What ACLs does a basic producer need to write to a topic, and what does a consumer in a consumer group need to read from it?
answer
- producer = Write on Topic
- consumer = Read Topic + Read Group
- Write/Read imply Describe
- forgot Group ACL → GroupAuthorizationException
- --producer / --consumer CLI shortcuts
- transactional = Write/Describe TransactionalId
basics
~10 sA producer needs Write on the topic. A consumer needs Read on the topic plus Read on its consumer group. Both implicitly get Describe from Write/Read.
solid answer
~40 sA plain producer needs `Write` on the target Topic; `Write` implicitly grants `Describe`, so it can fetch metadata without a separate Describe ACL. A consumer needs `Read` on the Topic and `Read` on the Group (its consumer-group id), because committing offsets and joining the group is authorized against the Group resource; `Read` on the topic also implies `Describe`. If the producer is transactional you additionally need `Write` and `Describe` on the `TransactionalId` resource and `IdempotentWrite` on the Cluster (pre-2.8) — modern brokers grant idempotent producer rights via topic `Write`. CLI example: `kafka-acls --add --allow-principal User:svc --producer --topic orders` sets up the producer side, and `--consumer --topic orders --group app1` sets up the consumer side in one shot using the convenience flags.
go deeper
Remember the two basics: producer = Write on topic, consumer = Read on topic + Read on group.
Explain implicit Describe and why the Group ACL is needed for offset commit / group membership.
Add the transactional path (TransactionalId Write/Describe) and version differences around IdempotentWrite/Cluster.
Design a least-privilege ACL template per service archetype (producer, consumer, EOS app) and automate its provisioning.
## The mental model Think in terms of the operation x resource-type matrix. The two everyday flows are produce and consume, and each touches specific resource types. ## Producer A basic (non-transactional, idempotent-by-default) producer needs: - **Write on Topic** — to append records. That's essentially it. Crucially, `Write` **implicitly grants `Describe`** on the same topic, so the producer can call the Metadata API to discover partitions and leaders without a separate `Describe` ACL. In old brokers idempotent producers also needed `IdempotentWrite` on the **Cluster**; since KIP-679 / newer brokers, topic `Write` is sufficient for idempotence. CLI shortcut: `kafka-acls.sh --bootstrap-server ... --add --allow-principal User:svc --producer --topic orders`. The `--producer` convenience flag expands to Write + Describe on the topic (and idempotent-write on the cluster on older versions). ## Consumer A consumer needs two grants: - **Read on Topic** — to fetch records (and `Read` implies `Describe`). - **Read on Group** — the `Group` resource is the consumer-group id. Joining the group, syncing, heartbeating, and committing offsets to `__consumer_offsets` are all authorized against `Read` on that Group. Forgetting the Group ACL is the single most common ACL mistake: the topic Read succeeds but the consumer can't join its group, surfacing as `GroupAuthorizationException`. CLI shortcut: `... --add --allow-principal User:svc --consumer --topic orders --group app1`, where `--consumer` expands to Read + Describe on the topic and Read on the group. ## Transactional producer (edge) Exactly-once / transactional producers add: - **Write + Describe on TransactionalId** — for the configured `transactional.id`. - On older brokers, **IdempotentWrite on Cluster**. ## Why implicit Describe matters Kafka deliberately bundles `Describe` under `Read`, `Write`, `Alter`, and `Delete` so you don't have to grant metadata visibility separately. But the reverse isn't true: `Describe` alone never grants Read or Write.
- A consumer can read records but throws GroupAuthorizationException on startup. What's missing?Read on the Group resource (the consumer-group id). Topic Read alone lets it fetch but not join/commit in the group.
- Does a producer need an explicit Describe ACL on the topic?No — Write implicitly grants Describe, so the producer can fetch metadata without a separate Describe ACL.
- What extra ACLs does a transactional producer require?Write and Describe on the TransactionalId resource for its transactional.id (plus IdempotentWrite on Cluster on older brokers).
saying these in an interview costs you the question
- Forgetting that a consumer needs Read on the Group, not just the Topic.
- Adding a separate Describe ACL for a producer — it's implied by Write.
- Claiming a consumer needs Write on the topic to commit offsets — offset commit is authorized via Read on the Group.
- Saying idempotent producers always need cluster-level IdempotentWrite — that's only older brokers.