SASL_PLAINTEXT认证 本人认为就是consumer连接broker开启了用户名,密码认证
acl权限控制 就是指针对用户 配置拥有哪些操作权限,如 topic的读,写,group的读,topic的创建,删除,等等都是可控制的权限


# see kafka.server.KafkaConfig for additional details and defaults############################# Server Basics ############################## The id of the broker. This must be set to a unique integer for each broker. Socket Server Settings ############################## The address the socket server listens on. It will get the value returned from
# if not configured.
#     listeners = listener_name://host_name:port
#     listeners = PLAINTEXT:// Hostname and port the broker will advertise to producers and consumers. If not set,
# it uses the value for "listeners" if configured.  Otherwise, it will use the value
#。此时client端配置连接的"bootstrap.servers"=就行# Maps listener names to security protocols, the default is for them to be the same. See the config documentation for more details,SSL:SSL,SASL_PLAINTEXT:SASL_PLAINTEXT,SASL_SSL:SASL_SSL# The number of threads that the server uses for receiving requests from the network and sending responses to the network The number of threads that the server uses for processing requests, which may include disk I/O The send buffer (SO_SNDBUF) used by the socket server
socket.send.buffer.bytes=102400# The receive buffer (SO_RCVBUF) used by the socket server
socket.receive.buffer.bytes=102400# The maximum size of a request that the socket server will accept (protection against OOM)
socket.request.max.bytes=104857600############################# Log Basics ############################## A comma separated list of directories under which to store log files
log.dirs=/home/whtemp/kafka/kafka-logs# The default number of log partitions per topic. More partitions allow greater
# parallelism for consumption, but this will also result in more files across
# the brokers.
num.partitions=1# The number of threads per data directory to be used for log recovery at startup and flushing at shutdown.
# This value is recommended to be increased for installations with data dirs located in RAID array. Internal Topic Settings  #############################
# The replication factor for the group metadata internal topics "__consumer_offsets" and "__transaction_state"
# For anything other than development testing, a value greater than 1 is recommended to ensure availability such as 3.
transaction.state.log.min.isr=1############################# Log Flush Policy ############################## Messages are immediately written to the filesystem but by default we only fsync() to sync
# the OS cache lazily. The following configurations control the flush of data to disk.
# There are a few important trade-offs here:
#    1. Durability: Unflushed data may be lost if you are not using replication.
#    2. Latency: Very large flush intervals may lead to latency spikes when the flush does occur as there will be a lot of data to flush.
#    3. Throughput: The flush is generally the most expensive operation, and a small flush interval may lead to excessive seeks.
# The settings below allow one to configure the flush policy to flush data after a period of time or
# every N messages (or both). This can be done globally and overridden on a per-topic basis.# The number of messages to accept before forcing a flush of data to disk
#log.flush.interval.messages=10000# The maximum amount of time a message can sit in a log before we force a flush Log Retention Policy ############################## The following configurations control the disposal of log segments. The policy can
# be set to delete segments after a period of time, or after a given size has accumulated.
# A segment will be deleted whenever *either* of these criteria are met. Deletion always happens
# from the end of the log.# The minimum age of a log file to be eligible for deletion due to age
log.retention.hours=168# A size-based retention policy for logs. Segments are pruned from the log unless the remaining
# segments drop below log.retention.bytes. Functions independently of log.retention.hours.
#log.retention.bytes=1073741824# The maximum size of a log segment file. When this size is reached a new log segment will be created.
log.segment.bytes=1073741824# The interval at which log segments are checked to see if they can be deleted according
# to the retention policies Zookeeper ############################## Zookeeper connection string (see zookeeper docs for details).
# This is a comma separated host:port pairs, each corresponding to a zk
# server. e.g. ",,".
# You can also append an optional chroot string to the urls to specify the
# root directory for all kafka znodes.
zookeeper.connect=101.913.89.166:2128# Timeout in ms for connecting to zookeeper Group Coordinator Settings ############################## The following configuration specifies the time, in milliseconds, that the GroupCoordinator will delay the initial consumer rebalance.
# The rebalance will be further delayed by the value of as new members join the group, up to a maximum of
# The default value for this is 3 seconds.
# We override this to 0 here as it makes for a better out-of-the-box experience for development and testing.
# However, in production environments the default value of 3 seconds is more suitable as this will help to avoid unnecessary, and potentially expensive, rebalances during application startup.的时候表示任何客户端的操作,如果发现你未配置acl权限,就不能



kafka_server_jaas.conf 的配置

KafkaServer { required
username="admin" #内部通信用
password="kafka" #内部通信用
user_zsh="niubi"#用户zsh 密码niubi
user_admin="kafka";#用户admin 密码kafka


KafkaClient { required


KafkaClient { required


//当然你也可以换成超级管理员的密码props.put(CommonClientConfigs.SECURITY_PROTOCOL_CONFIG,"SASL_PLAINTEXT");props.put(SaslConfigs.SASL_MECHANISM, "PLAIN");props.put("sasl.jaas.config"," required username='dataflow' password='dataflow';");
package zktest.zktest;
import java.util.Arrays;
import java.util.HashMap;
import java.util.List;
import java.util.Map;import org.apache.kafka.clients.admin.AdminClient;
import org.apache.kafka.clients.admin.AdminClientConfig;
import org.apache.kafka.clients.admin.DescribeAclsResult;
import org.apache.kafka.clients.admin.KafkaAdminClient;
import org.apache.kafka.common.acl.AccessControlEntry;
import org.apache.kafka.common.acl.AclBinding;
import org.apache.kafka.common.acl.AclBindingFilter;
import org.apache.kafka.common.acl.AclOperation;
import org.apache.kafka.common.acl.AclPermissionType;
import org.apache.kafka.common.resource.PatternType;
import org.apache.kafka.common.resource.ResourcePattern;
import org.apache.kafka.common.resource.ResourceType;
//import org.springframework.kafka.core.KafkaAdmin;public class AclTest {public static void main(String[] args) {Map<String, Object> configs = new HashMap<>();// broker地址,多个用逗号分割,这里用了ngix的地址,如果不需要ngix,请直接改为kafka的ip地址configs.put(AdminClientConfig.BOOTSTRAP_SERVERS_CONFIG, "");configs.put("security.protocol", "SASL_PLAINTEXT");configs.put("sasl.mechanism", "PLAIN");// 登录broker的账户 admin是管理员configs.put("sasl.jaas.config"," required username=\"admin\" password=\"kafka\";");AdminClient adminClient = KafkaAdminClient.create(configs);// principal:User:test2是需要赋予权限的帐号// host:主机 (*号即可)// operation:权限操作// permissionType:权限类型AccessControlEntry ace = new AccessControlEntry("User:dataflow", "*", AclOperation.READ, AclPermissionType.ALLOW);// resourceType:资源类型(topic)// name:topic名称// patternType:资源模式类型//下面的写法表示当client用sals认证的时候使用dataflow这个用户连接的时候,当使用groupid=wwaaaddfw,对topic-name17仅仅有读权限ResourcePattern rp = new ResourcePattern(ResourceType.TOPIC, "topic-name17", PatternType.LITERAL);ResourcePattern rp1 = new ResourcePattern(ResourceType.GROUP, "wwaaaddfw", PatternType.LITERAL);AclBinding ab = new AclBinding(rp, ace);AclBinding ab1 = new AclBinding(rp1, ace);// 多个权限赋予可以传listList<AclBinding> ablist = Arrays.asList(ab,ab1);adminClient.createAcls(ablist);// 可以查看赋予用户的所有权限DescribeAclsResult b = adminClient.describeAcls(AclBindingFilter.ANY);System.out.println(b.values());adminClient.close();}}

client consumer的例子

package zktest.zktest;
import java.time.Duration;
import java.util.Arrays;
import java.util.Properties;import org.apache.kafka.clients.CommonClientConfigs;
import org.apache.kafka.clients.consumer.Consumer;
import org.apache.kafka.clients.consumer.ConsumerConfig;
import org.apache.kafka.clients.consumer.ConsumerRecord;
import org.apache.kafka.clients.consumer.ConsumerRecords;
import org.apache.kafka.clients.consumer.KafkaConsumer;
import org.apache.kafka.common.config.SaslConfigs;
import org.apache.kafka.common.serialization.StringDeserializer;public class HelloWorldConsumer {public static void main(String[] args) throws InterruptedException {Properties props = new Properties();//这里我使用的是ngix,如果不需要ngix,请直接改为kafka的ip地址props.put(ConsumerConfig.BOOTSTRAP_SERVERS_CONFIG, "");props.put(ConsumerConfig.GROUP_ID_CONFIG ,"wwaaaddfw") ;props.put("auto.offset.reset", "earliest");props.put(ConsumerConfig.ENABLE_AUTO_COMMIT_CONFIG, "true");props.put(ConsumerConfig.AUTO_COMMIT_INTERVAL_MS_CONFIG, "1000");props.put(ConsumerConfig.KEY_DESERIALIZER_CLASS_CONFIG, StringDeserializer.class);props.put(ConsumerConfig.VALUE_DESERIALIZER_CLASS_CONFIG, StringDeserializer.class);//props.put("", "false");props.put(CommonClientConfigs.SECURITY_PROTOCOL_CONFIG,"SASL_PLAINTEXT");props.put(SaslConfigs.SASL_MECHANISM, "PLAIN");props.put(ConsumerConfig.MAX_POLL_RECORDS_CONFIG, "1");props.put("sasl.jaas.config"," required username='dataflow' password='dataflow';");Consumer<String, String> consumer = new KafkaConsumer<>(props);consumer.subscribe(Arrays.asList("topic-name17"));while (true) {ConsumerRecords<String, String> records = consumer.poll(10);
Thread.sleep(1000);for (ConsumerRecord<String, String> record : records) {System.out.println("分区:"+record.partition() +"分区offset&&"+record.offset()+"&&分区key:"+record.key());}}}}



