You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MirrorMaker 2连接Azure Event Hub认证阶段连接终止问题排查

解决MirrorMaker 2连接Azure Event Hub的认证超时问题

核心问题分析

从日志看,MirrorMaker 2在连接Azure Event Hub时反复出现认证期间连接断开,最终因超时无法获取集群元数据。结合配置和Azure Event Hub的Kafka兼容特性,问题集中在JAAS配置错误、不兼容的复制因子设置以及Worker组件的安全配置继承问题上。

解决步骤

1. 修正JAAS配置中的EntityPath

Azure Event Hub的全局命名空间连接字符串不应包含EntityPath=<topic>,该参数仅用于单个主题的生产者/消费者,而MirrorMaker 2需要连接整个命名空间管理主题镜像。修改destination.sasl.jaas.config:

destination.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="$ConnectionString" password="Endpoint=sb://<eventhub-dns-name>/;SharedAccessKeyName=<keyname>;SharedAccessKey=<primary-key>";

2. 移除所有复制因子配置

Azure Event Hub是托管服务,复制策略由Azure自动管理,不支持自定义复制因子。所有带replication.factor的配置会导致MirrorMaker 2尝试创建不被支持的内部主题,进而引发超时。删除以下配置项:

  • replication.factor=3
  • checkpoints.topic.replication.factor=3
  • heartbeats.topic.replication.factor=3
  • offset-syncs.topic.replication.factor=3
  • offset.storage.replication.factor=3
  • status.storage.replication.factor=3
  • config.storage.replication.factor=3

3. 显式配置Admin/Producer/Consumer的安全参数

日志显示MirrorMaker 2的Worker组件(AdminClient、Producer、Consumer)的安全配置未被正确使用,需显式指定这些组件的安全参数,确保继承目标集群的认证配置:

# AdminClient配置
admin.security.protocol=SASL_SSL
admin.sasl.mechanism=PLAIN
admin.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="$ConnectionString" password="你的命名空间连接字符串";

# Producer配置
producer.security.protocol=SASL_SSL
producer.sasl.mechanism=PLAIN
producer.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="$ConnectionString" password="你的命名空间连接字符串";

# Consumer配置
consumer.security.protocol=SASL_SSL
consumer.sasl.mechanism=PLAIN
consumer.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="$ConnectionString" password="你的命名空间连接字符串";

4. 强制使用TLSv1.2(可选)

部分环境下TLSv1.3与Azure Event Hub的Kafka端点存在兼容性问题,可强制使用TLSv1.2:

destination.ssl.protocol=TLSv1.2
destination.ssl.enabled.protocols=TLSv1.2

验证步骤

修改配置后,重新启动MirrorMaker 2:

bin/connect-mirror-maker.sh config/connct-mirror-maker.properties

观察日志,若不再出现认证断开和超时错误,且能成功获取Event Hub的元数据,则配置生效。

内容的提问来源于stack exchange,提问作者endnjsretia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 13:37:32