
Apache Kafka AclCreate
CertifiedCreate a Kafka ACL
Apache Kafka AclCreate
Create a Kafka ACL
Grants (or denies) an operation on a resource to a principal using the Kafka AdminClient.
Use patternType: PREFIXED to authorize an entire per-tenant namespace (for example all topics starting with tenant_acme_) with a single ACL.
type: io.kestra.plugin.kafka.AclCreateExamples
Authorize a tenant service account to produce to its own topic namespace
id: kafka_acl_create
namespace: company.team
tasks:
- id: create_acl
type: io.kestra.plugin.kafka.AclCreate
properties:
bootstrap.servers: localhost:9092
resourceType: TOPIC
resourceName: tenant_acme_
patternType: PREFIXED
principal: "User:tenant-acme-svc"
host: "*"
operation: WRITE
permissionType: ALLOW
Properties
operation *string
ALLREADWRITECREATEDELETEALTERDESCRIBECLUSTER_ACTIONDESCRIBE_CONFIGSALTER_CONFIGSIDEMPOTENT_WRITEOperation
For example READ, WRITE, CREATE, DELETE, ALTER, DESCRIBE, ALL.
permissionType *string
ALLOWDENYPermission type
ALLOW or DENY.
principal *string
Principal
For example User: alice.
properties *object
Kafka AdminClient properties
Must include bootstrap.servers; accepts any Kafka AdminClient config. Provide base64-encoded content for ssl.keystore.location and ssl.truststore.location when using SSL.
resourceName *string
Resource name
Exact name for LITERAL, or the namespace prefix for PREFIXED.
resourceType *string
TOPICGROUPCLUSTERTRANSACTIONAL_IDDELEGATION_TOKENUSERResource type
For example TOPIC, GROUP, CLUSTER, TRANSACTIONAL_ID, DELEGATION_TOKEN, USER.
assets
Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.
io.kestra.core.models.assets.AssetsDeclaration
IGNOREFAILWARNAsset failure behavior
Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.
Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.
The assets consumed as inputs.
io.kestra.core.models.assets.AssetIdentifier
1The assets produced as outputs.
io.kestra.plugin.ee.assets.Dataset
1150{}1150io.kestra.plugin.ee.assets.File
1150{}1150io.kestra.plugin.ee.assets.Table
1150{}1150io.kestra.plugin.ee.assets.VM
1150{}1150io.kestra.core.models.assets.External
1150{}1150io.kestra.core.models.assets.Custom
11501Custom asset type
{}1150callTimeout string
PT30SAdminClient call timeout
Maximum duration to wait for each AdminClient operation to complete before failing the task. Defaults to PT30S (30 seconds). Distinct from the task-level timeout, which lets the worker kill the task without retrying it.
host string
*Host
Defaults to * (any host).
patternType string
LITERALLITERALPREFIXEDMATCHResource pattern type
LITERAL matches the resource name exactly (default). PREFIXED matches every resource whose name starts with resourceName — the standard way to authorize a whole per-tenant namespace with one ACL. MATCH matches wildcard and prefixed patterns as well as literal ones.
Outputs
host string
Host
operation string
ALLREADWRITECREATEDELETEALTERDESCRIBECLUSTER_ACTIONDESCRIBE_CONFIGSALTER_CONFIGSIDEMPOTENT_WRITEOperation
patternType string
LITERALPREFIXEDMATCHResource pattern type
permissionType string
ALLOWDENYPermission type
principal string
Principal
resourceName string
Resource name
resourceType string
TOPICGROUPCLUSTERTRANSACTIONAL_IDDELEGATION_TOKENUSERResource type