[{"data":1,"prerenderedAt":755},["ShallowReactive",2],{"docs-nav":3,"docs-page-\u002Fdocs\u002Fschema-registry\u002Faws-glue":152},[4,27,53,68,87,102,121,136],{"slug":5,"label":6,"pages":7},"get-started","Get Started",[8,12,17,22],{"path":9,"title":10,"order":11},"\u002Fdocs","Welcome",0,{"path":13,"title":14,"navTitle":15,"order":16},"\u002Fdocs\u002Fget-started\u002Fquickstart","Quickstart",null,1,{"path":18,"title":19,"navTitle":20,"order":21},"\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster","Connecting to a Kafka Cluster","Clusters",2,{"path":23,"title":24,"navTitle":25,"order":26},"\u002Fdocs\u002Fget-started\u002Flicense","Licensing and Activation","License",3,{"slug":28,"label":29,"pages":30},"console","Console",[31,35,39,43,48],{"path":32,"title":33,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsole\u002Foverview","Kafka Console Overview","Overview",{"path":36,"title":37,"navTitle":38,"order":21},"\u002Fdocs\u002Fconsole\u002Fconsuming-messages","Kafka Consumer: Reading Messages from a Topic","Consuming",{"path":40,"title":41,"navTitle":42,"order":26},"\u002Fdocs\u002Fconsole\u002Fdecoding-messages","Decoding Kafka Avro and Protobuf Messages","Decoding",{"path":44,"title":45,"navTitle":46,"order":47},"\u002Fdocs\u002Fconsole\u002Fproducing-messages","Kafka Producer: Sending Messages to a Topic","Producing",4,{"path":49,"title":50,"navTitle":51,"order":52},"\u002Fdocs\u002Fconsole\u002Freplay-forward-and-export","Replay, Forward, and Export Kafka Messages","Replay, forward & export",5,{"slug":54,"label":55,"pages":56},"topics","Topics",[57,60,64],{"path":58,"title":59,"navTitle":34,"order":16},"\u002Fdocs\u002Ftopics\u002Foverview","Browse and Inspect Kafka Topics",{"path":61,"title":62,"navTitle":63,"order":21},"\u002Fdocs\u002Ftopics\u002Fcreate-a-topic","Create a Kafka Topic: Partitions, Replication, and Retention","Create a topic",{"path":65,"title":66,"navTitle":67,"order":26},"\u002Fdocs\u002Ftopics\u002Fpartitions-and-records","Adding Kafka Partitions and Deleting Records","Partitions & records",{"slug":69,"label":70,"pages":71},"schema-registry","Schema Registry",[72,75,79,83],{"path":73,"title":74,"navTitle":34,"order":16},"\u002Fdocs\u002Fschema-registry\u002Foverview","Browse Kafka Schema Registry Subjects and Versions",{"path":76,"title":77,"navTitle":78,"order":21},"\u002Fdocs\u002Fschema-registry\u002Fnew-versions","Register Kafka Schemas and Publish New Versions","New versions",{"path":80,"title":81,"navTitle":82,"order":26},"\u002Fdocs\u002Fschema-registry\u002Fmock-and-lab","Avro Schema Validator and Mock Data Generator","Mock & Lab",{"path":84,"title":85,"navTitle":86,"order":47},"\u002Fdocs\u002Fschema-registry\u002Faws-glue","Use AWS Glue Schema Registry in Kafma","AWS Glue",{"slug":88,"label":89,"pages":90},"consumer-groups","Consumer Groups",[91,94,98],{"path":92,"title":93,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsumer-groups\u002Foverview","Browse Kafka Consumer Groups and Assignments",{"path":95,"title":96,"navTitle":97,"order":21},"\u002Fdocs\u002Fconsumer-groups\u002Flag","Monitor Kafka Consumer Lag","Lag",{"path":99,"title":100,"navTitle":101,"order":26},"\u002Fdocs\u002Fconsumer-groups\u002Freset-offsets","Reset Kafka Consumer Group Offsets","Reset offsets",{"slug":103,"label":104,"pages":105},"data-clone","Data Clone",[106,109,113,117],{"path":107,"title":108,"navTitle":34,"order":16},"\u002Fdocs\u002Fdata-clone\u002Foverview","Clone Kafka Topics Between Clusters",{"path":110,"title":111,"navTitle":112,"order":21},"\u002Fdocs\u002Fdata-clone\u002Fscope-and-range","Configure Kafka Topic Cloning","Scope & range",{"path":114,"title":115,"navTitle":116,"order":26},"\u002Fdocs\u002Fdata-clone\u002Fmasking","Mask Sensitive Data in Kafka Messages","Masking",{"path":118,"title":119,"navTitle":120,"order":47},"\u002Fdocs\u002Fdata-clone\u002Fpre-flight","Run Pre-flight Checks Before a Kafka Data