0


windows 11 配置 kafka 使用SASL SCRAM-SHA-256 认证

1. 下载安装apache-zookeeper-3.9.2

配置 \conf\zoo.cfg
  1. # The number of milliseconds of each tick
  2. tickTime=2000
  3. # The number of ticks that the initial
  4. # synchronization phase can take
  5. initLimit=10
  6. # The number of ticks that can pass between
  7. # sending a request and getting an acknowledgement
  8. syncLimit=5
  9. # the directory where the snapshot is stored.
  10. # do not use /tmp for storage, /tmp here is just
  11. # example sakes.
  12. dataDir=D:/server/data/zookeeper
  13. dataLogDir=D:/server/data/zookeeperLog
  14. # admin管理端端口
  15. #admin.serverPort=8887
  16. # the port at which the clients will connect
  17. clientPort=2181
  18. # the maximum number of client connections.
  19. # increase this if you need to handle more clients
  20. #maxClientCnxns=60
  21. #
  22. # Be sure to read the maintenance section of the
  23. # administrator guide before turning on autopurge.
  24. #
  25. # https://zookeeper.apache.org/doc/current/zookeeperAdmin.html#sc_maintenance
  26. #
  27. # The number of snapshots to retain in dataDir
  28. #autopurge.snapRetainCount=3
  29. # Purge task interval in hours
  30. # Set to "0" to disable auto purge feature
  31. #autopurge.purgeInterval=1
  32. ## Metrics Providers
  33. #
  34. # https://prometheus.io Metrics Exporter
  35. #metricsProvider.className=org.apache.zookeeper.metrics.prometheus.PrometheusMetricsProvider
  36. #metricsProvider.httpHost=0.0.0.0
  37. #metricsProvider.httpPort=7000
  38. #metricsProvider.exportJvmInfo=true
2. 启动 zkServer.cmd

