← Back to plugin index

Kafka SASL OAuth 2.0 Client Credential Grant Authentication

Description
SASL/OAUTHBEARER authentication for Kafka.

Note: The token endpoint URL must be explicitly allowed via Java Opts, in the instance.properties file (this is enforced by the library), e.g. iam.java.opts=-Dorg.apache.kafka.sasl.oauthbearer.allowed.urls=https://localhost:8443/auth-login/rest/oauth2/authorization-servers/local-iam-as/token

For more information, see Authentication using SASL.

Type name
KafkaSaslOAuthBearerAuthentication
Class
com.airlock.iam.servicecontainer.app.application.configuration.event.kafka.KafkaSaslOAuthBearerAuthenticationConfig
May be used by
Properties
Client ID (clientId)
Description
The client ID for SASL/OAUTHBEARER authentication.

Related Kafka producer property: sasl.oauthbearer.client.credentials.client.id

Attributes
String
Mandatory
Example
airlock-iam-kafka-oauth-client
Example
49e162ab-156b-40d9-a6ab-1934b7ceec3d
Client Secret (clientSecret)
Description
The client secret for SASL/OAUTHBEARER authentication.

Related Kafka producer property: sasl.oauthbearer.client.credentials.client.secret

Attributes
String
Mandatory
Sensitive
Scope (scope)
Description
The scope for SASL/OAUTHBEARER authentication.

Related Kafka producer property: sasl.oauthbearer.scope

Attributes
String
Optional
Example
my-application-scope
Token Endpoint URL (tokenEndpointUrl)
Description
The token endpoint URL for SASL/OAUTHBEARER authentication.

Note: The token endpoint URL must be explicitly allowed via Java Opts, in the instance.properties file (this is enforced by the library), e.g. iam.java.opts=-Dorg.apache.kafka.sasl.oauthbearer.allowed.urls=https://localhost:8443/auth-login/rest/oauth2/authorization-servers/local-iam-as/token

Related Kafka producer property: sasl.oauthbearer.token.endpoint.url

Attributes
String
Mandatory
Example
https://example.com/oauth2/v1/token
YAML Template (with default values)

type: KafkaSaslOAuthBearerAuthentication
id: KafkaSaslOAuthBearerAuthentication-xxxxxx
displayName: 
comment: 
properties:
  clientId:
  clientSecret:
  scope:
  tokenEndpointUrl: