skip to content

What ACLs does a basic producer need to write to a topic, and what does a consumer in a consumer group need to read from it?

level: middleimportance: must knowfreq 75%

answer

  1. producer = Write on Topic
  2. consumer = Read Topic + Read Group
  3. Write/Read imply Describe
  4. forgot Group ACL → GroupAuthorizationException
  5. --producer / --consumer CLI shortcuts
  6. transactional = Write/Describe TransactionalId

basics

~10 s

A producer needs Write on the topic. A consumer needs Read on the topic plus Read on its consumer group. Both implicitly get Describe from Write/Read.

solid answer

~40 s

A plain producer needs `Write` on the target Topic; `Write` implicitly grants `Describe`, so it can fetch metadata without a separate Describe ACL. A consumer needs `Read` on the Topic and `Read` on the Group (its consumer-group id), because committing offsets and joining the group is authorized against the Group resource; `Read` on the topic also implies `Describe`. If the producer is transactional you additionally need `Write` and `Describe` on the `TransactionalId` resource and `IdempotentWrite` on the Cluster (pre-2.8) — modern brokers grant idempotent producer rights via topic `Write`. CLI example: `kafka-acls --add --allow-principal User:svc --producer --topic orders` sets up the producer side, and `--consumer --topic orders --group app1` sets up the consumer side in one shot using the convenience flags.

go deeper

for a junior

Remember the two basics: producer = Write on topic, consumer = Read on topic + Read on group.

for a middle

Explain implicit Describe and why the Group ACL is needed for offset commit / group membership.

for a senior

Add the transactional path (TransactionalId Write/Describe) and version differences around IdempotentWrite/Cluster.

for a principal

Design a least-privilege ACL template per service archetype (producer, consumer, EOS app) and automate its provisioning.

## The mental model Think in terms of the operation x resource-type matrix. The two everyday flows are produce and consume, and each touches specific resource types. ## Producer A basic (non-transactional, idempotent-by-default) producer needs: - **Write on Topic** — to append records. That's essentially it. Crucially, `Write` **implicitly grants `Describe`** on the same topic, so the producer can call the Metadata API to discover partitions and leaders without a separate `Describe` ACL. In old brokers idempotent producers also needed `IdempotentWrite` on the **Cluster**; since KIP-679 / newer brokers, topic `Write` is sufficient for idempotence. CLI shortcut: `kafka-acls.sh --bootstrap-server ... --add --allow-principal User:svc --producer --topic orders`. The `--producer` convenience flag expands to Write + Describe on the topic (and idempotent-write on the cluster on older versions). ## Consumer A consumer needs two grants: - **Read on Topic** — to fetch records (and `Read` implies `Describe`). - **Read on Group** — the `Group` resource is the consumer-group id. Joining the group, syncing, heartbeating, and committing offsets to `__consumer_offsets` are all authorized against `Read` on that Group. Forgetting the Group ACL is the single most common ACL mistake: the topic Read succeeds but the consumer can't join its group, surfacing as `GroupAuthorizationException`. CLI shortcut: `... --add --allow-principal User:svc --consumer --topic orders --group app1`, where `--consumer` expands to Read + Describe on the topic and Read on the group. ## Transactional producer (edge) Exactly-once / transactional producers add: - **Write + Describe on TransactionalId** — for the configured `transactional.id`. - On older brokers, **IdempotentWrite on Cluster**. ## Why implicit Describe matters Kafka deliberately bundles `Describe` under `Read`, `Write`, `Alter`, and `Delete` so you don't have to grant metadata visibility separately. But the reverse isn't true: `Describe` alone never grants Read or Write.

  • A consumer can read records but throws GroupAuthorizationException on startup. What's missing?
    Read on the Group resource (the consumer-group id). Topic Read alone lets it fetch but not join/commit in the group.
  • Does a producer need an explicit Describe ACL on the topic?
    No — Write implicitly grants Describe, so the producer can fetch metadata without a separate Describe ACL.
  • What extra ACLs does a transactional producer require?
    Write and Describe on the TransactionalId resource for its transactional.id (plus IdempotentWrite on Cluster on older brokers).

saying these in an interview costs you the question

  • Forgetting that a consumer needs Read on the Group, not just the Topic.
  • Adding a separate Describe ACL for a producer — it's implied by Write.
  • Claiming a consumer needs Write on the topic to commit offsets — offset commit is authorized via Read on the Group.
  • Saying idempotent producers always need cluster-level IdempotentWrite — that's only older brokers.

context