Skip to content

Add Confluent Platform RBAC guidance to Kafka ACL setup - #38664

Draft
piochelepiotr wants to merge 2 commits into
masterfrom
piotr.wolski/confluent-rbac-kafka-acl-tabs
Draft

Add Confluent Platform RBAC guidance to Kafka ACL setup#38664
piochelepiotr wants to merge 2 commits into
masterfrom
piotr.wolski/confluent-rbac-kafka-acl-tabs

Conversation

@piochelepiotr

Copy link
Copy Markdown
Contributor

What does this PR do? What is the motivation?

Splits the "ACL permissions" section of the Kafka Monitoring setup page into two tabs — ACLs and Confluent Platform roles — so self-hosted Confluent Platform customers using RBAC (instead of native Kafka ACLs) have explicit guidance on which role bindings (Operator on the cluster, DeveloperRead on topics/groups) to grant the Datadog Agent principal, including example confluent iam rbac role-binding create commands. Also clarifies that the message-inspection "Additional ACL permission" section doesn't require an extra RBAC binding, since DeveloperRead already includes Read.

Prompted by a support case (Zendesk #2964638) where a Confluent Platform RBAC customer asked whether ACL requirements differ under RBAC.

Merge readiness

  • Ready for merge

For Datadog employees:

  • ⚠️ Your branch name MUST follow the <name>/<description> convention and include the forward slash (/). If you've already created your PR with an incorrect branch name, please rename your branch and open a fresh PR.
  • 🤖 New: Comment with /review to run an automated check that catches common issues before a Documentation team member reviews your PR.

AI assistance

Drafted with Claude Code based on Slack thread discussion and a read of the kafka_consumer integration's admin-client calls in integrations-core; not yet reviewed by a Confluent RBAC subject-matter expert.

Additional notes

The exact RBAC role-to-operation mapping (Operator + DeveloperRead) is based on Confluent's documented predefined roles and the Kafka Agent's describe_cluster/describe_consumer_groups/list_consumer_group_offsets calls, but has not been validated against a live Confluent RBAC cluster. Please have someone with hands-on Confluent RBAC experience confirm before merging.

…or Kafka setup

Customers running self-hosted Confluent Platform with RBAC instead of native Kafka ACLs had no guidance on which role bindings the Datadog Agent principal needs.
Remove the CLI example and rationale prose per feedback; scope DeveloperRead to all topics/groups instead of naming specific resources.
@github-actions

Copy link
Copy Markdown
Contributor

Preview links (active after the build_preview check completes)

Modified Files

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant