Skip to content

in_rdkafka_group: Apply SSL and SASL parameters to the consumer - #580

Merged
kenhys merged 2 commits into
fluent:masterfrom
Watson1978:rdkafka-group-ssl-sasl-settings
Sep 4, 2026
Merged

kenhys merged 2 commits into
fluent:masterfrom
Watson1978:rdkafka-group-ssl-sasl-settings

Conversation

@Watson1978

Copy link
Copy Markdown
Contributor

in_rdkafka_group accepted the ssl_* and SASL parameters shared with the other plugins but never passed them to librdkafka.
The consumer was built from kafka_configs alone, so a configuration that only set ssl_ca_cert or ssl_ca_certs_from_system connected over PLAINTEXT without any error.
This moves the parameter mapping of out_rdkafka2#build_config into a shared module and uses it from both plugins. Keys given in kafka_configs take precedence, matching how rdkafka_options works in out_rdkafka2.

Note for existing users: parameters that in_rdkafka_group previously ignored now take effect, so leftover username and password settings start reaching librdkafka. The sasl_over_ssl check applies to in_rdkafka_group as well, and it now matches security.protocol case-insensitively, so the lowercase sasl_plaintext spelling used in the librdkafka documentation is no longer able to bypass it in either plugin. Set sasl_over_ssl false to keep sending SASL credentials over a plaintext connection.

in_rdkafka_group accepted the ssl_* and SASL parameters but never passed
them to librdkafka. The consumer was built from kafka_configs alone, so a
configuration that only set ssl_ca_cert connected over PLAINTEXT without
any error.

Move the parameter mapping of out_rdkafka2#build_config into a shared
module and use it from both plugins. Keys given in kafka_configs take
precedence, matching rdkafka_options in out_rdkafka2. The sasl_over_ssl
check now applies to in_rdkafka_group as well, and it matches
security.protocol case-insensitively so that the lowercase sasl_plaintext
spelling used in the librdkafka documentation cannot bypass it.

Signed-off-by: Shizuo Fujita <fujita@clear-code.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@Watson1978
Watson1978 requested a review from kenhys September 4, 2026 00:58
Comment thread lib/fluent/plugin/kafka_plugin_util.rb
Comment thread test/plugin/test_in_rdkafka_group.rb Outdated
…entials

scram_mechanism only takes effect when username and password are set, so
a configuration that sets it alone was ignored without any message.

Also switch the test configurations of in_rdkafka_group to the %[] style
already used in that file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Shizuo Fujita <fujita@clear-code.com>
@Watson1978
Watson1978 requested a review from kenhys September 4, 2026 01:54
@kenhys
kenhys merged commit e6be8f1 into fluent:master Sep 4, 2026
32 checks passed
@Watson1978
Watson1978 deleted the rdkafka-group-ssl-sasl-settings branch September 4, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants