[{"data":1,"prerenderedAt":316},["ShallowReactive",2],{"docs-nav":3,"docs-page-\u002Fdocs\u002Foperate\u002Faccess-control":133},[4,27,53,68,83,98,117],{"slug":5,"label":6,"pages":7},"get-started","Get Started",[8,12,17,22],{"path":9,"title":10,"order":11},"\u002Fdocs","Welcome",0,{"path":13,"title":14,"navTitle":15,"order":16},"\u002Fdocs\u002Fget-started\u002Fquickstart","Quickstart",null,1,{"path":18,"title":19,"navTitle":20,"order":21},"\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster","Connecting to a Kafka Cluster","Clusters",2,{"path":23,"title":24,"navTitle":25,"order":26},"\u002Fdocs\u002Fget-started\u002Flicense","Licensing and Activation","License",3,{"slug":28,"label":29,"pages":30},"console","Console",[31,35,39,43,48],{"path":32,"title":33,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsole\u002Foverview","Produce and Consume Messages in the Kafka Console","Overview",{"path":36,"title":37,"navTitle":38,"order":21},"\u002Fdocs\u002Fconsole\u002Fconsuming-messages","Kafka Consumer: Reading Messages from a Topic","Consuming",{"path":40,"title":41,"navTitle":42,"order":26},"\u002Fdocs\u002Fconsole\u002Fdecoding-messages","Decoding Kafka Avro and Protobuf Messages","Decoding",{"path":44,"title":45,"navTitle":46,"order":47},"\u002Fdocs\u002Fconsole\u002Fproducing-messages","Kafka Producer: Sending Messages to a Topic","Producing",4,{"path":49,"title":50,"navTitle":51,"order":52},"\u002Fdocs\u002Fconsole\u002Freplay-forward-and-export","Replay and Export Kafka Messages","Replay & export",5,{"slug":54,"label":55,"pages":56},"topics","Topics",[57,60,64],{"path":58,"title":59,"navTitle":34,"order":16},"\u002Fdocs\u002Ftopics\u002Foverview","Browse and Inspect Kafka Topics",{"path":61,"title":62,"navTitle":63,"order":21},"\u002Fdocs\u002Ftopics\u002Fcreate-a-topic","Create a Kafka Topic: Partitions, Replication, and Retention","Create a topic",{"path":65,"title":66,"navTitle":67,"order":26},"\u002Fdocs\u002Ftopics\u002Fpartitions-and-records","Adding Kafka Partitions and Deleting Records","Partitions & records",{"slug":69,"label":70,"pages":71},"schema-registry","Schema Registry",[72,75,79],{"path":73,"title":74,"navTitle":34,"order":16},"\u002Fdocs\u002Fschema-registry\u002Foverview","Browse Kafka Schema Registry Subjects and Versions",{"path":76,"title":77,"navTitle":78,"order":21},"\u002Fdocs\u002Fschema-registry\u002Fnew-versions","Register Kafka Schemas and Publish New Versions","New versions",{"path":80,"title":81,"navTitle":82,"order":26},"\u002Fdocs\u002Fschema-registry\u002Fmock-and-lab","Avro Schema Validator and Mock Data Generator","Mock & Lab",{"slug":84,"label":85,"pages":86},"consumer-groups","Consumer Groups",[87,90,94],{"path":88,"title":89,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsumer-groups\u002Foverview","Browse Kafka Consumer Groups and Assignments",{"path":91,"title":92,"navTitle":93,"order":21},"\u002Fdocs\u002Fconsumer-groups\u002Flag","Monitor Kafka Consumer Lag","Lag",{"path":95,"title":96,"navTitle":97,"order":26},"\u002Fdocs\u002Fconsumer-groups\u002Freset-offsets","Reset Kafka Consumer Group Offsets","Reset offsets",{"slug":99,"label":100,"pages":101},"data-clone","Data Clone",[102,105,109,113],{"path":103,"title":104,"navTitle":34,"order":16},"\u002Fdocs\u002Fdata-clone\u002Foverview","Clone Kafka Topics Between Clusters",{"path":106,"title":107,"navTitle":108,"order":21},"\u002Fdocs\u002Fdata-clone\u002Fscope-and-range","Configure Kafka Topic Cloning","Scope & range",{"path":110,"title":111,"navTitle":112,"order":26},"\u002Fdocs\u002Fdata-clone\u002Fmasking","Mask Sensitive Data in Kafka Messages","Masking",{"path":114,"title":115,"navTitle":116,"order":47},"\u002Fdocs\u002Fdata-clone\u002Fpre-flight","Run Pre-flight Checks Before a Kafka Data Clone","Pre-flight",{"slug":118,"label":119,"pages":120},"operate","Operate",[121,125,129],{"path":122,"title":123,"navTitle":124,"order":16},"\u002Fdocs\u002Foperate\u002Fbrokers","Inspect Kafka Brokers and Cluster Configuration","Brokers",{"path":126,"title":127,"navTitle":128,"order":21},"\u002Fdocs\u002Foperate\u002Faccess-control","Inspect Kafka ACLs and Simulate Access","Access Control",{"path":130,"title":131,"navTitle":132,"order":26},"\u002Fdocs\u002Foperate\u002Factivity-logs","Review Kafka Changes in Kafma Activity Logs","Activity Logs",{"id":134,"title":127,"body":135,"description":307,"extension":308,"lastUpdated":309,"meta":310,"navTitle":128,"navigation":311,"order":21,"path":126,"seo":312,"sitemap":313,"stem":314,"__hash__":315},"docs\u002Fdocs\u002Foperate\u002Faccess-control.md",{"type":136,"value":137,"toc":299},"minimark",[138,142,147,159,170,174,177,187,196,200,207,210,241,249,263,267,274,277,281],[139,140,141],"p",{},"Access