Skip to content

Setup custom gssapi listener #7887

Answered by jusch23
jusch23 asked this question in Q&A
Jan 10, 2023 · 2 comments · 2 replies
Discussion options

You must be logged in to vote

I guess another problem is that the keytab needs to be renewed periodically as well?

On bare-metal the kerberos ticket is (as far as I know) renewed by the kafka service, there is no need to renew the ticket from outside. In the documentation (https://docs.confluent.io/platform/current/kafka/authentication_sasl/authentication_sasl_gssapi.html) there are also no additional configurations than the ones above mentioned.

Out of curiosity ... what is your motivation for using Kerberos? It is not exactly Kubernetes-friendly technology.

I'm working on a bare-metal kafka cluster with a kerberos listener and I was looking for alternatives based on kubernetes. I would like to check if a setup o…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@scholzj
Comment options

@jusch23
Comment options

Answer selected by jusch23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants