You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Strimzi Kafka用户资源未就绪且无对应Secret生成求助

KafkaUser资源无法就绪且未生成对应Secret问题排查

我正在尝试通过User Operator创建用于客户端连接Kafka的KafkaUser资源,同时配置授权规则。

Kafka集群配置文件

apiVersion: kafka.strimzi.io/v1beta2
kind: Kafka
metadata:
  name: my-cluster
spec:
  kafka:
    version: 3.2.1
    replicas: 1
    listeners:
      - name: plain
        port: 9092
        type: internal
        tls: false
      - name: tls
        port: 9093
        type: internal
        tls: true
        authentication:
          type: scram-sha-512
    authorization:
      type: simple
    resources:
      requests:
        memory: 1Gi
        cpu: 0.4
      limits:
        memory: 1Gi
        cpu: 0.5
    template:
      pod:
        tolerations:
          - key: "kubernetes.azure.com/scalesetpriority"
            operator: "Equal"
            value: "spot"
            effect: "NoSchedule"
    config:
      offsets.topic.replication.factor: 1
      transaction.state.log.replication.factor: 1
      transaction.state.log.min.isr: 1
      default.replication.factor: 1
      min.insync.replicas: 1
      inter.broker.protocol.version: "3.1"
    storage:
      type: ephemeral
    metricsConfig:
      type: jmxPrometheusExporter
      valueFrom:
        configMapKeyRef:
          name: kafka-metrics
          key: kafka-metrics-config.yml
  zookeeper:
    replicas: 1
    storage:
      type: ephemeral
    metricsConfig:
      type: jmxPrometheusExporter
      valueFrom:
        configMapKeyRef:
          name: kafka-metrics
          key: zookeeper-metrics-config.yml
  kafkaExporter:
    topicRegex: ".*"
    groupRegex: ".*"

KafkaUser资源配置文件

apiVersion: kafka.strimzi.io/v1beta2
kind: KafkaUser
metadata:
  name: kafka-user1
  labels:
    strimzi.io/cluster: my-cluster
spec:
  authentication:
    type: "scram-sha-512"
  authorization:
    type: "simple"
    acls:
      - resource:
          type: "topic"
          name: "sit-*"
          patternType: "prefix"
        operation: "Read"
      - resource:
          type: "topic"
          name: "sit-*"
          patternType: "prefix"
        operation: "Write"
      - resource:
          type: "topic"
          name: "sit-*"
          patternType: "prefix"
        operation: "Create"
      - resource:
          type: "topic"
          name: "sit-*"
          patternType: "prefix"
        operation: "Describe"

问题描述

  1. KafkaUser资源创建后无法进入READY状态:

$ kubectl get kafkauser.kafka.strimzi.io -n kafka

NAME CLUSTER AUTHENTICATION AUTHORIZATION READY

kafka-user1 my-cluster scram-sha-512 simple

  1. 未生成该用户对应的Secret:

$ kubectl get secret -n kafka
NAME TYPE DATA AGE
kafka-user-auth Opaque 2 54d
my-cluster-clients-ca Opaque 1 5m55s
my-cluster-clients-ca-cert Opaque 3 5m55s
my-cluster-cluster-ca Opaque 1 5m55s
my-cluster-cluster-ca-cert Opaque 3 5m55s
my-cluster-cluster-operator-certs Opaque 4 5m55s
my-cluster-kafka-brokers Opaque 4 5m32s
my-cluster-kafka-exporter-certs Opaque 4 4m59s
my-cluster-zookeeper-nodes Opaque 4 5m54s
sh.helm.release.v1.strimzi.v1 helm.sh/release.v1 1 61d

注:忽略kafka-user-auth Secret,它属于其他资源。

KafkaUser资源详情

Name:         kafka-user1
Namespace:    kafka
Labels:       strimzi.io/cluster=my-cluster
Annotations:  <none>
API Version:  kafka.strimzi.io/v1beta2
Kind:         KafkaUser
Metadata:
  Creation Timestamp:  2023-05-16T15:50:56Z
  Generation:          1
  Managed Fields:
    API Version:  kafka.strimzi.io/v1beta2
    Fields Type:  FieldsV1
    fieldsV1:
      f:metadata:
        f:annotations:
          .:
          f:kubectl.kubernetes.io/last-applied-configuration:
        f:labels:
          .:
          f:strimzi.io/cluster:
      f:spec:
        .:
        f:authentication:
          .:
          f:type:
        f:authorization:
          .:
          f:acls:
          f:type:
    Manager:         kubectl-client-side-apply
    Operation:       Update
    Time:            2023-05-16T15:50:56Z
  Resource Version:  26514057
  UID:               6131c71a-7fa9-4de5-9a5e-59970f346faa
Spec:
  Authentication:
    Type:  scram-sha-512
  Authorization:
    Acls:
      Operation:  Read
      Resource:
        Name:          sit-*
        Pattern Type:  prefix
        Type:          topic
      Operation:       Write
      Resource:
        Name:          sit-*
        Pattern Type:  prefix
        Type:          topic
      Operation:       Create
      Resource:
        Name:          sit-*
        Pattern Type:  prefix
        Type:          topic
      Operation:       Describe
      Resource:
        Name:          sit-*
        Pattern Type:  prefix
        Type:          topic
    Type:              simple
Events:                <none>

排查与解决步骤

  1. 检查Strimzi Cluster Operator状态

    • 执行命令查看Operator是否正常运行:kubectl get pods -n kafka | grep strimzi-cluster-operator
    • 如果Operator未运行或异常,重启Pod并查看日志:kubectl logs -n kafka <strimzi-operator-pod-name>,排查是否有权限问题、资源不足或连接Kafka/ZooKeeper失败。
  2. 验证KafkaUser标签正确性

    • 确认KafkaUser的strimzi.io/cluster标签值与Kafka集群的metadata.name完全一致(此处为my-cluster,已配置正确,但需确保无大小写或拼写错误)。
  3. 检查授权配置合法性

    • 对于Simple Authorization,确保AC规则格式正确:
      • 确认patternType取值为prefix时,资源名称格式符合要求,可尝试改为literal模式测试是否能正常创建用户。
      • 临时简化AC规则(比如只保留一条Read权限),重新应用配置看是否能就绪。
  4. 查看Kafka集群状态

    • 确认Kafka集群处于READY状态:kubectl get kafka -n kafka
    • 如果集群未就绪,先排查Kafka和ZooKeeper Pod的运行状态与日志,确保集群正常运行。
  5. 检查Operator日志

    • 查看Strimzi Operator的日志,过滤KafkaUser相关内容:kubectl logs -n kafka <strimzi-operator-pod-name> | grep kafka-user1,通常会输出用户创建失败的具体原因(比如ZooKeeper连接问题、权限不足、配置错误等)。
  6. 重新触发用户创建

    • 删除现有KafkaUser资源:kubectl delete kafkauser kafka-user1 -n kafka
    • 重新应用KafkaUser配置文件:kubectl apply -f <kafka-user-config.yml> -n kafka
    • 观察Operator日志和KafkaUser状态变化。

内容的提问来源于stack exchange,提问作者Faheem Sultan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 14:14:57