Session
One Identity Provider, Zero Trust Gaps: Securing Kafka Data Platforms End-to-End
Your Kafka cluster uses one auth mechanism. Your schema registry uses another. Your applications use a third. Each component is "secured" — but the gaps between them are where breaches happen. Attackers don't break your Kafka ACLs; they exploit the credential handoff between Kafka and everything around it.
In this session, I'll show how to collapse three auth mechanisms into one by wiring Keycloak as the single identity provider across a Kafka data platform on Kubernetes. You'll see OAuth2/OIDC replace fragmented credentials, mutual TLS enforce identity across every connection — broker, schema registry, consuming applications — and fine-grained authorization control who can produce, consume, and evolve schemas. The demo runs on Strimzi and Apicurio Registry (CNCF sandbox), but the zero-trust pattern applies to any Kafka deployment with pluggable auth.
Attendees will walk away with:
- A deployable reference architecture for securing Kafka pipelines with centralized identity on Kubernetes
- The specific configuration pitfalls that cause "it works in dev, fails in prod" security setups
- A checklist for moving a data platform from open prototype to audit-ready without slowing down developer workflows
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top