skip to content

How do prefixed and wildcard (literal '*') ACLs differ, and how do you create each with kafka-acls?

level: middleimportance: should knowfreq 55%

answer

  1. LITERAL exact, LITERAL '*' = all
  2. PREFIXED = name starts-with (KIP-290)
  3. --resource-pattern-type prefixed (default literal)
  4. namespace via naming convention
  5. covers future topics under the prefix

basics

~20 s

A wildcard ACL uses the literal name '*' to match all resources of a type. A prefixed ACL matches every resource whose name starts with a given prefix. You select prefixed mode with --resource-pattern-type prefixed.

solid answer

~40 s

Kafka resource patterns have a **pattern type**: LITERAL or PREFIXED. A LITERAL pattern matches one exact name, except the special literal `*` which matches every resource of that type (the wildcard). A PREFIXED pattern matches every resource whose name begins with the given string — e.g. prefix `orders-` matches `orders-eu`, `orders-us`, etc. With `kafka-acls.sh` you pass `--resource-pattern-type` (alias `--pattern-type`): the default is `literal`, and `--topic '*'` makes a wildcard. For a prefix you write `--topic orders- --resource-pattern-type prefixed`. Prefixed ACLs (KIP-290) are the standard way to grant a team or service a whole namespace of topics/groups without enumerating each name, while keeping the grant narrower than `*`. Listing with `--list` shows the pattern type so you can audit literal vs prefixed vs wildcard grants.

go deeper

for a junior

Know that '*' means all resources and that prefixed matches names starting with a string.

for a middle

Produce the exact CLI for wildcard vs prefixed and know the default is literal.

for a senior

Tie prefixed ACLs to naming conventions and explain how matches pool with literal/wildcard before precedence.

for a principal

Design a topic/group namespace scheme so prefixed ACLs become the org's least-privilege authorization model.

## Pattern types Every ACL's resource is described by a **resource type** (Topic, Group, Cluster, TransactionalId), a **name**, and a **pattern type**. The pattern type determines how the name is matched: - **LITERAL** — exact-match on the name. As a special case, the literal name `*` is the **wildcard**: it matches *all* resources of that type. - **PREFIXED** — the name is treated as a prefix; it matches every resource whose name starts with it. Introduced by KIP-290. So `--topic '*'` (literal) means "every topic", while `--topic orders- --resource-pattern-type prefixed` means "every topic named `orders-…`". ## CLI syntax The flag is `--resource-pattern-type` (older alias `--pattern-type`), and it defaults to `literal`. Wildcard (all topics): ``` kafka-acls.sh --bootstrap-server b:9092 --add \ --allow-principal User:svc --operation Read --topic '*' ``` Prefixed (a namespace): ``` kafka-acls.sh --bootstrap-server b:9092 --add \ --allow-principal User:team-a --operation Read \ --topic team-a- --resource-pattern-type prefixed ``` ## Why prefixed matters operationally Without prefixed ACLs you'd either grant `*` (too broad, every team's data) or add one LITERAL ACL per topic (unscalable, racey when topics are created dynamically). A PREFIXED grant on `team-a-` automatically covers topics created later under that prefix — so a well-chosen topic-naming convention turns into a clean, future-proof authorization boundary. ## Matching interplay At evaluation time, a request for topic `team-a-clicks` matches: any LITERAL ACL on `team-a-clicks`, the wildcard LITERAL `*`, and any PREFIXED ACL whose prefix (`t`, `team-`, `team-a-`, …) is a prefix of the name. All matches are pooled, then DENY-wins precedence applies. ## Listing / auditing `--list` (optionally with `--resource-pattern-type any` or `match`) surfaces all three flavours so you can review whether a grant is literal, prefixed, or wildcard — important because a stray `*` is a frequent over-grant.

  • Why prefer a PREFIXED ACL over enumerating LITERAL ACLs per topic?
    A prefix grant covers topics created later under that prefix automatically and keeps the ACL set small — no per-topic churn, no race when topics are created on the fly.
  • What's the default pattern type if you omit --resource-pattern-type?
    literal. So --topic foo matches exactly 'foo'; you must add --resource-pattern-type prefixed for prefix matching.

saying these in an interview costs you the question

  • Thinking --topic 'orders*' does prefix matching — partial-glob isn't supported; only literal '*' (all) or PREFIXED mode.
  • Confusing the wildcard literal '*' (all topics) with a prefix.
  • Forgetting the default pattern type is literal, so a prefix flag is required for prefix grants.

context