Rethinking Apache Kafka Security and Account Management
https://cnfl.io/podcast-episode-246 | Is there a better way to manage access to resources without compromising security? New employees need access to a variety of resources within a company's tech stack. But manually granting access can be error-prone. And when employees leave, their access must be revoked, thus potentially introducing security risks if an admin misses one. In this podcast, Kris Jenkins talks to Anuj Sawani (Security Product Manager, Confluent) about the centralized identity management system he helped build to integrate with Apache Kafka® to prevent common identity management headaches and security risks. With 12+ years of experience building cybersecurity products for enterprise companies, Anuj Sawani explains how he helped build out KIP-768 (Secured OAuth support in Kafka) that supports a unified identity mechanism that spans across cloud and on-premises (hybrid scenarios). Confluent Cloud customers wanted a single identity to access all their services. The manual process required managing different sets of identity stores across the ecosystem. Anuj goes on to explain how Identity and Access Management (IAM) using cloud-native authentication protocols, such as OAuth or OpenID Connect, solves this problem by centralizing identity and minimizing security risks. Anuj emphasizes that sticking with industry standards is key because it makes integrating with other systems easy. With OAuth now supported in Kafka, this means performing client upgrades, configuring identity providers, etc. to ensure the applications can leverage new capabilities. Some examples of how to do this are to use centralized identities for client/broker connections. As Anuj continues to build and enhance features, he hopes to recommend this unified solution to other technology vendors because it makes integration much easier. The goal is to create a web of connectors that support the same standards. The future is bright, as other organizations are researching supporting OAuth and similar industry standards. Anuj is looking forward to the evolution and applying it to other use cases and scenarios. EPISODE LINKS ► Introduction to Confluent Cloud Security: https://cnfl.io/intro-to-confluent-cloud-security-episode-246 ► KIP-768: Secured OAuth support in Apache Kafka: https://cnfl.io/kip-768-secured-oauth-support-in-apache-kafka-episode-246 ► Confluent Cloud Documentation: OAuth 2.0 Support: https://cnfl.io/use-oauth-for-confluent-cloud-episode-246 ► Apache Kafka Security Best Practices: https://cnfl.io/apache-kafka-security-best-practices-episode-246 ► Security for Real-Time Data Stream Processing with Confluent Cloud: https://cnfl.io/security-for-real-time-data-stream-processing-with-confluent-cloud-episode-246 ► Kris Jenkins’ Twitter: https://twitter.com/krisajenkins ► Streaming Audio Playlist: https://www.youtube.com/playlist?list=PLa7VYi0yPIH1B0i7mhzVi78TIkKSd-0vE ► Join the Confluent Community: https://cnfl.io/confluent-community-episode-246 ► Learn more with Kafka tutorials, resources, and guides at Confluent Developer: https://cnfl.io/confluent-developer-episode-246 ► Live demo: Intro to Event-Driven Microservices with Confluent: https://cnfl.io/demo-intro-to-event-driven-microservices-with-confluent-episode-246 ► Use PODCAST100 to get an additional $100 of free Confluent Cloud usage: https://cnfl.io/try-cloud-episode-246 ► Promo code details: https://cnfl.io/podcast100-details-episode-246 TIMESTAMPS 0:00 - Intro 6:19 - Common identity management problems and security risks 11:33 - Building a centralized identity management system 14:47 - Recommendations for enterprise IAM 18:35 - OAuth vs. Open ID Connect 22:36 - Integrating identity providers with Apache Kafka 25:24 - KIP-768: Introducing support for secured OAuth 30:35 - Setting up discovery end points 35:22 - Tips for getting started with centralized identity management 38:41 - Authentication vs. authorization standards 39:42 - It's a wrap! ABOUT CONFLUENT Confluent is pioneering a fundamentally new category of data infrastructure focused on data in motion. Confluent’s cloud-native offering is the foundational platform for data in motion – designed to be the intelligent connective tissue enabling real-time data, from multiple sources, to constantly stream across the organization. With Confluent, organizations can meet the new business imperative of delivering rich, digital front-end customer experiences and transitioning to sophisticated, real-time, software-driven backend operations. To learn more, please visit www.confluent.io. #cloudsecurity #microservices #apachekafka #kafka #confluent