How do prefixed and wildcard (literal '*') ACLs differ, and how do you create each with kafka-acls?
answer
- LITERAL exact, LITERAL '*' = all
- PREFIXED = name starts-with (KIP-290)
- --resource-pattern-type prefixed (default literal)
- namespace via naming convention
- covers future topics under the prefix
basics
~20 sA wildcard ACL uses the literal name '*' to match all resources of a type. A prefixed ACL matches every resource whose name starts with a given prefix. You select prefixed mode with --resource-pattern-type prefixed.
solid answer
~40 sKafka resource patterns have a **pattern type**: LITERAL or PREFIXED. A LITERAL pattern matches one exact name, except the special literal `*` which matches every resource of that type (the wildcard). A PREFIXED pattern matches every resource whose name begins with the given string — e.g. prefix `orders-` matches `orders-eu`, `orders-us`, etc. With `kafka-acls.sh` you pass `--resource-pattern-type` (alias `--pattern-type`): the default is `literal`, and `--topic '*'` makes a wildcard. For a prefix you write `--topic orders- --resource-pattern-type prefixed`. Prefixed ACLs (KIP-290) are the standard way to grant a team or service a whole namespace of topics/groups without enumerating each name, while keeping the grant narrower than `*`. Listing with `--list` shows the pattern type so you can audit literal vs prefixed vs wildcard grants.
go deeper
Know that '*' means all resources and that prefixed matches names starting with a string.
Produce the exact CLI for wildcard vs prefixed and know the default is literal.
Tie prefixed ACLs to naming conventions and explain how matches pool with literal/wildcard before precedence.
Design a topic/group namespace scheme so prefixed ACLs become the org's least-privilege authorization model.
## Pattern types Every ACL's resource is described by a **resource type** (Topic, Group, Cluster, TransactionalId), a **name**, and a **pattern type**. The pattern type determines how the name is matched: - **LITERAL** — exact-match on the name. As a special case, the literal name `*` is the **wildcard**: it matches *all* resources of that type. - **PREFIXED** — the name is treated as a prefix; it matches every resource whose name starts with it. Introduced by KIP-290. So `--topic '*'` (literal) means "every topic", while `--topic orders- --resource-pattern-type prefixed` means "every topic named `orders-…`". ## CLI syntax The flag is `--resource-pattern-type` (older alias `--pattern-type`), and it defaults to `literal`. Wildcard (all topics): ``` kafka-acls.sh --bootstrap-server b:9092 --add \ --allow-principal User:svc --operation Read --topic '*' ``` Prefixed (a namespace): ``` kafka-acls.sh --bootstrap-server b:9092 --add \ --allow-principal User:team-a --operation Read \ --topic team-a- --resource-pattern-type prefixed ``` ## Why prefixed matters operationally Without prefixed ACLs you'd either grant `*` (too broad, every team's data) or add one LITERAL ACL per topic (unscalable, racey when topics are created dynamically). A PREFIXED grant on `team-a-` automatically covers topics created later under that prefix — so a well-chosen topic-naming convention turns into a clean, future-proof authorization boundary. ## Matching interplay At evaluation time, a request for topic `team-a-clicks` matches: any LITERAL ACL on `team-a-clicks`, the wildcard LITERAL `*`, and any PREFIXED ACL whose prefix (`t`, `team-`, `team-a-`, …) is a prefix of the name. All matches are pooled, then DENY-wins precedence applies. ## Listing / auditing `--list` (optionally with `--resource-pattern-type any` or `match`) surfaces all three flavours so you can review whether a grant is literal, prefixed, or wildcard — important because a stray `*` is a frequent over-grant.
- Why prefer a PREFIXED ACL over enumerating LITERAL ACLs per topic?A prefix grant covers topics created later under that prefix automatically and keeps the ACL set small — no per-topic churn, no race when topics are created on the fly.
- What's the default pattern type if you omit --resource-pattern-type?literal. So --topic foo matches exactly 'foo'; you must add --resource-pattern-type prefixed for prefix matching.
saying these in an interview costs you the question
- Thinking --topic 'orders*' does prefix matching — partial-glob isn't supported; only literal '*' (all) or PREFIXED mode.
- Confusing the wildcard literal '*' (all topics) with a prefix.
- Forgetting the default pattern type is literal, so a prefix flag is required for prefix grants.