Skip to Content
FeaturesACL Management

ACL Management

Pilot provides a UI and API for viewing and managing Kafka Access Control Lists (ACLs).

Overview

Kafka ACLs control which principals (users, services) can perform specific operations on cluster resources. Pilot makes it easy to view, create, update, and delete ACLs without direct Kafka CLI access.

ACL Components

Each ACL binding consists of:

FieldDescription
Resource TypeTopic, Group, Cluster, TransactionalId, DelegationToken
Resource NameName of the resource (e.g., topic name)
Pattern TypeLiteral (exact match) or Prefixed (prefix match)
PrincipalUser identity (e.g., User:alice)
HostClient host (* for any)
OperationRead, Write, Create, Delete, Alter, Describe, All, etc.
Permission TypeAllow or Deny

API Endpoints

MethodPathDescriptionLicense
GET/api/v1/aclsList all ACL bindingsNo
POST/api/v1/aclsCreate ACL bindingsYes
PUT/api/v1/aclsUpdate (replace) an ACL bindingYes
DELETE/api/v1/aclsDelete ACL bindings by filterYes

Example: Create a Read ACL

curl -X POST http://localhost:8080/api/v1/acls \ -H "Content-Type: application/json" \ -d '{ "bindings": [{ "resourceType": "Topic", "resourceName": "my-topic", "patternType": "Literal", "principal": "User:consumer-app", "host": "*", "operation": "Read", "permissionType": "Allow" }] }'

Example: List ACLs for a Principal

curl "http://localhost:8080/api/v1/acls?principal=User:consumer-app"
Last updated on