
Apache Kafka ScramCredentialCreate
CertifiedCreate or update a Kafka SCRAM user credential
Apache Kafka ScramCredentialCreate
Create or update a Kafka SCRAM user credential
Upserts a SASL/SCRAM credential for a user using the Kafka AdminClient, typically to provision a per-tenant service account.
type: io.kestra.plugin.kafka.ScramCredentialCreateExamples
Provision a SCRAM credential for a tenant service account
id: kafka_scram_credential_create
namespace: company.team
tasks:
- id: create_credential
type: io.kestra.plugin.kafka.ScramCredentialCreate
properties:
bootstrap.servers: localhost:9092
user: tenant-acme-svc
password: "{{ secret('TENANT_ACME_KAFKA_PASSWORD') }}"
mechanism: SCRAM_SHA_512
Properties
password *string
Password
properties *object
Kafka AdminClient properties
Must include bootstrap.servers; accepts any Kafka AdminClient config. Provide base64-encoded content for ssl.keystore.location and ssl.truststore.location when using SSL.
user *string
Username
assets
Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.
io.kestra.core.models.assets.AssetsDeclaration
IGNOREFAILWARNAsset failure behavior
Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.
Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.
The assets consumed as inputs.
io.kestra.core.models.assets.AssetIdentifier
1The assets produced as outputs.
io.kestra.plugin.ee.assets.Dataset
1150{}1150io.kestra.plugin.ee.assets.File
1150{}1150io.kestra.plugin.ee.assets.Table
1150{}1150io.kestra.plugin.ee.assets.VM
1150{}1150io.kestra.core.models.assets.External
1150{}1150io.kestra.core.models.assets.Custom
11501Custom asset type
{}1150callTimeout string
PT30SAdminClient call timeout
Maximum duration to wait for each AdminClient operation to complete before failing the task. Defaults to PT30S (30 seconds). Distinct from the task-level timeout, which lets the worker kill the task without retrying it.
iterations integerstring
4096Iteration count
Number of SCRAM hashing iterations, between 4096 and 16384. Defaults to 4096.
mechanism string
SCRAM_SHA_512SCRAM_SHA_256SCRAM_SHA_512SCRAM mechanism
Defaults to SCRAM_SHA_512.
Outputs
iterations integer
Iteration count
mechanism string
SCRAM_SHA_256SCRAM_SHA_512SCRAM mechanism
user string
Username