Control lists the Kafka ACLs visible to Kafma and helps explain which\nrules affect a request. The page is read-only; manage ACLs with your cluster\nadministration tools.",[143,144,146],"h2",{"id":145},"what-is-a-kafka-acl","What is a Kafka ACL?",[139,148,149,150,154,155,158],{},"A Kafka access control list rule connects a principal and host to an operation\non a resource. Its permission is either ",[151,152,153],"strong",{},"ALLOW"," or ",[151,156,157],{},"DENY",".",[139,160,161,162,166,167,169],{},"A literal pattern normally matches one resource name; the literal name ",[163,164,165],"code",{},"*","\nmatches every resource of that type. A prefixed pattern matches names that\nbegin with the configured prefix. When both permissions match, ",[151,168,157],{}," takes\nprecedence.",[143,171,173],{"id":172},"browse-kafka-acls","Browse Kafka ACLs",[139,175,176],{},"Each row shows the principal, resource, operation, permission, and host. Search\nby principal or resource name, or filter by resource type, operation, and\npermission.",[139,178,179,180,182,183,186],{},"A host of ",[163,181,165],{}," matches every client host, and ",[163,184,185],{},"User:*"," matches every user\nprincipal. An asterisk appended to a resource name marks a prefixed pattern.",[139,188,189],{},[190,191],"img",{"alt":192,"height":193,"src":194,"width":195},"Browsing and filtering Kafka ACLs in Kafma",868,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Foperate\u002Faccess-control\u002Facl-list.png",1558,[143,197,199],{"id":198},"simulate-access","Simulate access",[139,201,202,203,206],{},"Open ",[151,204,205],{},"ACL Simulator",", enter a principal, then choose the operation, resource\ntype, and resource name. Kafma evaluates the visible Kafka ACLs and highlights\nthe rules that grant, block, or are overridden for that request.",[139,208,209],{},"The result can be:",[211,212,213,226,235],"ul",{},[214,215,216,219,220,222,223,225],"li",{},[151,217,218],{},"Allowed"," — at least one matching ",[163,221,153],{}," rule applies and no matching\n",[163,224,157],{}," rule overrides it.",[214,227,228,231,232,234],{},[151,229,230],{},"Denied"," — an explicit matching ",[163,233,157],{}," rule applies.",[214,236,237,240],{},[151,238,239],{},"Indeterminate"," — no visible ACL decides the request, the result depends on\nthe client IP, or Kafma cannot safely interpret a rule.",[139,242,243],{},[190,244],{"alt":245,"height":246,"src":247,"width":248},"Simulating Kafka access and identifying the matching deny ACL",906,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Foperate\u002Faccess-control\u002Facl-simulator.png",1556,[139,250,251,252,255,256,259,260,262],{},"The simulator checks one resource at a time and does not know the client IP\nseen by the broker. It also cannot see ",[163,253,254],{},"super.users",",\n",[163,257,258],{},"allow.everyone.if.no.acl.found",", provider-managed authorization, or custom\nauthorizers. An ",[151,261,239],{}," result is not a denial.",[143,264,266],{"id":265},"troubleshoot-kafka-authorization-failures","Troubleshoot Kafka authorization failures",[139,268,269,270,273],{},"A Kafka operation can require access to more than one resource. For example, a\nconsumer normally needs ",[163,271,272],{},"READ"," on both its topic and consumer group. Simulate\neach resource separately to find which permission is missing.",[139,275,276],{},"Start with the client's principal, the failed operation, and the affected\nresource. Refresh the ACL list before running the simulation if an administrator\nhas just changed the rules.",[143,278,280],{"id":279},"next-steps","Next steps",[211,282,283,289,294],{},[214,284,285],{},[286,287,288],"a",{"href":130},"Review Kafka changes in Activity Logs",[214,290,291],{},[286,292,293],{"href":122},"Inspect Kafka brokers and cluster configuration",[214,295,296],{},[286,297,298],{"href":91},"Monitor Kafka consumer lag",{"title":300,"searchDepth":26,"depth":26,"links":301},"",[302,303,304,305,306],{"id":145,"depth":21,"text":146},{"id":172,"depth":21,"text":173},{"id":198,"depth":21,"text":199},{"id":265,"depth":21,"text":266},{"id":279,"depth":21,"text":280},"Inspect Kafka ACLs and simulate access in Kafma. Filter rules by resource, operation, or permission, and see which visible ACLs allow or deny a request.","md","2026-08-01",{},true,{"title":127,"description":307},{"loc":126},"docs\u002Foperate\u002Faccess-control","4kb7_MdQmn15EGCDJJmxzeczBwgcG2jbjFiC_IozoHI",1785561255827]