kafka启用SASL/PLAIN+ACL后,kafka-consumer-group.sh查看消费组报错

kafka启用SASL/PLAIN+ACL后,kafka-consumer-group.sh查看消费组报错

问题

kafka启用用户认证和权限管理(SASL/PLAIN+ACL)之后,kafka-consumer-group.sh 查看消费组会报错

-bash-4.2$cd $KAFKA_HOME
-bash-4.2$bin/kafka-consumer-groups.sh --new-consumer --bootstrap-server  192.168.15.11:9092,192.168.15.12:9092,192.168.15.13:9092 --list

Note: This will only show information about consumers that use the Java consumer API (non-ZooKeeper-based consumers).

[2020-04-02 12:37:43,272] WARN Bootstrap broker 192.168.15.11:9092 disconnected (org.apache.kafka.clients.NetworkClient)
[2020-04-02 12:37:43,275] WARN Bootstrap broker 192.168.15.12:9092 disconnected (org.apache.kafka.clients.NetworkClient)
[2020-04-02 12:37:43,276] WARN Bootstrap broker 192.168.15.13:9092 disconnected (org.apache.kafka.clients.NetworkClient)
Error: Executing consumer group command failed due to Request METADATA failed on brokers List(192.168.15.12:9092 (id: -2 rack: null), 192.168.15.13:9092 (id: -3 rack: null), 192.168.15.11:9092 (id: -1 rack: null))

命令

kafka-consumer-group.sh 命令
新版本

cd $KAFKA_HOME
bin/kafka-consumer-groups.sh --new-consumer --bootstrap-server 192.168.15.11:9092,192.168.15.12:9092,192.168.15.13:9092 --list

旧版本

cd $KAFKA_HOME
bin/kafka-consumer-groups.sh --zookeeper 192.168.15.11:2181,192.168.15.12:2181,192.168.15.13:2181 --list

kafka启用用户认证和权限管理(SASL/PLAIN+ACL)之后,只能使用新版本,已经不支持ZK去连接kafka broker,下面以kafka 0.10.2.0版本测试,kafka新版本也适用。

改动

改动如下

cd $KAFKA/bin
cp kafka-consumer-group.sh kafka-consumer-group_jaas.sh
vi kafka-consumer-group_jaas.sh

#!/bin/bash

# 方式1:Add jaas file
export KAFKA_OPTS="-Djava.security.auth.login.config=/home/app/software/kafka/config/kafka_client_jaas.conf"
exec $(dirname $0)/kafka-run-class.sh kafka.admin.ConsumerGroupCommand "$@"

# 方式2:Add jaas file
exec $(dirname $0)/kafka-run-class.sh -Djava.security.auth.login.config=/home/app/software/kafka/config/kafka_client_jaas.conf kafka.admin.ConsumerGroupCommand "$@"

cd $KAFKA_HOME/config
vi kafka_client_jaas.conf

KafkaClient{
        org.apache.kafka.common.security.plain.PlainLoginModule required
        username="admin"
        password="admin123!@";
};

vi command_jaas.properties 

security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN

测试

-bash-4.2$cd $KAFKA_HOME
-bash-4.2$ bin/kafka-consumer-groups_jaas.sh --new-consumer --command-config config/command_jaas.properties  --bootstrap-server  192.168.15.11:9092,192.168.15.12:9092,192.168.15.13:9092 --list

Note: This will only show information about consumers that use the Java consumer API (non-ZooKeeper-based consumers).

test_01
test_02
test_03
test_04
test_05

测试过程中发现kafka_client_jaas.conf文件中配置ACL普通用户查询时不报错,但是没有数据。只能用ACL管理用户admin

  • 2
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 2
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值