What is a Kafka ACL, and what are the fields that make up a single ACL binding?
answer
- 5-tuple: principal, operation, resource, permission, host
- User:alice
- LITERAL vs PREFIXED pattern type
- default = deny, DENY wins
- kafka-acls.sh / AdminClient
basics
~20 sAn ACL (access control list entry) is a rule saying a principal (user) is allowed or denied a specific operation (like Read or Write) on a resource (like a topic), optionally from a specific host.
solid answer
~40 sA Kafka ACL is a single authorization rule. It is a 5-tuple: principal (who, e.g. User:alice), operation (Read, Write, Describe, Create, Delete, Alter, etc.), resource pattern (resource type + name + pattern type — LITERAL or PREFIXED), permission type (ALLOW or DENY), and host (the client IP, or * for any). When a client attempts an action, the authorizer collects every ACL matching that principal/resource/operation and decides. ACLs are managed via the kafka-acls CLI or the AdminClient API and stored by the authorizer (the metadata log under KRaft, or ZooKeeper in legacy clusters). Each ACL is purely additive in the ALLOW case but a single matching DENY overrides any ALLOW.
go deeper
Know that an ACL grants or denies a principal an operation on a resource, and that the default is deny.
Be able to list all five fields including pattern type (LITERAL/PREFIXED) and the host field, and name the common resource types.
Explain implicit Describe, where ACLs are stored per authorizer, and how a decision aggregates matching rules.
Reason about ACL modeling at scale — naming conventions for principals/topics that keep the ACL set small and auditable.
## What problem ACLs solve Kafka authentication answers "who are you" (via SASL/SSL). Authorization answers "what are you allowed to do". ACLs (Access Control List entries) are the rules that drive authorization. ## The anatomy of one ACL A single ACL binding is conceptually a 5-tuple: 1. **Principal** — the identity, written as `User:alice` (the type is almost always `User`). This is the authenticated name produced by your SASL/SSL mechanism. 2. **Operation** — the action: `Read`, `Write`, `Create`, `Delete`, `Alter`, `Describe`, `ClusterAction`, `DescribeConfigs`, `AlterConfigs`, `IdempotentWrite`, etc. `All` is a wildcard operation. 3. **Resource pattern** — two parts: a **resource type** (`Topic`, `Group`, `Cluster`, `TransactionalId`, `DelegationToken`) plus a **resource name** and a **pattern type** (`LITERAL` for an exact name, `PREFIXED` for a name prefix). The literal name `*` means "all resources of this type". 4. **Permission type** — `ALLOW` or `DENY`. 5. **Host** — the client source IP the rule applies to, or `*` for any host. ## How a decision is made When a client makes a request, the broker's authorizer takes the (principal, operation, resource, host) of the attempt and scans all stored ACLs that match. The default decision is **deny** (nothing matches → denied). If at least one ALLOW matches and no DENY matches, the action is permitted. A matching DENY always wins. ## Where ACLs live and how they're managed You create ACLs with the `kafka-acls.sh` CLI (or programmatically via `AdminClient.createAcls`). The authorizer implementation persists them: `StandardAuthorizer` writes them into the KRaft metadata log; the legacy `AclAuthorizer` stored them in ZooKeeper. ## Edge note Many operations implicitly require `Describe` — for example a producer needs `Write` on a topic, but `Write` also grants implicit `Describe` so the producer can fetch metadata. This is why you often don't need to add `Describe` separately.
- If no ACL matches a request, what happens by default?The request is denied — Kafka authorization is deny-by-default. (A separate config, allow.everyone.if.no.acl.found, can flip that, but that's a defaults concern, not the ACL binding itself.)
- What does the host field do?It restricts an ACL to a specific client source IP. The default and most common value is * (any host). You can scope an ALLOW to a known producer IP for defense in depth.
saying these in an interview costs you the question
- Saying an ACL is just principal + operation and forgetting resource type, pattern type, permission type, or host.
- Claiming ACLs default to allow — they default to deny.
- Confusing authentication (who you are) with authorization (what you can do).