{"repo":"StyraOSS/opa-kafka-plugin","free":true,"listed":false,"github":"https://github.com/StyraOSS/opa-kafka-plugin","clone":"git clone https://github.com/StyraOSS/opa-kafka-plugin.git","description":"Open Policy Agent (OPA) plug-in for Kafka authorization","language":"Scala","stars":63,"topics":["opa-kafka-plugin","opa","kafka","kafka-authorization","authorization","openpolicyagent","rego","open-policy-agent"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"Open Policy Agent plugin for Kafka authorization Open Policy Agent (OPA) plugin for Kafka authorization. Prerequisites Kafka 3.8.0+ (for older Kafka versions, please check previous release) Java 17 or above OPA installed and running on the brokers Installation Download the latest OPA authorizer plugin jar from Releases (or Maven Central) and put the file ( opa-authorizer-{$VERSION}.jar ) somewhere Kafka recognizes it - this could be directly in Kafka's libs directory or in a separate plugin directory pointed out to Kafka at startup, e.g: CLASSPATH=/usr/local/share/kafka/plugins/ To activate the opa-kafka-plugin add the authorizer.class.name to server.properties\\ authorizer.class.name=org.openpolicyagent.kafka.OpaAuthorizer The plugin supports the following properties: Property Key Example Default Description --- --- --- --- opa.authorizer.url http://opa:8181/v1/data/kafka/authz/allow Name of the OPA policy to query. [required] opa.authorizer.allow.on.error false false Fail-closed or fail-open if OPA call fails. opa.authorizer.cache.initial.capacity 5000 5000 Initial decision cache size. opa.authorizer.cache.maximum.size 50000 50000 Max decision cache size. opa.authorizer.cache.expire.after.seconds 3600 3600 Decision cache expiry in seconds. opa.authorizer.metrics.enabled true false Whether or not expose JMX metrics for monitoring. super.users User:alice;User:bob Super users which are always allowed. opa.authorizer.truststore.path /path/to/mytruststore.p12 Path to the PKCS12 t","default_branch":null,"files":null,"tree":[],"storefront":"/r/StyraOSS","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/StyraOSS/opa-kafka-plugin/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}