure, and when it expires the retries stop regardless of the count. Raising retries without raising this changes nothing at all, which is one of the most common wasted changes in a Kafka config.

    There is no password field, and that is the point

    The generated config references a mounted secret through Kafka's own FileConfigProvider rather than containing a credential, and the commands to create that file come with it. A .properties file holding a password is as sensitive as the password, and it ends up in an image layer, a ConfigMap, a Helm values file and a git history, each of which is a copy nobody is tracking. The trap that comes with the reference is checked too: without config.providers set, the reference is not resolved and no error is raised, so the literal ${file:...} string is used as the password.

    This page checks its own output

    Every change runs the generated file back through the producer config linter on this site, and the result is reported under the output. That is not decoration: it caught two real bugs in this generator during development. The first version emitted no key.serializer or value.serializer, which are required and have no default, so the config would not have started. Choose the throughput-first durability option and the linter reports the silent-loss finding on this page, immediately.

    What this cannot see

    It does not know your broker version, your topic's min.insync.replicas, or whether your cluster has enough replicas for acks=all to mean what you want. acks=all is only as strong as min.insync.replicas: with that at 1, acks=all waits for one replica and a single disk failure still loses data. It also cannot verify that the secret file exists or that the credentials in it work. For the upgrade question, the config upgrade checker on this site reads the same file against two versions.

    More kafka tools

    Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Quota Generator Byte rates are per broker, not per cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka ACL Generator The grant you forgot is on another resource type Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka ACL Permission Matrix Viewer DENY beats every ALLOW Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Config to Strimzi Half of it belongs elsewhere Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka JAAS Config Decoder The line that stops SASL working Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf Binary Decoder Works without the .proto Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka SASL JAAS Generator One login module, four syntaxes Kafka CLI Command Builder kcat is librdkafka, not Kafka

    Elsewhere on the site