Apache Kafka AclList

Apache Kafka AclList

Certified

List Kafka ACLs matching a filter

Lists every ACL matching the given filter using the Kafka AdminClient. Unset filter fields match any value; an empty filter lists every ACL on the cluster.

yaml
type: io.kestra.plugin.kafka.AclList

List every ACL granted on a tenant's topic namespace

yaml
id: kafka_acl_list
namespace: company.team

tasks:
  - id: list_acls
    type: io.kestra.plugin.kafka.AclList
    properties:
      bootstrap.servers: localhost:9092
    resourceType: TOPIC
    resourceName: tenant_acme_
    patternType: PREFIXED
Properties

Kafka AdminClient properties

Must include bootstrap.servers; accepts any Kafka AdminClient config. Provide base64-encoded content for ssl.keystore.location and ssl.truststore.location when using SSL.

Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.

Definitions
assetFailureBehaviorstring
Possible Values
IGNOREFAILWARN

Asset failure behavior

Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.

enableAutobooleanstring

Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.

inputsarray

The assets consumed as inputs.

id*string
Min length1
typestring
outputs

The assets produced as outputs.

id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*string
Min length1

Custom asset type

descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
DefaultPT30S

AdminClient call timeout

Maximum duration to wait for each AdminClient operation to complete before failing the task. Defaults to PT30S (30 seconds). Distinct from the task-level timeout, which lets the worker kill the task without retrying it.

Host filter

Matches any host when unset.

Possible Values
ALLREADWRITECREATEDELETEALTERDESCRIBECLUSTER_ACTIONDESCRIBE_CONFIGSALTER_CONFIGSIDEMPOTENT_WRITE

Operation filter

Matches any operation when unset.

Possible Values
LITERALPREFIXEDMATCH

Resource pattern type filter

Matches any pattern type when unset.

Possible Values
ALLOWDENY

Permission type filter

Matches any permission type when unset.

Principal filter

For example User: alice. Matches any principal when unset.

Resource name filter

Matches any resource name when unset.

Possible Values
TOPICGROUPCLUSTERTRANSACTIONAL_IDDELEGATION_TOKENUSER

Resource type filter

Matches any resource type when unset.

SubTypeobject

Matching ACLs

Each entry contains resourceType, resourceName, patternType, principal, host, operation and permissionType.