ACL Management
Pilot provides a UI and API for viewing and managing Kafka Access Control Lists (ACLs).
Overview
Kafka ACLs control which principals (users, services) can perform specific operations on cluster resources. Pilot makes it easy to view, create, update, and delete ACLs without direct Kafka CLI access.
ACL Components
Each ACL binding consists of:
| Field | Description |
|---|---|
| Resource Type | Topic, Group, Cluster, TransactionalId, DelegationToken |
| Resource Name | Name of the resource (e.g., topic name) |
| Pattern Type | Literal (exact match) or Prefixed (prefix match) |
| Principal | User identity (e.g., User:alice) |
| Host | Client host (* for any) |
| Operation | Read, Write, Create, Delete, Alter, Describe, All, etc. |
| Permission Type | Allow or Deny |
API Endpoints
| Method | Path | Description | License |
|---|---|---|---|
GET | /api/v1/acls | List all ACL bindings | No |
POST | /api/v1/acls | Create ACL bindings | Yes |
PUT | /api/v1/acls | Update (replace) an ACL binding | Yes |
DELETE | /api/v1/acls | Delete ACL bindings by filter | Yes |
Example: Create a Read ACL
curl -X POST http://localhost:8080/api/v1/acls \
-H "Content-Type: application/json" \
-d '{
"bindings": [{
"resourceType": "Topic",
"resourceName": "my-topic",
"patternType": "Literal",
"principal": "User:consumer-app",
"host": "*",
"operation": "Read",
"permissionType": "Allow"
}]
}'Example: List ACLs for a Principal
curl "http://localhost:8080/api/v1/acls?principal=User:consumer-app"Last updated on