You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用kafka-mirror-maker.sh时遇SASL握手阶段METADATA请求认证失败

Kafka MirrorMaker 主题镜像同步认证失败解决方案

问题详情

执行Kafka主题镜像同步时出现认证失败错误:

INFO [SocketServer brokerId=___] 与 /server_ip 认证失败(SASL握手期间收到意外的METADATA类型Kafka请求)

使用的启动命令:

bin/kafka-mirror-maker.sh --consumer.config config/consumer.properties --producer.config config/producer.properties --whitelist "topicName"

相关配置文件:

producer.properties

bootstrap.servers=目标集群IP及Kafka端口
acks=-1
linger.ms=100
batch.size=16384
retries=3
security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN
sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="用户名" password="密码";
compression.type=none

consumer.properties

bootstrap.servers=源集群IP及Kafka端口
enable.auto.commit=true
auto.offset.reset=earliest
auto.commit.interval.ms=1000
security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN
sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="用户名" password="密码";
group.id=mirror-maker-group

使用的Kafka版本:kafka_2.13-2.7.2


解决方法

1. 排查SASL配置匹配性

这个错误核心原因是SASL握手流程中客户端提前发送了METADATA请求,大概率是客户端与服务端的SASL配置不兼容:

  • 确认源、目标Kafka集群的server.properties已正确配置SASL_PLAINTEXT监听,且设置了SASL_MECHANISMS=PLAIN,服务端JAAS文件配置的账号密码与客户端一致。
  • 在客户端配置文件(consumer.properties和producer.properties)中添加明确的登录类配置:
    sasl.login.class=org.apache.kafka.common.security.plain.PlainLoginModule
    

2. 切换为MirrorMaker 2.0(推荐)

你使用的Kafka 2.7.2已原生支持MirrorMaker 2.0,相比旧版MirrorMaker 1.x,它的配置更统一,认证逻辑更稳定,能有效避免这类握手问题:

  • 创建mm2.properties配置文件:
    clusters=source,target
    # 源集群配置
    source.bootstrap.servers=源集群IP及Kafka端口
    source.security.protocol=SASL_PLAINTEXT
    source.sasl.mechanism=PLAIN
    source.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="用户名" password="密码";
    # 目标集群配置
    target.bootstrap.servers=目标集群IP及Kafka端口
    target.security.protocol=SASL_PLAINTEXT
    target.sasl.mechanism=PLAIN
    target.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username="用户名" password="密码";
    # 要同步的主题
    mirror.topics=topicName
    # 基础同步配置
    offset-syncs.topic.replication.factor=1
    replication.factor=1
    
  • 启动MirrorMaker 2.0:
    bin/kafka-mirror-maker.sh --config mm2.properties
    

3. 检查网络与端口

确保运行MirrorMaker的机器能正常连通源、目标集群的Kafka端口,无防火墙、安全组拦截SASL握手请求。


内容的提问来源于stack exchange,提问作者QIAN KEQIAO

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 22:15:41