Clone","Pre-flight",{"slug":122,"label":123,"pages":124},"kafka-connect","Kafka Connect",[125,128,132],{"path":126,"title":127,"navTitle":34,"order":16},"\u002Fdocs\u002Fkafka-connect\u002Foverview","Manage Kafka Connect in Kafma",{"path":129,"title":130,"navTitle":131,"order":21},"\u002Fdocs\u002Fkafka-connect\u002Fcreate-and-configure","Create and Configure Kafka Connectors","Create & configure",{"path":133,"title":134,"navTitle":135,"order":26},"\u002Fdocs\u002Fkafka-connect\u002Ftasks-and-offsets","Troubleshoot Kafka Connect Tasks and Inspect Offsets","Tasks & offsets",{"slug":137,"label":138,"pages":139},"operate","Operate",[140,144,148],{"path":141,"title":142,"navTitle":143,"order":16},"\u002Fdocs\u002Foperate\u002Fbrokers","Inspect Kafka Brokers and Cluster Configuration","Brokers",{"path":145,"title":146,"navTitle":147,"order":21},"\u002Fdocs\u002Foperate\u002Faccess-control","Inspect Kafka ACLs and Simulate Access","Access Control",{"path":149,"title":150,"navTitle":151,"order":26},"\u002Fdocs\u002Foperate\u002Factivity-logs","Review Kafka Changes in Kafma Activity Logs","Activity Logs",{"id":153,"title":85,"body":154,"datePublished":746,"description":747,"extension":748,"image":244,"lastUpdated":746,"meta":749,"navTitle":86,"navigation":750,"order":47,"path":84,"seo":751,"seoTitle":15,"sitemap":752,"stem":753,"__hash__":754},"docs\u002Fdocs\u002Fschema-registry\u002Faws-glue.md",{"type":155,"value":156,"toc":734},"minimark",[157,165,170,187,190,230,237,246,265,269,272,355,364,375,383,386,390,400,407,410,454,467,471,485,496,499,502,515,519,526,606,618,621,625,639,642,651,662,666,671,682,701,705,708,711,715],[158,159,160,161,164],"p",{},"Choose ",[162,163,86],"strong",{}," in a Kafka connection's Schema Registry settings to browse and manage Avro, JSON Schema, and Protobuf schemas. Kafma uses the official AWS Glue wire format to decode and produce records and can copy schemas and records between registries with Data Clone. Glue support is available on Free and Pro.",[166,167,169],"h2",{"id":168},"configure-aws-glue","Configure AWS Glue",[158,171,172,173,175,176,178,179,182,183,186],{},"Open the Kafka cluster's settings, expand ",[162,174,70],{},", and choose ",[162,177,86],{},". Enter the ",[162,180,181],{},"AWS Region"," and ",[162,184,185],{},"Registry Name"," of an existing Glue registry.",[158,188,189],{},"Glue credentials are configured separately from Kafka authentication. A Kafka cluster does not need to use MSK or AWS IAM authentication to use Glue.",[191,192,193,206],"table",{},[194,195,196],"thead",{},[197,198,199,203],"tr",{},[200,201,202],"th",{},"Credential source",[200,204,205],{},"What to enter",[207,208,209,220],"tbody",{},[197,210,211,217],{},[212,213,214],"td",{},[162,215,216],{},"Default credential chain",[212,218,219],{},"Leave Profile name blank to use the AWS SDK credential chain, or enter an AWS profile name",[197,221,222,227],{},[212,223,224],{},[162,225,226],{},"Manual",[212,228,229],{},"Access key ID and secret access key; add a session token for temporary credentials",[158,231,232,233,236],{},"Optionally enter an ",[162,234,235],{},"Assume role ARN",". Kafma uses the chosen credentials to assume that role, then uses the role's credentials for Glue requests.",[158,238,239],{},[240,241],"img",{"alt":242,"height":243,"src":244,"width":245},"AWS Glue Schema Registry settings with Region, registry name, AWS credential source, profile, optional assume role, and Test",1318,"https:\u002F\u002Fmedia.kafma.app\u002Fchangelog\u002Fv1.2.0\u002Faws-glue.png",1606,[158,247,248,249,252,253,264],{},"Select ",[162,250,251],{},"Test",", then save the connection. ",[162,254,255,256,182,260,263],{},"Test calls only ",[257,258,259],"code",{},"GetRegistry",[257,261,262],{},"ListSchemas","."," A successful test confirms those two requests; it does not confirm permission to retrieve schema versions for decoding, or to register, modify, or delete schemas.",[166,266,268],{"id":267},"required-iam-permissions","Required