KIP-772 — Encrypt KRaft Metadata Secrets at Rest
Discussion KRaftSecurity
Adds pluggable encryption for sensitive values (passwords, secrets) stored in the KRaft metadata log, with a configurable key-management provider so encryption keys can be held separately from the metadata log. In ZooKeeper mode KIP-226 encrypted secret configs, but KRaft has no equivalent protection, exposing secrets to anyone who can read the metadata log.
Details
| Author | Colin McCabe |
| Status | Discussion |
| Wiki | View on Apache Wiki |
| Created | 2021-09-01 |
| Last Modified | 2021-10-14 |
Explore how this KIP affects the Kafka protocol in the Protocol Explorer, or see the full KIP database.