in_rdkafka_group: Apply SSL and SASL parameters to the consumer - #580
Merged
Merged
Conversation
in_rdkafka_group accepted the ssl_* and SASL parameters but never passed them to librdkafka. The consumer was built from kafka_configs alone, so a configuration that only set ssl_ca_cert connected over PLAINTEXT without any error. Move the parameter mapping of out_rdkafka2#build_config into a shared module and use it from both plugins. Keys given in kafka_configs take precedence, matching rdkafka_options in out_rdkafka2. The sasl_over_ssl check now applies to in_rdkafka_group as well, and it matches security.protocol case-insensitively so that the lowercase sasl_plaintext spelling used in the librdkafka documentation cannot bypass it. Signed-off-by: Shizuo Fujita <fujita@clear-code.com> Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
kenhys
requested changes
Sep 4, 2026
…entials scram_mechanism only takes effect when username and password are set, so a configuration that sets it alone was ignored without any message. Also switch the test configurations of in_rdkafka_group to the %[] style already used in that file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Shizuo Fujita <fujita@clear-code.com>
kenhys
approved these changes
Sep 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
in_rdkafka_groupaccepted thessl_*and SASL parameters shared with the other plugins but never passed them to librdkafka.The consumer was built from
kafka_configsalone, so a configuration that only setssl_ca_certorssl_ca_certs_from_systemconnected over PLAINTEXT without any error.This moves the parameter mapping of
out_rdkafka2#build_configinto a shared module and uses it from both plugins. Keys given inkafka_configstake precedence, matching howrdkafka_optionsworks inout_rdkafka2.Note for existing users: parameters that
in_rdkafka_grouppreviously ignored now take effect, so leftoverusernameandpasswordsettings start reaching librdkafka. Thesasl_over_sslcheck applies toin_rdkafka_groupas well, and it now matchessecurity.protocolcase-insensitively, so the lowercasesasl_plaintextspelling used in the librdkafka documentation is no longer able to bypass it in either plugin. Setsasl_over_ssl falseto keep sending SASL credentials over a plaintext connection.