[{"data":1,"prerenderedAt":422},["ShallowReactive",2],{"docs-nav":3,"docs-page-\u002Fdocs\u002Fdata-clone\u002Fmasking":133},[4,27,53,68,83,98,117],{"slug":5,"label":6,"pages":7},"get-started","Get Started",[8,12,17,22],{"path":9,"title":10,"order":11},"\u002Fdocs","Welcome",0,{"path":13,"title":14,"navTitle":15,"order":16},"\u002Fdocs\u002Fget-started\u002Fquickstart","Quickstart",null,1,{"path":18,"title":19,"navTitle":20,"order":21},"\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster","Connecting to a Kafka Cluster","Clusters",2,{"path":23,"title":24,"navTitle":25,"order":26},"\u002Fdocs\u002Fget-started\u002Flicense","Licensing and Activation","License",3,{"slug":28,"label":29,"pages":30},"console","Console",[31,35,39,43,48],{"path":32,"title":33,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsole\u002Foverview","Produce and Consume Messages in the Kafka Console","Overview",{"path":36,"title":37,"navTitle":38,"order":21},"\u002Fdocs\u002Fconsole\u002Fconsuming-messages","Kafka Consumer: Reading Messages from a Topic","Consuming",{"path":40,"title":41,"navTitle":42,"order":26},"\u002Fdocs\u002Fconsole\u002Fdecoding-messages","Decoding Kafka Avro and Protobuf Messages","Decoding",{"path":44,"title":45,"navTitle":46,"order":47},"\u002Fdocs\u002Fconsole\u002Fproducing-messages","Kafka Producer: Sending Messages to a Topic","Producing",4,{"path":49,"title":50,"navTitle":51,"order":52},"\u002Fdocs\u002Fconsole\u002Freplay-forward-and-export","Replay and Export Kafka Messages","Replay & export",5,{"slug":54,"label":55,"pages":56},"topics","Topics",[57,60,64],{"path":58,"title":59,"navTitle":34,"order":16},"\u002Fdocs\u002Ftopics\u002Foverview","Browse and Inspect Kafka Topics",{"path":61,"title":62,"navTitle":63,"order":21},"\u002Fdocs\u002Ftopics\u002Fcreate-a-topic","Create a Kafka Topic: Partitions, Replication, and Retention","Create a topic",{"path":65,"title":66,"navTitle":67,"order":26},"\u002Fdocs\u002Ftopics\u002Fpartitions-and-records","Adding Kafka Partitions and Deleting Records","Partitions & records",{"slug":69,"label":70,"pages":71},"schema-registry","Schema Registry",[72,75,79],{"path":73,"title":74,"navTitle":34,"order":16},"\u002Fdocs\u002Fschema-registry\u002Foverview","Browse Kafka Schema Registry Subjects and Versions",{"path":76,"title":77,"navTitle":78,"order":21},"\u002Fdocs\u002Fschema-registry\u002Fnew-versions","Register Kafka Schemas and Publish New Versions","New versions",{"path":80,"title":81,"navTitle":82,"order":26},"\u002Fdocs\u002Fschema-registry\u002Fmock-and-lab","Avro Schema Validator and Mock Data Generator","Mock & Lab",{"slug":84,"label":85,"pages":86},"consumer-groups","Consumer Groups",[87,90,94],{"path":88,"title":89,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsumer-groups\u002Foverview","Browse Kafka Consumer Groups and Assignments",{"path":91,"title":92,"navTitle":93,"order":21},"\u002Fdocs\u002Fconsumer-groups\u002Flag","Monitor Kafka Consumer Lag","Lag",{"path":95,"title":96,"navTitle":97,"order":26},"\u002Fdocs\u002Fconsumer-groups\u002Freset-offsets","Reset Kafka Consumer Group Offsets","Reset offsets",{"slug":99,"label":100,"pages":101},"data-clone","Data Clone",[102,105,109,113],{"path":103,"title":104,"navTitle":34,"order":16},"\u002Fdocs\u002Fdata-clone\u002Foverview","Clone Kafka Topics Between Clusters",{"path":106,"title":107,"navTitle":108,"order":21},"\u002Fdocs\u002Fdata-clone\u002Fscope-and-range","Configure Kafka Topic Cloning","Scope & range",{"path":110,"title":111,"navTitle":112,"order":26},"\u002Fdocs\u002Fdata-clone\u002Fmasking","Mask Sensitive Data in Kafka Messages","Masking",{"path":114,"title":115,"navTitle":116,"order":47},"\u002Fdocs\u002Fdata-clone\u002Fpre-flight","Run Pre-flight Checks Before a Kafka Data Clone","Pre-flight",{"slug":118,"label":119,"pages":120},"operate","Operate",[121,125,129],{"path":122,"title":123,"navTitle":124,"order":16},"\u002Fdocs\u002Foperate\u002Fbrokers","Inspect Kafka Brokers and Cluster Configuration","Brokers",{"path":126,"title":127,"navTitle":128,"order":21},"\u002Fdocs\u002Foperate\u002Faccess-control","Inspect Kafka ACLs and Simulate Access","Access Control",{"path":130,"title":131,"navTitle":132,"order":26},"\u002Fdocs\u002Foperate\u002Factivity-logs","Review Kafka Changes in Kafma Activity Logs","Activity Logs",{"id":134,"title":111,"body":135,"description":413,"extension":414,"lastUpdated":415,"meta":416,"navTitle":112,"navigation":417,"order":26,"path":110,"seo":418,"sitemap":419,"stem":420,"__hash__":421},"docs\u002Fdocs\u002Fdata-clone\u002Fmasking.md",{"type":136,"value":137,"toc":404},"minimark",[138,142,145,150,162,173,188,191,200,204,272,275,287,291,294,301,308,312,327,331,338,360,367,375,379,385,388,392],[139,140,141],"p",{},"Masking changes selected fields before Kafma writes a cloned record to the\ntarget. Use it when production or shared test data contains values that should\nnot reach a local cluster unchanged.",[139,143,144],{},"Kafma warns when a production source has no masking rules. You still need to\nidentify every sensitive field that applies to your data.",[146,147,149],"h2",{"id":148},"add-a-masking-rule","Add a masking rule",[139,151,152,153,157,158,161],{},"Select ",[154,155,156],"strong",{},"Add"," in the ",[154,159,160],{},"Mask"," section and enter a rule in this form:",[163,164,170],"pre",{"className":165,"code":167,"language":168,"meta":169},[166],"language-text","topic:field.path\n","text","",[171,172,167],"code",{"__ignoreMap":169},[139,174,175,176,179,180,183,184,187],{},"For example, ",[171,177,178],{},"users:contact.email"," applies to the ",[171,181,182],{},"contact.email"," field in the\nmessage value on the ",[171,185,186],{},"users"," topic. One rule applies to one topic; add separate\nrules when the same field appears on multiple topics.",[139,189,190],{},"Rules apply to message values, not keys or headers.",[139,192,193],{},[194,195],"img",{"alt":196,"height":197,"src":198,"width":199},"Adding a masking rule for a Kafka message value",962,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Fdata-clone\u002Fmasking\u002Fmask-rule.png",1846,[146,201,203],{"id":202},"hash-redact-or-drop","Hash, Redact, or Drop",[205,206,207,223],"table",{},[208,209,210],"thead",{},[211,212,213,217,220],"tr",{},[214,215,216],"th",{},"Action",[214,218,219],{},"Result",[214,221,222],{},"Use it when",[224,225,226,240,256],"tbody",{},[211,227,228,234,237],{},[229,230,231],"td",{},[154,232,233],{},"Hash",[229,235,236],{},"Replaces a string with a 16-character pseudonym",[229,238,239],{},"You need to correlate records without keeping the original value",[211,241,242,247,253],{},[229,243,244],{},[154,245,246],{},"Redact",[229,248,249,250],{},"Replaces a string with ",[171,251,252],{},"***",[229,254,255],{},"The original value is unnecessary",[211,257,258,263,269],{},[229,259,260],{},[154,261,262],{},"Drop",[229,264,265,266],{},"Sets the selected field value to ",[171,267,268],{},"null",[229,270,271],{},"The schema permits a null value",[139,273,274],{},"Hash output is stable for the same input during one clone run. Kafma uses a new\nsalt for each run, so the pseudonym is not stable across separate clones. The\nresult is a one-way pseudonym, not encryption.",[139,276,277,278,280,281,283,284,286],{},"Despite its name, ",[154,279,262],{}," does not remove the field or the whole record. It\nsets the field to ",[171,282,268],{},". If the schema does not allow ",[171,285,268],{},", pre-flight warns\nthat the rule cannot be applied safely.",[146,288,290],{"id":289},"supported-formats-and-field-paths","Supported formats and field paths",[139,292,293],{},"Masking supports schema-backed Avro, JSON Schema, and Protobuf message values.\nKafma decodes the value, applies the rules, and re-encodes it for the target\nSchema Registry.",[139,295,296,297,300],{},"Field selectors use dot-separated object paths such as\n",[171,298,299],{},"customer.address.street",". Array indexes, wildcards, and recursive selectors\nare not supported.",[139,302,303,304,307],{},"Masking cannot be combined with ",[154,305,306],{},"Raw bytes"," because fields are not available\nuntil the payload is decoded.",[146,309,311],{"id":310},"round-trip-limits","Round-trip limits",[139,313,314,315,318,319,322,323,326],{},"Masking decodes and re-encodes the entire message value. During this round\ntrip, Avro ",[171,316,317],{},"int64"," values outside JavaScript's safe integer range may lose\nprecision, and Avro ",[171,320,321],{},"bytes"," or ",[171,324,325],{},"fixed"," fields may not round-trip exactly. Large\nJSON Schema numbers outside that range may also be rounded. Kafma reports the\nrelevant codec warning in the execution log.",[146,328,330],{"id":329},"validate-masking-rules-in-pre-flight","Validate masking rules in pre-flight",[139,332,333,337],{},[334,335,336],"a",{"href":114},"Run pre-flight"," after adding or changing rules.\nKafma samples the selected topics and checks that:",[339,340,341,345,348,351,357],"ul",{},[342,343,344],"li",{},"The topic is still selected.",[342,346,347],{},"The field path exists.",[342,349,350],{},"Hash and Redact target string fields.",[342,352,353,354,356],{},"Drop targets a field that can accept ",[171,355,268],{},".",[342,358,359],{},"The message format can be decoded and re-encoded.",[139,361,362,363,366],{},"Mask rows appear below their topics in the execution plan. ",[154,364,365],{},"Start Clone","\nremains disabled until every mask warning is resolved.",[139,368,369],{},[194,370],{"alt":371,"height":372,"src":373,"width":374},"Reviewing masking rules in the Data Clone pre-flight plan",1182,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Fdata-clone\u002Fmasking\u002Fmask-preflight.png",1860,[146,376,378],{"id":377},"what-happens-when-masking-fails","What happens when masking fails",[139,380,381,382,384],{},"Kafma does not fall back to sending the original value. If a field has the\nwrong type or the masked value cannot be re-encoded, Kafma drops that record\nand reports the failure in the execution log. If the field is absent or already\n",[171,383,268],{},", Kafma skips that mask rule and continues cloning the record.",[139,386,387],{},"This prevents a requested field from reaching the target unmasked, but it can\nproduce a partial result. Check the copied and failed message counts, then\nreview the execution log before using the cloned data.",[146,389,391],{"id":390},"next-steps","Next steps",[339,393,394,399],{},[342,395,396],{},[334,397,398],{"href":106},"Choose a focused message range",[342,400,401],{},[334,402,403],{"href":114},"Validate the clone in pre-flight",{"title":169,"searchDepth":26,"depth":26,"links":405},[406,407,408,409,410,411,412],{"id":148,"depth":21,"text":149},{"id":202,"depth":21,"text":203},{"id":289,"depth":21,"text":290},{"id":310,"depth":21,"text":311},{"id":329,"depth":21,"text":330},{"id":377,"depth":21,"text":378},{"id":390,"depth":21,"text":391},"Mask sensitive data in Kafka messages during a Kafma clone. Hash or redact string fields, or set selected fields to null, before records reach the target.","md","2026-08-01",{},true,{"title":111,"description":413},{"loc":110},"docs\u002Fdata-clone\u002Fmasking","tR-HIUsO2n6traMaK7qhnc5sZXqj1R4KPG5MipxHMQE",1785561255515]