Kafka 3.0.0创建主题遇认证错误:是否需用户名密码?
Kafka 3.0.0 创建主题认证失败问题解答
问题详情
我正在使用Kafka 3.0.0,执行以下命令创建主题:
kafka-topics.sh --command-config playground.config --bootstrap-server localhost:9092 --topic first_topic --create --partitions 5 --replication-factor 1
出现如下错误:
[2025-01-04 14:09:04,953] WARN [AdminClient clientId=adminclient-1] Connection to node -1 (localhost./127.0.1.1:9092) terminated during authentication. This may happen due to any of the following reasons: (1) Authentication failed due to invalid credentials with brokers older than 1.0.0, (2) Firewall blocking Kafka TLS traffic (eg it may only allow HTTPS traffic), (3) Transient network issue. (org.apache.kafka.clients.NetworkClient)
使用的playground.config配置内容:
security.protocol=SASL_SSL sasl.mechanism=PLAIN sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="username" password="password"
我在/etc/kafka/、/opt/kafka/config/、/usr/local/kafka/config/这些路径都找不到定义用户名密码的jaas.conf文件,疑问是:我是否需要提供用户名和密码?毕竟server.properties里没明确要求用SASL认证。
核心解答
结论:你完全不需要提供用户名密码
你的Kafka集群server.properties没有开启SASL认证,说明集群是无认证模式运行的,客户端根本不需要配置任何SASL相关参数。
问题原因
你当前用的playground.config强制指定了security.protocol=SASL_SSL,这会让客户端尝试用SASL认证方式连接无认证的Broker,直接导致认证失败报错。
解决方法
- 直接移除
--command-config playground.config参数,执行无认证的创建命令:
kafka-topics.sh --bootstrap-server localhost:9092 --topic first_topic --create --partitions 5 --replication-factor 1
- 只有当你后续需要给集群开启SASL认证时,才需要创建
jaas.conf文件并配置正确的用户名密码,现在完全没必要。
额外说明
jaas.conf不是Kafka默认自带的文件,需要手动创建,前提是集群确实开启了SASL认证,现在你的集群没开,找不到这个文件是正常情况。- 报错里提到的TLS流量问题可以排除,因为你的集群没启用SSL,客户端也不需要用
SASL_SSL协议。
内容的提问来源于stack exchange,提问作者rds80
相关产品推荐
相关产品推荐

