Kafka SASL JAAS Generator

The SASL login module written for a client properties file, a JAAS file, a broker's KafkaServer stanza or a Kubernetes secret. No password field: the output references a mounted secret and the commands that create the credential come with it.

Login module

There is no password field. The output references a mounted secret through Kafka's FileConfigProvider, and the commands that create the credential are in the notes.

Kerberos

GSSAPI only. Kerberos authenticates from a keytab rather than a password, so there is no secret reference at all.

sasl-jaas

updates as you type

    Common mistakes

    These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

    1. Mixing the four syntaxes

      The same login module is written differently in a JAAS file, in sasl.jaas.config, in a Java system property and in Kubernetes. Copying between them without translating produces a parse error at best.

      Instead:Generate for the target, and note that sasl.jaas.config must end with a semicolon inside its quoted value.

    2. Using PLAIN over a plaintext listener

      The password crosses the network essentially in the clear.

      Instead:SASL_SSL, or SCRAM which never transmits the password.

    3. Putting the JAAS file path in a shared image

      Anyone with the image has the credential, and it survives every redeploy.

      Instead:Mount it at runtime from a secret.

    One login module, four syntaxes, one unhelpful error

    The same SASL credential has to be written four different ways depending on where it goes, and only one of them is a Kafka property. When it is wrong the client starts, authentication fails, and the message names the credential rather than the file that could not be parsed.

    The semicolon is mandatory and is the usual mistake

    A JAAS login module entry ends with a semicolon, and leaving it out is the most common fault in a hand-written line. The error is a JAAS parser complaint about the configuration rather than anything mentioning Kafka or the credential, so it sends people to check the password first. In a properties file the whole entry also has to be on one line: a newline inside sasl.jaas.config splits the property, and the rest of the module becomes a key of its own and is silently ignored.

    sasl.jaas.config=org.apache.kafka.common.\
      security.scram.ScramLoginModule required \
      username="app" password="${file:...}";

    The context name is not free text

    In a JAAS file each stanza has a name and the name decides who reads it. A client reads KafkaClient, a broker reads KafkaServer, and a broker's ZooKeeper connection reads Client. A stanza under the wrong name parses successfully and is never used, which looks exactly like a credential that does not work. The Client stanza applies to 3.9 and earlier only: ZooKeeper is removed in 4.0, so a 4.0 broker has nothing to authenticate to.

    There is no password field here, on purpose

    A properties file holding a password is as sensitive as the password, and it ends up in an image layer, a ConfigMap, a Helm values file and a git history. The properties output references a mounted secret through Kafka's own FileConfigProvider instead, and config.providers plus config.providers.file.class are always emitted with it: without those two the reference is not resolved and no error is raised, so the literal string becomes the password and authentication fails against a config that reads correctly.

    A JAAS file cannot use a config provider at all

    It is read by the JVM rather than by Kafka, so provider references mean nothing in it and the password is a literal in the file. That is why the properties form is the better answer wherever the client supports it, which is everything since 0.10.2, and why the file form is still the only way to configure a broker's own login contexts.

    SCRAM and PLAIN differ in where the credential lives

    A SCRAM credential is created with kafka-configs.sh and stored by the cluster, so adding or rotating a user takes effect immediately. PLAIN keeps its whole user list inline in the broker's JAAS file, so every change needs a rolling restart. PLAIN also sends the password itself on each connection, which means SASL_SSL and never SASL_PLAINTEXT. For anything long lived, SCRAM.

    What this cannot see

    Whether the credential exists, whether the mechanism is in the broker's sasl.enabled.mechanisms, and whether the ACLs name the right principal. A SCRAM credential created while its mechanism is disabled is stored and unusable, and the failure looks identical to a wrong password. The JAAS decoder on this site reads a config back and never prints the password.

    More kafka tools

    Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Quota Generator Byte rates are per broker, not per cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka ACL Generator The grant you forgot is on another resource type Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Producer Config Generator No password field, on purpose Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka ACL Permission Matrix Viewer DENY beats every ALLOW Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Config to Strimzi Half of it belongs elsewhere Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka JAAS Config Decoder The line that stops SASL working Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf Binary Decoder Works without the .proto Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka CLI Command Builder kcat is librdkafka, not Kafka

    Elsewhere on the site