3. 下载并重命名 kafka , kafka2.12.3.8.0

4. 编辑配置 \config\server.properties 以使用 SCRAM-SHA-256
  1. # Licensed to the Apache Software Foundation (ASF) under one or more
  2. # contributor license agreements. See the NOTICE file distributed with
  3. # this work for additional information regarding copyright ownership.
  4. # The ASF licenses this file to You under the Apache License, Version 2.0
  5. # (the "License"); you may not use this file except in compliance with
  6. # the License. You may obtain a copy of the License at
  7. #
  8. # http://www.apache.org/licenses/LICENSE-2.0
  9. #
  10. # Unless required by applicable law or agreed to in writing, software
  11. # distributed under the License is distributed on an "AS IS" BASIS,
  12. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. # See the License for the specific language governing permissions and
  14. # limitations under the License.
  15. #
  16. # This configuration file is intended for use in ZK-based mode, where Apache ZooKeeper is required.
  17. # See kafka.server.KafkaConfig for additional details and defaults
  18. #
  19. ############################# Server Basics #############################
  20. # The id of the broker. This must be set to a unique integer for each broker.
  21. broker.id=0
  22. ############################# Socket Server Settings #############################
  23. # The address the socket server listens on. If not configured, the host name will be equal to the value of
  24. # java.net.InetAddress.getCanonicalHostName(), with PLAINTEXT listener name, and port 9092.
  25. # FORMAT:
  26. # listeners = listener_name://host_name:port
  27. # EXAMPLE:
  28. # listeners = PLAINTEXT://your.host.name:9092
  29. #listeners=PLAINTEXT://:9092
  30. # 启用 SASL 机制
  31. sasl.enabled.mechanisms=SCRAM-SHA-256
  32. # 配置 SASL 认证方式
  33. sasl.mechanism.inter.broker.protocol=SCRAM-SHA-256
  34. security.inter.broker.protocol=SASL_PLAINTEXT
  35. # 启用用户认证的 Kafka 认证控制
  36. allow.everyone.if.no.acl.found=false
  37. # 配置 Kafka 用户的 JAAS 配置
  38. listener.name.sasl_plaintext.scram-sha-256.sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required \
  39. username="kafka" \
  40. password="kafkaAdmin#20240304";
  41. # 如果使用 SSL, 配置 SSL 文件路径(可选)
  42. # ssl.keystore.location=/path/to/keystore.jks
  43. # ssl.keystore.password=your_keystore_password
  44. # ssl.key.password=your_key_password
  45. # 设置Kafka 端口
  46. listeners=SASL_PLAINTEXT://127.0.0.1:9092
  47. advertised.listeners=SASL_PLAINTEXT://127.0.0.1:9092
  48. # Listener name, hostname and port the broker will advertise to clients.
  49. # If not set, it uses the value for "listeners".
  50. #advertised.listeners=PLAINTEXT://your.host.name:9092
  51. # Maps listener names to security protocols, the default is for them to be the same. See the config documentation for more details
  52. #listener.security.protocol.map=PLAINTEXT:PLAINTEXT,SSL:SSL,SASL_PLAINTEXT:SASL_PLAINTEXT,SASL_SSL:SASL_SSL
  53. # The number of threads that the server uses for receiving requests from the network and sending responses to the network
  54. num.network.threads=3
  55. # The number of threads that the server uses for processing requests, which may include disk I/O
  56. num.io.threads=8
  57. # The send buffer (SO_SNDBUF) used by the socket server
  58. socket.send.buffer.bytes=102400
  59. # The receive buffer (SO_RCVBUF) used by the socket server
  60. socket.receive.buffer.bytes=102400
  61. # The maximum size of a request that the socket server will accept (protection against OOM)
  62. socket.request.max.bytes=104857600
  63. ############################# Log Basics #############################
  64. # A comma separated list of directories under which to store log files
  65. # 设置Kafka日志
  66. log.dirs=D:/server/data/kafka-logs
  67. # The default number of log partitions per topic. More partitions allow greater
  68. # parallelism for consumption, but this will also result in more files across
  69. # the brokers.
  70. num.partitions=1
  71. # The number of threads per data directory to be used for log recovery at startup and flushing at shutdown.
  72. # This value is recommended to be increased for installations with data dirs located in RAID array.
  73. num.recovery.threads.per.data.dir=1
  74. ############################# Internal Topic Settings #############################
  75. # The replication factor for the group metadata internal topics "__consumer_offsets" and "__transaction_state"
  76. # For anything other than development testing, a value greater than 1 is recommended to ensure availability such as 3.
  77. offsets.topic.replication.factor=1
  78. transaction.state.log.replication.factor=1
  79. transaction.state.log.min.isr=1
  80. ############################# Log Flush Policy #############################
  81. # Messages are immediately written to the filesystem but by default we only fsync() to sync
  82. # the OS cache lazily. The following configurations control the flush of data to disk.
  83. # There are a few important trade-offs here:
  84. # 1. Durability: Unflushed data may be lost if you are not using replication.
  85. # 2. Latency: Very large flush intervals may lead to latency spikes when the flush does occur as there will be a lot of data to flush.
  86. # 3. Throughput: The flush is generally the most expensive operation, and a small flush interval may lead to excessive seeks.
  87. # The settings below allow one to configure the flush policy to flush data after a period of time or
  88. # every N messages (or both). This can be done globally and overridden on a per-topic basis.
  89. # The number of messages to accept before forcing a flush of data to disk
  90. #log.flush.interval.messages=10000
  91. # The maximum amount of time a message can sit in a log before we force a flush
  92. #log.flush.interval.ms=1000
  93. ############################# Log Retention Policy #############################
  94. # The following configurations control the disposal of log segments. The policy can
  95. # be set to delete segments after a period of time, or after a given size has accumulated.
  96. # A segment will be deleted whenever *either* of these criteria are met. Deletion always happens
  97. # from the end of the log.
  98. # The minimum age of a log file to be eligible for deletion due to age
  99. log.retention.hours=168
  100. # A size-based retention policy for logs. Segments are pruned from the log unless the remaining
  101. # segments drop below log.retention.bytes. Functions independently of log.retention.hours.
  102. #log.retention.bytes=1073741824
  103. # The maximum size of a log segment file. When this size is reached a new log segment will be created.
  104. #log.segment.bytes=1073741824
  105. # The interval at which log segments are checked to see if they can be deleted according
  106. # to the retention policies
  107. log.retention.check.interval.ms=300000
  108. ############################# Zookeeper #############################
  109. # Zookeeper connection string (see zookeeper docs for details).
  110. # This is a comma separated host:port pairs, each corresponding to a zk
  111. # server. e.g. "127.0.0.1:3000,127.0.0.1:3001,127.0.0.1:3002".
  112. # You can also append an optional chroot string to the urls to specify the
  113. # root directory for all kafka znodes.
  114. #设置ZK地址
  115. zookeeper.connect=localhost:2181
  116. # Timeout in ms for connecting to zookeeper
  117. zookeeper.connection.timeout.ms=18000
  118. ############################# Group Coordinator Settings #############################
  119. # The following configuration specifies the time, in milliseconds, that the GroupCoordinator will delay the initial consumer rebalance.
  120. # The rebalance will be further delayed by the value of group.initial.rebalance.delay.ms as new members join the group, up to a maximum of max.poll.interval.ms.
  121. # The default value for this is 3 seconds.
  122. # We override this to 0 here as it makes for a better out-of-the-box experience for development and testing.
  123. # However, in production environments the default value of 3 seconds is more suitable as this will help to avoid unnecessary, and potentially expensive, rebalances during application startup.
  124. group.initial.rebalance.delay.ms=0