IAM permissions",[158,270,271],{},"The AWS identity used for Glue needs permission for the operations you use:",[191,273,274,284],{},[194,275,276],{},[197,277,278,281],{},[200,279,280],{},"Use",[200,282,283],{},"IAM actions",[207,285,286,300,323,344],{},[197,287,288,291],{},[212,289,290],{},"Connection test",[212,292,293,296,297],{},[257,294,295],{},"glue:GetRegistry",", ",[257,298,299],{},"glue:ListSchemas",[197,301,302,305],{},[212,303,304],{},"Browse and resolve schemas",[212,306,307,296,309,296,311,296,314,296,317,296,320],{},[257,308,295],{},[257,310,299],{},[257,312,313],{},"glue:GetSchema",[257,315,316],{},"glue:ListSchemaVersions",[257,318,319],{},"glue:GetSchemaVersion",[257,321,322],{},"glue:GetSchemaByDefinition",[197,324,325,328],{},[212,326,327],{},"Register and modify schemas",[212,329,330,331,296,334,296,337,296,340,343],{},"The read actions above, plus ",[257,332,333],{},"glue:CreateSchema",[257,335,336],{},"glue:RegisterSchemaVersion",[257,338,339],{},"glue:UpdateSchema",[257,341,342],{},"glue:DeleteSchema"," for the corresponding operations",[197,345,346,349],{},[212,347,348],{},"Assume a role",[212,350,351,354],{},[257,352,353],{},"sts:AssumeRole"," for the target role",[158,356,357,358,360,361,363],{},"Decoding a record requires ",[257,359,319],{},", even when ",[162,362,251],{}," succeeds. Writing a schema also involves reading its definition and checking the new version's status, so write actions alone are insufficient.",[158,365,366,367,374],{},"Scope the Glue permissions to the registry and schema resources you use. See the ",[368,369,373],"a",{"href":370,"rel":371},"https:\u002F\u002Fdocs.aws.amazon.com\u002Fservice-authorization\u002Flatest\u002Freference\u002Flist_glue.html",[372],"nofollow","AWS Glue IAM action and resource reference"," for the resource types supported by each action.",[158,376,377,378,263],{},"When using an assumed role, grant the Glue permissions to that role and configure its trust policy to allow your source identity to assume it. See ",[368,379,382],{"href":380,"rel":381},"https:\u002F\u002Fdocs.aws.amazon.com\u002FIAM\u002Flatest\u002FUserGuide\u002Fid_roles_update-role-trust-policy.html",[372],"AWS role trust policies",[158,384,385],{},"If you receive Access Denied after a successful test, check the action named in the error, the selected AWS account and Region, and the permissions of the identity or role actually making the request.",[166,387,389],{"id":388},"browse-schemas-and-versions","Browse schemas and versions",[158,391,392,393,395,396,399],{},"Open ",[162,394,70],{}," to list the schemas in the configured registry. Select a schema to inspect its definition, fields, versions, and compatibility, or use ",[162,397,398],{},"Diff"," to compare available versions.",[158,401,402,403,406],{},"Glue assigns each version a numeric version number and a ",[162,404,405],{},"schema version UUID",". The UUID identifies the version in encoded records; it is not a Standard registry's numeric schema ID.",[158,408,409],{},"When a schema has no available version, Kafma shows its state:",[191,411,412,422],{},[194,413,414],{},[197,415,416,419],{},[200,417,418],{},"State",[200,420,421],{},"Meaning",[207,423,424,434,444],{},[197,425,426,431],{},[212,427,428],{},[162,429,430],{},"No versions",[212,432,433],{},"No available schema version is present",[197,435,436,441],{},[212,437,438],{},[162,439,440],{},"Pending",[212,442,443],{},"Glue is still checking a submitted version",[197,445,446,451],{},[212,447,448],{},[162,449,450],{},"Failed",[212,452,453],{},"The submitted versions did not become available",[158,455,456,457,296,460,463,464,466],{},"These schemas cannot be used for ",[162,458,459],{},"Mock",[162,461,462],{},"Lab",", or message production until a version becomes available, and a ",[162,465,440],{}," schema can't take a new version until you refresh it. Refresh a Pending schema after Glue completes its