conduktor.io ↗

KIP-772 — Encrypt KRaft Metadata Secrets at Rest

Discussion KRaftSecurity

Adds pluggable encryption for sensitive values (passwords, secrets) stored in the KRaft metadata log, with a configurable key-management provider so encryption keys can be held separately from the metadata log. In ZooKeeper mode KIP-226 encrypted secret configs, but KRaft has no equivalent protection, exposing secrets to anyone who can read the metadata log.

Details

AuthorColin McCabe
StatusDiscussion
WikiView on Apache Wiki
Created2021-09-01
Last Modified2021-10-14
Explore how this KIP affects the Kafka protocol in the Protocol Explorer, or see the full KIP database.