如何通过Kafka CLI访问配置SASL PLAIN的Kafka?连接遇阻求助
Hey there, let's troubleshoot why your SASL PLAIN authenticated Kafka cluster isn't connecting with the CLI command you're using. The core issue here is that your current command doesn't provide any of the SASL credentials or configuration Kafka requires to authenticate your request. Here's how to fix this step by step:
1. Pass SASL Authentication Details to the CLI
The simplest fix is to either specify a client configuration file directly in your command, or embed the SASL parameters inline (though inline isn't recommended for production since passwords show up in command history).
Option A: Use a Client Configuration File
First, create a client.properties file with the following content (replace the username and password with your actual credentials):
security.protocol=SASL_PLAINTEXT sasl.mechanism=PLAIN sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \ username="your-kafka-username" \ password="your-kafka-password";
Then run your topic list command with the --command-config flag pointing to this file:
bin/kafka-topics.sh --list --bootstrap-server localhost:9093 \ --command-config /path/to/client.properties
Option B: Inline SASL Parameters (Quick Test Only)
If you just want to test quickly without creating a file, you can add the SASL parameters directly to the command:
bin/kafka-topics.sh --list --bootstrap-server localhost:9093 \ --security-protocol SASL_PLAINTEXT \ --sasl-mechanism PLAIN \ --sasl-jaas-config 'org.apache.kafka.common.security.plain.PlainLoginModule required username="your-kafka-username" password="your-kafka-password";'
2. Verify Broker SASL Configuration
If adding the client parameters still doesn't work, double-check your Kafka broker's server.properties to ensure SASL is properly enabled:
# Ensure the listener is set to SASL_PLAINTEXT listeners=SASL_PLAINTEXT://localhost:9093 advertised.listeners=SASL_PLAINTEXT://localhost:9093 # Enable SASL for inter-broker communication (if needed) security.inter.broker.protocol=SASL_PLAINTEXT sasl.mechanism.inter.broker.protocol=PLAIN sasl.enabled.mechanisms=PLAIN
Also, confirm your broker's JAAS configuration file (e.g., kafka_server_jaas.conf) is correctly set up with valid users and passwords, and that you're starting the broker with this file referenced:
# Set the JAAS config as an environment variable before starting the broker export KAFKA_OPTS="-Djava.security.auth.login.config=/path/to/kafka_server_jaas.conf" bin/kafka-server-start.sh config/server.properties
The JAAS file should look like this (replace with your own users and passwords):
KafkaServer { org.apache.kafka.common.security.plain.PlainLoginModule required username="admin" password="admin-secret" user_admin="admin-secret" user_your-username="your-kafka-password"; };
Note: The user_<username> lines define valid users and their passwords for client authentication.
3. Check Network and Port Access
Make sure the port 9093 on localhost is accessible. You can test this with telnet or nc:
telnet localhost 9093 # Or using netcat nc -zv localhost 9093
If the connection fails, check if the broker is running, if firewalls are blocking the port, or if the listener is configured for a different interface/port.
4. Confirm User Permissions
If your Kafka cluster uses ACLs, ensure your user has the Describe permission required to list topics. You can add this permission with the kafka-acls.sh tool:
bin/kafka-acls.sh --bootstrap-server localhost:9093 \ --command-config /path/to/client.properties \ --add --allow-principal User:your-kafka-username \ --operation Describe --topic '*'
Start with the first step (adding client auth parameters) since that's the most common culprit. If that doesn't work, work through the broker config and network checks next.
内容的提问来源于stack exchange,提问作者Upendra