check. For Failed, review the definition and compatibility before publishing again.",[166,468,470],{"id":469},"register-schemas-and-publish-versions","Register schemas and publish versions",[158,472,248,473,476,477,480,481,484],{},[162,474,475],{},"Register Schema",", choose Avro, JSON Schema, or Protobuf, then enter the ",[162,478,479],{},"Schema Name",", definition, and compatibility setting. Select ",[162,482,483],{},"Register"," to submit the first version.",[158,486,487,488,491,492,495],{},"For an existing schema, open its details and select ",[162,489,490],{},"New Version",". Edit the draft beside the selected version, review the diff, and select ",[162,493,494],{},"Publish",". A new version must keep the schema's existing format.",[158,497,498],{},"Glue can accept a submission before its compatibility check finishes. If Kafma reports that Glue is still checking, refresh the schema before retrying so you can see whether the version became available.",[158,500,501],{},"Glue does not support Standard Schema Registry references. Include the required definitions in the schema instead of referencing other registry subjects.",[158,503,504,505,507,508,510,511,514],{},"Once a version is available, use ",[162,506,459],{}," to generate a sample or ",[162,509,462],{}," to validate a JSON payload. See ",[368,512,513],{"href":80},"Mock and Lab"," for the shared workflow.",[166,516,518],{"id":517},"set-schema-compatibility","Set schema compatibility",[158,520,521,522,525],{},"Compatibility is configured separately for each Glue schema; there is no global compatibility setting or inherited default. Use the edit control on the schema's ",[162,523,524],{},"Compatibility"," card.",[191,527,528,538],{},[194,529,530],{},[197,531,532,535],{},[200,533,534],{},"Setting",[200,536,537],{},"Effect",[207,539,540,550,560,570,586,596],{},[197,541,542,547],{},[212,543,544],{},[257,545,546],{},"BACKWARD",[212,548,549],{},"New-schema consumers can read data written with the previous version",[197,551,552,557],{},[212,553,554],{},[257,555,556],{},"FORWARD",[212,558,559],{},"Previous-schema consumers can read data written with the new version",[197,561,562,567],{},[212,563,564],{},[257,565,566],{},"FULL",[212,568,569],{},"Both backward and forward compatibility",[197,571,572,583],{},[212,573,574,296,577,296,580],{},[257,575,576],{},"BACKWARD_ALL",[257,578,579],{},"FORWARD_ALL",[257,581,582],{},"FULL_ALL",[212,584,585],{},"Apply that direction across versions from the compatibility checkpoint",[197,587,588,593],{},[212,589,590],{},[257,591,592],{},"NONE",[212,594,595],{},"Skip version-to-version compatibility checks",[197,597,598,603],{},[212,599,600],{},[257,601,602],{},"DISABLED",[212,604,605],{},"Prevent additional versions after the first; change compatibility to publish again",[158,607,608,609,612,613,263],{},"The ",[162,610,611],{},"checkpoint"," is the version from which Glue applies compatibility checks to later versions. When you change compatibility in Kafma, it moves this checkpoint to the latest version. The change does not revalidate the entire version history. See ",[368,614,617],{"href":615,"rel":616},"https:\u002F\u002Fdocs.aws.amazon.com\u002Fglue\u002Flatest\u002Fwebapi\u002FAPI_UpdateSchema.html",[372],"AWS Glue UpdateSchema",[158,619,620],{},"Schema registration, publishing, compatibility changes, and deletion are unavailable on a Read-Only connection.",[166,622,624],{"id":623},"decode-and-produce-messages","Decode and produce messages",[158,626,627,628,182,631,634,635,638],{},"In the Console, keep the ",[162,629,630],{},"KEY",[162,632,633],{},"VALUE"," decoders on ",[162,636,637],{},"Automatic",". Kafma reads the Glue wire header, retrieves the version by UUID, and decodes the payload with its Avro, JSON Schema, or Protobuf definition, including zlib-compressed records. Kafma reads records from your existing Glue producers, and your Glue consumers can read records produced by