Apache Kafka AclCreate

Apache Kafka AclCreate

Certified

Create a Kafka ACL

Grants (or denies) an operation on a resource to a principal using the Kafka AdminClient. Use patternType: PREFIXED to authorize an entire per-tenant namespace (for example all topics starting with tenant_acme_) with a single ACL.

yaml
type: io.kestra.plugin.kafka.AclCreate

Authorize a tenant service account to produce to its own topic namespace

yaml
id: kafka_acl_create
namespace: company.team

tasks:
  - id: create_acl
    type: io.kestra.plugin.kafka.AclCreate
    properties:
      bootstrap.servers: localhost:9092
    resourceType: TOPIC
    resourceName: tenant_acme_
    patternType: PREFIXED
    principal: "User:tenant-acme-svc"
    host: "*"
    operation: WRITE
    permissionType: ALLOW
Properties
Possible Values
ALLREADWRITECREATEDELETEALTERDESCRIBECLUSTER_ACTIONDESCRIBE_CONFIGSALTER_CONFIGSIDEMPOTENT_WRITE

Operation

For example READ, WRITE, CREATE, DELETE, ALTER, DESCRIBE, ALL.

Possible Values
ALLOWDENY

Permission type

ALLOW or DENY.

Principal

For example User: alice.

Kafka AdminClient properties

Must include bootstrap.servers; accepts any Kafka AdminClient config. Provide base64-encoded content for ssl.keystore.location and ssl.truststore.location when using SSL.

Resource name

Exact name for LITERAL, or the namespace prefix for PREFIXED.

Possible Values
TOPICGROUPCLUSTERTRANSACTIONAL_IDDELEGATION_TOKENUSER

Resource type

For example TOPIC, GROUP, CLUSTER, TRANSACTIONAL_ID, DELEGATION_TOKEN, USER.

Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.

Definitions
assetFailureBehaviorstring
Possible Values
IGNOREFAILWARN

Asset failure behavior

Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.

enableAutobooleanstring

Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.

inputsarray

The assets consumed as inputs.

id*string
Min length1
typestring
outputs

The assets produced as outputs.

id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*string
Min length1

Custom asset type

descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
DefaultPT30S

AdminClient call timeout

Maximum duration to wait for each AdminClient operation to complete before failing the task. Defaults to PT30S (30 seconds). Distinct from the task-level timeout, which lets the worker kill the task without retrying it.

Default*

Host

Defaults to * (any host).

DefaultLITERAL
Possible Values
LITERALPREFIXEDMATCH

Resource pattern type

LITERAL matches the resource name exactly (default). PREFIXED matches every resource whose name starts with resourceName — the standard way to authorize a whole per-tenant namespace with one ACL. MATCH matches wildcard and prefixed patterns as well as literal ones.

Host

Possible Values
ALLREADWRITECREATEDELETEALTERDESCRIBECLUSTER_ACTIONDESCRIBE_CONFIGSALTER_CONFIGSIDEMPOTENT_WRITE

Operation

Possible Values
LITERALPREFIXEDMATCH

Resource pattern type

Possible Values
ALLOWDENY

Permission type

Principal

Resource name

Possible Values
TOPICGROUPCLUSTERTRANSACTIONAL_IDDELEGATION_TOKENUSER

Resource type