无需自定义Docker镜像为Confluent Cloud的Kafka Rest Proxy添加Basic Auth认证
Absolutely! You don’t need to maintain a custom Docker image to enable Basic Authentication for your Kafka REST Proxy connected to Confluent Cloud. Instead, you can mount the required configuration files directly into the official confluentinc/cp-kafka-rest container using Docker volumes—this achieves the same result as your custom image but keeps you on the official, up-to-date container.
Here's how to do it step-by-step:
1. Prepare the Required Configuration Files
First, create the two files needed for Basic Auth on your local machine (in the same directory as your env.list):
rest-jaas.properties
This file defines the login module for Jetty to use your password file:
KafkaRest { org.eclipse.jetty.jaas.spi.PropertyFileLoginModule required file="/etc/kafka-rest/password.properties"; };
password.properties
This file maps usernames to passwords and assigned roles (match the role you set in KAFKA_REST_AUTHENTICATION_ROLES):
# Format: username: password, role1[, role2...] myadminuser: MySecurePassword123!, thisismyrole readonlyuser: ReadOnlyPass456!, thisismyrole
2. Verify Your env.list
Ensure your existing env.list already includes these Basic Auth-related variables (you already added most of these, double-check for completeness):
# Existing Confluent Cloud connection settings... KAFKA_REST_AUTHENTICATION_METHOD=BASIC KAFKA_REST_AUTHENTICATION_REALM=KafkaRest KAFKA_REST_AUTHENTICATION_ROLES=thisismyrole KAFKAREST_OPTS=-Djava.security.auth.login.config=/etc/kafka-rest/rest-jaas.properties
3. Run the Official Container with Volume Mounts
Use the docker run command with -v flags to mount your local config files into the container's /etc/kafka-rest/ directory. This replaces the need to copy files into a custom image:
docker run -p 8082:8082 \ --env-file env.list \ -v $(pwd)/rest-jaas.properties:/etc/kafka-rest/rest-jaas.properties \ -v $(pwd)/password.properties:/etc/kafka-rest/password.properties \ confluentinc/cp-kafka-rest:latest
Key Notes
- File Permissions: Ensure your local files are readable by the container's user (the official
cp-kafka-restimage runs as userappuserby default). If you hit permission issues, adjust local file permissions withchmod 644 rest-jaas.properties password.properties. - Portability: This approach works across environments—you can move the config files and
env.listto any machine running Docker, no image rebuild needed. - Upgrades: When Confluent releases a new version of the official image, you just pull the latest tag and re-run the command, no need to rebuild a custom image.
内容的提问来源于stack exchange,提问作者Shamshiel