Kafma.",[158,640,641],{},"Automatic schema decoding follows the registry type configured for the Kafka connection. Confluent-format records on a Glue connection, and Glue-format records on a Standard connection, remain raw bytes instead of being decoded through the other registry format.",[158,643,644,645,647,648,650],{},"When producing messages, Kafma automatically binds the ",[162,646,633],{}," to an available Glue schema with the same name as the topic, matching the official serializer's default schema name. You can choose a different schema or remove this binding. ",[162,649,630],{}," is not automatically bound to a Glue schema; select it manually when the key is schema-encoded.",[158,652,653,654,657,658,263],{},"Enter the payload as JSON, select the version and any Protobuf message type, then choose ",[162,655,656],{},"Produce",". Kafma validates and encodes it in the Glue wire format. See ",[368,659,661],{"href":660},"\u002Fdocs\u002Fconsole\u002Fproducing-messages#produce-avro-protobuf-and-json-schema-messages","Producing messages",[166,663,665],{"id":664},"clone-schemas-and-records","Clone schemas and records",[158,667,668,670],{},[368,669,104],{"href":107}," can copy schemas and selected messages between Glue registries, or between Glue and Standard Schema Registry. Schema-backed records are converted to the destination's schema identifiers and wire format; records without a schema are copied unchanged.",[158,672,673,674,677,678,681],{},"A Standard schema can't be registered in a Glue target if it uses references, or if its subject name isn't a valid Glue schema name (1–255 letters, numbers, dots, hyphens, underscores, ",[257,675,676],{},"$",", or ",[257,679,680],{},"#","). The copy stops for that topic during the run; pre-flight does not flag it.",[158,683,684,685,688,689,692,693,696,697,700],{},"Glue schemas named ",[257,686,687],{},"\u003Ctopic>-value"," or ",[257,690,691],{},"\u003Ctopic>-key"," map to one side of the record. A schema named exactly after the topic can serve either side, so Kafma decides from the records; see ",[368,694,695],{"href":110},"scope and range",". Optional ",[368,698,699],{"href":114},"field masking"," applies to supported schema-backed values before they reach the target.",[166,702,704],{"id":703},"delete-a-schema","Delete a schema",[158,706,707],{},"Kafma can delete an entire Glue schema, including its versions. It does not offer deletion of an individual Glue version, and there is no Standard-style soft-delete followed by permanent deletion.",[158,709,710],{},"Deleting the schema does not delete Kafka topics or their messages. However, once Glue removes the versions, it can no longer resolve the UUIDs referenced by those records. When Console cannot retrieve the referenced version, it shows a decode error and keeps the raw bytes available. Check the producers and consumers that still need the schema before confirming deletion.",[166,712,714],{"id":713},"next-steps","Next steps",[716,717,718,724,729],"ul",{},[719,720,721],"li",{},[368,722,723],{"href":80},"Generate mock data and validate payloads",[719,725,726],{},[368,727,728],{"href":40},"Decode messages in the Console",[719,730,731],{},[368,732,733],{"href":107},"Clone topics between clusters",{"title":735,"searchDepth":26,"depth":26,"links":736},"",[737,738,739,740,741,742,743,744,745],{"id":168,"depth":21,"text":169},{"id":267,"depth":21,"text":268},{"id":388,"depth":21,"text":389},{"id":469,"depth":21,"text":470},{"id":517,"depth":21,"text":518},{"id":623,"depth":21,"text":624},{"id":664,"depth":21,"text":665},{"id":703,"depth":21,"text":704},{"id":713,"depth":21,"text":714},"2026-10-01","Configure AWS Glue Schema Registry and IAM permissions in Kafma, manage schema versions, decode and produce messages, and clone schema-backed data.","md",{},true,{"title":85,"description":747},{"loc":84},"docs\u002Fschema-registry\u002Faws-glue","_r7bjwRdfuYZ0Y3zoskFGnBKBxYJHG0GfSz2AzJcEmQ",1790862044511]