Strimzi Kafka集群从0.36.1升级到0.40.0后明文监听器授权失败
Strimzi Kafka 0.36.1升级至0.40.0后明文监听器授权失败问题解决
问题现象
- 升级后9092端口
plain明文监听器无法连接Kafka,生产者、消费者均报错:Can't connect Not authorized to access topics: [Topic authorization failed] - Kafka Broker日志记录:
INFO Principal = User:ANONYMOUS is Denied Operation = Describe from host = xx.xx.xx.xx on resource = Topic:LITERAL:topic-name - 9094端口TLS监听器可正常处理生产者、消费者请求
当前集群监听器配置
listeners: - name: plain port: 9092 type: nodeport tls: false - name: tlsnp port: 9094 type: nodeport tls: true authentication: type: tls authorization: type: simple superUsers: - CN=xxx-user
问题根因
Strimzi从0.35版本起,强化了无认证监听器的安全限制:当集群全局启用simple授权模式时,未配置认证的明文监听器会将所有请求归为User:ANONYMOUS身份,而匿名用户默认没有任何Topic资源的访问权限——这是新版本默认的安全策略,旧版本可能未强制此限制。
解决方案
根据实际场景选择以下方案:
方案1:为明文监听器添加认证(生产环境推荐)
给plain监听器配置认证方式(如SCRAM-SHA-512),创建合法用户并分配对应Topic权限。示例配置:
listeners: - name: plain port: 9092 type: nodeport tls: false authentication: type: scram-sha-512 users: - name: app-user password: "secure-password-here" - name: tlsnp port: 9094 type: nodeport tls: true authentication: type: tls authorization: type: simple superUsers: - CN=xxx-user
接着为该用户配置Topic访问权限:
kubectl apply -f - <<EOF apiVersion: kafka.strimzi.io/v1beta2 kind: KafkaUser metadata: name: app-user labels: strimzi.io/cluster: your-cluster-name spec: authentication: type: scram-sha-512 authorization: type: simple acls: - resource: type: topic name: topic-name operation: All EOF
方案2:允许匿名用户访问指定资源(仅测试环境使用)
若必须保留无认证的明文监听器,可在授权配置中为User:ANONYMOUS添加ACLs,开放指定Topic的访问权限:
authorization: type: simple superUsers: - CN=xxx-user acls: - resource: type: topic name: topic-name operation: All principal: User:ANONYMOUS
⚠️ 风险提示:此配置会允许任意客户端通过明文端口访问目标Topic,存在严重安全隐患,禁止在生产环境使用。
方案3:调整安全默认行为(不推荐)
不建议采用该方案,因为会削弱集群安全防护。若临时需要,可查看Strimzi文档中allow.everyone.if.no.acl.found参数的配置(部分新版本可能已废弃该参数)。
内容的提问来源于stack exchange,提问作者Rashid
相关产品推荐
相关产品推荐

