Skip to main content

Topic

Creates a topic in Kafka.
  • API key(s): AdminToken, AppToken
  • Managed with: API, CLI, UI, TF
  • Labels support: Full
Topic checks:
  • metadata.cluster is a valid Kafka cluster
  • metadata.name has to belong to the application instance
  • spec.replicationFactor and spec.partitions are immutable and can’t be modified once the topic is created
  • spec.configs has to be a valid Kafka topic config
All the properties are validated against the topic policies attached to the application instance. Conduktor annotations:
  • metadata.description (optional), the description field in markdown that will be displayed in the Topic Catalog page in the UI.
  • metadata.descriptionIsEditable (optional), defaults to true. Defines whether the description can be updated in the UI.
  • metadata.catalogVisibility (optional), can be PUBLIC or PRIVATE. When the topic is linked to a Self-service application, defines whether the topic is visible (PUBLIC) in the Topic Catalog or not (PRIVATE). If empty, the visibility in the topic list is inherited from spec.defaultCatalogVisibility.
Side effects:

Subject

Creates a subject in the schema registry.
  • API key(s): AdminToken, AppToken
  • Managed with: API, CLI, UI
  • Labels support: Partial
Local file
Inline
Schema reference
Subject checks:
  • metadata.cluster is a valid Kafka cluster.
  • metadata.name has to belong to the application instance.
  • Mandatory spec.schema or spec.schemaFileshould be set:
    • schema requires an inline schema.
    • schemaFile requires a path to a file that contains the schema relative to the CLI (version >=0.2.5) execution path.
  • spec.format is mandatory. Defines the schema format: AVRO, PROTOBUF or JSON.
  • spec.compatibility (optional), defines the subject compatibility mode: BACKWARD, BACKWARD_TRANSITIVE, FORWARD, FORWARD_TRANSITIVE, FULL, FULL_TRANSITIVE or NONE. If undefined, the compatibility mode will be the one defined at the schema registry global level.
  • spec.references (optional), specifies the names of referenced schemas.
Side effects:
  • Kafka/schema registry:
    • subject is created/updated.
    • in dry-run mode, subject will be checked against the schema registry’s compatibility API .

GlueSchema

Creates a schema in a AWS Glue schema registry.
  • API key(s): AdminToken, AppToken
  • Managed with: API, CLI, UI
  • Labels support: Partial
Local file
Inline
Subject checks:
  • metadata.cluster is a valid Kafka cluster.
  • metadata.name has to belong to the application instance.
  • Mandatory spec.schema or spec.schemaFileshould be set:
  • schema requires an inline schema.
  • schemaFile requires a path to a file that contains the schema relative to the CLI (version >=0.2.5) execution path.
  • spec.format is mandatory. Defines the schema format: AVRO, PROTOBUF or JSON.
  • spec.compatibility is mandatory, defines the subject compatibility mode: BACKWARD, BACKWARD_ALL, FORWARD, FORWARD_ALL, FULL, FULL_ALL, DISABLED or NONE.
Side effects:
  • Kafka/schema registry:
    • schema is created/updated.
Because AWS Glue does not provide an API to check the compatibility of a schema, the update of an incompatible schema might not result in an error at apply time. The schema will be updated in Glue but will not be marked as the latest version.

Connector

Creates a connector on a Kafka Connect cluster.
  • API key(s): AdminToken, AppToken
  • Managed with: API, CLI, UI
  • Labels support: Partial
Connector checks:
  • metadata.connectCluster is a valid Kafka Connect cluster
  • metadata.name has to belong to the application instance
Conduktor annotations:
  • metadata.autoRestart.enabled (optional), default is "false". Defines whether Console’s automatic restart feature is enabled for this connector.
  • metadata.autoRestart.frequencySeconds (optional), default is 600, meaning 10 minutes. Defines the delay between consecutive restart attempts.

Service account

Manages the ACLs of a service account in Kafka. This does not create the service account, only assigns the ACLs.
  • API key(s): AdminToken
  • Managed with: API, CLI, UI
  • Labels support: Full
Kafka service account example:
schemaRegistryAuthorization (Subject ACLs for the Schema Registry Proxy) is only supported on application-managed service accounts, not on standard ServiceAccount resources. It only takes effect when the service account’s application instance is on a cluster whose Schema Registry is fronted by a Schema Registry Proxy.Schema Registry Proxy is a preview feature — reach out to your solutions architect for more information.
Aiven service account example:
Service account checks:
  • metadata.cluster is a valid Kafka cluster.
  • metadata.name is a valid, pre-existing service account.
  • spec.authorization.type has to be KAFKA_ACL (not supported for Aiven Kafka clusters) or AIVEN_ACL (is only supported for Aiven Kafka clusters). When set to KAFKA_ACL:
    • spec.acls[].type has to be a valid Kafka resource type .
    • spec.acls[].operations has to contain only operations that are valid for the resource type.
    • spec.acls[].host (optional), will default to *.
    • spec.acls[].permission (optional), will default to Allow.
    When set to AIVEN_ACL:
    • spec.acls[].resourceType has to be a valid resource type on Aiven Kafka for TOPIC or a valid resource for SCHEMA.
    • spec.acls[].name has to be a valid resource name on Aiven Kafka. For schemas, it has to match ^(Config:|Subject:[A-Za-z0-9/_.*?-]+).
    • spec.acls[].permission has to contain only operations that are valid for the resource type.
Side effects:
  • Kafka:
    • Service account ACLs are created/updated.
    • In dry-run mode, service account ACLs are validated against the aforementioned criteria, ensuring the ACL definitions are legal.