配置 JAAS 文件 \kafka2.12.3.8.0\config\kafka_server_jaas.conf

  1. KafkaServer {
  2. org.apache.kafka.common.security.scram.ScramLoginModule required
  3. username="kafka"
  4. password="kafkaAdmin#20240304";
  5. };
  6. Client {
  7. org.apache.kafka.common.security.scram.ScramLoginModule required
  8. username="kafka"
  9. password="kafkaAdmin#20240304";
  10. };

设置环境变量 (optional)

set KAFKA_OPTS=-Djava.security.auth.login.config=D:/server/kafka2.12.3.8.0/config/kafka_server_jaas.conf

为 kafka 用户创建 SCRAM-SHA-256 凭据

\kafka2.12.3.8.0\bin\windows\kafka-configs --zookeeper localhost:2181 --alter --add-config SCRAM-SHA-256=[iterations=4096,password=kafkaAdmin#20240304],SCRAM-SHA-512=[password=kafkaAdmin#20240304] --entity-type users --entity-name kafka

配置 Kafka 客户端 \kafka2.12.3.8.0\config\client.properties

security.protocol=SASL_PLAINTEXT
sasl.mechanism=SCRAM-SHA-256

sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required \

username="kafka"
password="kafkaAdmin#20240304";

  1. 启动kafka kafka-server-start.bat ....\config\server.properties
6. 测试配置

新建主题

kafka-topics --create --topic test-topic --bootstrap-server localhost:9092 --partitions 1 --replication-factor 1 --command-config ../../config/client.properties

新建生产者 并输入数据

kafka-console-producer --topic test-topic --bootstrap-server localhost:9092 --producer.config ../../config/client.properties

新建消费者以显示生产者数据

kafka-console-consumer --topic test-topic --bootstrap-server localhost:9092 --from-beginning --consumer.config ../../config/client.properties

测试成功

7. 安装配置kafka UI 消息查看工具

下载git 代码打包生产 kafdrop-4.0.3-SNAPSHOT.jar (git 跳过 test), 路径D:\soft\kafka

配置UI客户端连接文件 kafka.properties

  1. security.protocol=SASL_PLAINTEXT
  2. sasl.mechanism=SCRAM-SHA-256
  3. sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required username="kafka" password="kafkaAdmin#20240304";

命令行启动UI

java --add-opens=java.base/sun.nio.ch=ALL-UNNAMED -jar kafdrop-4.0.3-SNAPSHOT.jar --kafka.brokerConnect=127.0.0.1:9092 --kafka.properties=kafka.properties

或者指定控制台端口

java --add-opens=java.base/sun.nio.ch=ALL-UNNAMED -jar kafdrop-4.0.3-SNAPSHOT.jar --kafka.brokerConnect=localhost:9092 --server.port=9999 --management.server.port=9999 --kafka.properties=kafka.properties

登录控制台查看 URL: http://localhost:9000/ 可查看先前 topic: test-topic

windows11 WSL 配置后只能WSL下使用,主机 SCRAM-SHA-256 配置访问不成功,故放弃.

看来WSL只能简单使用一些工具,多安全网络相关配置不适用

标签: kafka 分布式

本文转载自: https://blog.csdn.net/aa765aa/article/details/143283795
版权归原作者 aa765aa 所有, 如有侵权,请联系我们删除。

“windows 11 配置 kafka 使用SASL SCRAM-SHA-256 认证”的评论:

还没有评论