Aiven-Open / Aiven-Open/karapace

Support for client.dns.lookup=resolve_canonical_bootstrap_servers_only

未关闭
#695 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
634
派生
110
平均合并
4 天 7 小时
30 天内合并 PR
4

描述

# What is currently missing?

Better support when kafka is running in kubernetes.

When setting up kafka in kubernetes, one can setup the client's bootstrap_uri to point to a kafka headless service and take advantages of k8s's dns to get back a list of canonical kafka broker pod names (FQDNs) that can then be used by the client to establish a proper broker bootstrap connection.

In order for that to work when the kafka brokers are setup with SSL or SASL_SSL, kafka clients must set client.dns.lookup=resolve_canonical_bootstrap_servers_only. This is because proper ssl support requires clients to connect to the broker using an FQDN and the cert returned by the broker will need to have a subjectAltName field that can match the FQDN).

The suggestion is to add a setting that functions like client.dns.lookup. See https://cwiki.apache.org/confluence/display/KAFKA/KIP-602%3A+Change+default+value+for+client.dns.lookup

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。