mirror of
https://github.com/bitnami/containers.git
synced 2026-10-10 18:21:56 +02:00
[bitnami/kafka] Release 4.3.0-debian-12-r1 (#93992)
Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
@@ -8,7 +8,7 @@ ARG JAVA_EXTRA_SECURITY_DIR="/bitnami/java/extra-security"
|
||||
ARG TARGETARCH
|
||||
|
||||
LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \
|
||||
org.opencontainers.image.created="2026-05-25T10:47:50Z" \
|
||||
org.opencontainers.image.created="2026-05-26T06:11:00Z" \
|
||||
org.opencontainers.image.description="Application packaged by Broadcom, Inc." \
|
||||
org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/kafka/README.md" \
|
||||
org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/kafka" \
|
||||
@@ -53,7 +53,7 @@ RUN /opt/bitnami/scripts/java/postunpack.sh
|
||||
RUN /opt/bitnami/scripts/kafka/postunpack.sh
|
||||
ENV APP_VERSION="4.3.0" \
|
||||
BITNAMI_APP_NAME="kafka" \
|
||||
IMAGE_REVISION="0" \
|
||||
IMAGE_REVISION="1" \
|
||||
JAVA_HOME="/opt/bitnami/java" \
|
||||
PATH="/opt/bitnami/java/bin:/opt/bitnami/kafka/bin:$PATH"
|
||||
|
||||
|
||||
@@ -139,3 +139,40 @@ wait_for_log_entry() {
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
########################
|
||||
# Creates a secure temporary file containing the provided secret
|
||||
# Arguments:
|
||||
# $1 - secret to write to the temporary file
|
||||
# Returns:
|
||||
# String
|
||||
#########################
|
||||
credential_to_temp_file() {
|
||||
local secret="$1"
|
||||
local tmp_file
|
||||
|
||||
# Use mktemp with a specific prefix for easier debugging if something lingers
|
||||
if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then
|
||||
echo "Error: Failed to create temp file" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
# Restrict permissions before writing the secret
|
||||
chmod 0600 "$tmp_file"
|
||||
# Write secret and ensure it's flushed to disk
|
||||
printf "%s" "$secret" > "$tmp_file"
|
||||
# Output the filename so the caller can capture it
|
||||
echo "$tmp_file"
|
||||
}
|
||||
|
||||
########################
|
||||
# Cleans up temporary files created by credential_to_temp_file
|
||||
# Arguments:
|
||||
# None
|
||||
# Returns:
|
||||
# None
|
||||
#########################
|
||||
cleanup_credentials() {
|
||||
debug "Cleaning up temporary files containing credentials"
|
||||
rm -rf "${TMPDIR:-/tmp}"/at.cred.*
|
||||
}
|
||||
|
||||
@@ -110,15 +110,15 @@ export KAFKA_ZOOKEEPER_TLS_VERIFY_HOSTNAME="${KAFKA_ZOOKEEPER_TLS_VERIFY_HOSTNAM
|
||||
|
||||
# Authentication
|
||||
export KAFKA_INTER_BROKER_USER="${KAFKA_INTER_BROKER_USER:-user}"
|
||||
export KAFKA_INTER_BROKER_PASSWORD="${KAFKA_INTER_BROKER_PASSWORD:-bitnami}"
|
||||
export KAFKA_INTER_BROKER_PASSWORD="${KAFKA_INTER_BROKER_PASSWORD:-}"
|
||||
export KAFKA_CONTROLLER_USER="${KAFKA_CONTROLLER_USER:-controller_user}"
|
||||
export KAFKA_CONTROLLER_PASSWORD="${KAFKA_CONTROLLER_PASSWORD:-bitnami}"
|
||||
export KAFKA_CONTROLLER_PASSWORD="${KAFKA_CONTROLLER_PASSWORD:-}"
|
||||
export KAFKA_CERTIFICATE_PASSWORD="${KAFKA_CERTIFICATE_PASSWORD:-}"
|
||||
export KAFKA_TLS_TRUSTSTORE_FILE="${KAFKA_TLS_TRUSTSTORE_FILE:-}"
|
||||
export KAFKA_TLS_TYPE="${KAFKA_TLS_TYPE:-JKS}"
|
||||
export KAFKA_TLS_CLIENT_AUTH="${KAFKA_TLS_CLIENT_AUTH:-required}"
|
||||
export KAFKA_CLIENT_USERS="${KAFKA_CLIENT_USERS:-user}"
|
||||
export KAFKA_CLIENT_PASSWORDS="${KAFKA_CLIENT_PASSWORDS:-bitnami}"
|
||||
export KAFKA_CLIENT_USERS="${KAFKA_CLIENT_USERS:-}"
|
