Support custom TLS principals
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Domain
- distributed-systems, security
Research direction
Start by reading Kafka's KafkaPrincipalBuilder documentation and tracing how the Secret Operator currently sets the certificate principal. Define the desired DN-to-principal mapping and verify that the resulting principal is used correctly for authorization; the issue does not name a file or test to run.
Written by the indexing model from the issue text.
Description
A vanilla Kafka installation will use the TLS certificate's Distinguished Name (DN) as the principal, which is then used for authorization (see https://kafka.apache.org/documentation/#security_authz_ssl). This isn't great for us, since the Secret Operator will currently always hard-code this to "CN=generated certificate for pod".
We could implement a custom https://kafka.apache.org/28/javadoc/org/apache/kafka/common/security/auth/KafkaPrincipalBuilder.html to do whatever mapping we want.
- Dominant language
- Rust
- Stars
- 29
- Forks
- 9
- Avg merge
- 1d 23h
- Merged PRs (30d)
- 11
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from stackabletech/kafka-operator
-
Wrong casing for `metadataManager` field in CRDPossibly taken @sbernauer claimed this 5 days ago. Opentype/bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
stackabletech/kafka-operator#1033 · 2 comments ·
Maintainers usually reply within 1 day
-
type/bug
Difficulty 5/5 Over a week Newbie friendliness 35/100
stackabletech/kafka-operator#955 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
stackabletech/kafka-operator#941 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
stackabletech/kafka-operator#874 ·
Maintainers usually reply within 1 day
-
Kafka 4.xMay be free again @razvan claimed this 356 days ago, and no pull request is open. Openrefinement-needed
stackabletech/kafka-operator#870 · 5 comments · 2 assignees ·
Maintainers usually reply within 1 day
All issues in stackabletech/kafka-operator
Similar issues
-
contribution
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
tree-sitter/tree-sitter#6005 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
-
agent:triaged bug bughunt pm:pipenv priority:p1
Difficulty 2/5 1-3 hours Newbie friendliness 83/100
SocketDev/socket-patch#744 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
maplibre/maplibre-tile-spec#1844 ·
Maintainers usually reply within 1 day