||||
export KAFKA_CLIENT_PASSWORDS="${KAFKA_CLIENT_PASSWORDS:-}"
|
||||
|
||||
# Java settings
|
||||
export KAFKA_HEAP_OPTS="${KAFKA_HEAP_OPTS:--Xmx1024m -Xms1024m}"
|
||||
|
||||
@@ -10,6 +10,7 @@ set -o pipefail
|
||||
# set -o xtrace # Uncomment this line for debugging purposes
|
||||
|
||||
# Load libraries
|
||||
. /opt/bitnami/scripts/libfile.sh
|
||||
. /opt/bitnami/scripts/libfs.sh
|
||||
. /opt/bitnami/scripts/libos.sh
|
||||
. /opt/bitnami/scripts/libkafka.sh
|
||||
@@ -20,6 +21,8 @@ set -o pipefail
|
||||
# Map Kafka environment variables
|
||||
kafka_create_alias_environment_variables
|
||||
|
||||
# Ensure we clean up temporary files when this script ends
|
||||
trap cleanup_credentials EXIT
|
||||
# Dynamically set node.id/broker.id/controller.quorum.bootstrap.servers if the _COMMAND environment variable is set
|
||||
kafka_dynamic_environment_variables
|
||||
# Set the default truststore locations before validation
|
||||
|
||||
@@ -731,8 +731,11 @@ kafka_zookeeper_create_sasl_scram_users() {
|
||||
fi
|
||||
for ((i = 0; i < ${#users[@]}; i++)); do
|
||||
debug "Creating user ${users[i]} in zookeeper"
|
||||
# Avoid passing credentials as arguments to kafka-configs.sh, to avoid leaking them given a local observer with /proc read access can read them
|
||||
local config_file
|
||||
config_file="$(credential_to_temp_file "SCRAM-SHA-256=[iterations=8192,password=${passwords[i]}],SCRAM-SHA-512=[password=${passwords[i]}]")"
|
||||
# Ref: https://docs.confluent.io/current/kafka/authentication_sasl/authentication_sasl_scram.html#sasl-scram-overview
|
||||
debug_execute kafka-configs.sh --zookeeper "$zookeeper_connect" --alter --add-config "SCRAM-SHA-256=[iterations=8192,password=${passwords[i]}],SCRAM-SHA-512=[password=${passwords[i]}]" --entity-type users --entity-name "${users[i]}"
|
||||
debug_execute kafka-configs.sh --zookeeper "$zookeeper_connect" --alter --add-config "$(<"$config_file")" --entity-type users --entity-name "${users[i]}"
|
||||
done
|
||||
}
|
||||
|
||||
@@ -892,26 +895,38 @@ kafka_kraft_storage_initialize() {
|
||||
# Configure SCRAM-SHA-256 if enabled
|
||||
if grep -Eq "^sasl.enabled.mechanisms=.*SCRAM-SHA-256" "$KAFKA_CONF_FILE"; then
|
||||
for ((i = 0; i < ${#users[@]}; i++)); do
|
||||
args+=("--add-scram" "SCRAM-SHA-256=[name=${users[i]},password=${passwords[i]}]")
|
||||
local scram_file
|
||||
scram_file="$(credential_to_temp_file "SCRAM-SHA-256=[name=${users[i]},password=${passwords[i]}]")"
|
||||
args+=("--add-scram" "$(<"$scram_file")")
|
||||
done
|
||||
fi
|
||||
# Configure SCRAM-SHA-512 if enabled
|
||||
if grep -Eq "^sasl.enabled.mechanisms=.*SCRAM-SHA-512" "$KAFKA_CONF_FILE"; then
|
||||
for ((i = 0; i < ${#users[@]}; i++)); do
|
||||
args+=("--add-scram" "SCRAM-SHA-512=[name=${users[i]},password=${passwords[i]}]")
|
||||
local scram_file
|
||||
scram_file="$(credential_to_temp_file "SCRAM-SHA-512=[name=${users[i]},password=${passwords[i]}]")"
|
||||
args+=("--add-scram" "$(<"$scram_file")")
|
||||
done
|
||||
fi
|
||||
# Add interbroker credentials
|
||||
if grep -Eq "^sasl.mechanism.inter.broker.protocol=SCRAM-SHA-256" "$KAFKA_CONF_FILE"; then
|
||||
args+=("--add-scram" "SCRAM-SHA-256=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")
|
||||
local scram_file
|
||||
scram_file="$(credential_to_temp_file "SCRAM-SHA-256=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")"
|
||||
args+=("--add-scram" "$(<"$scram_file")")
|
||||
elif grep -Eq "^sasl.mechanism.inter.broker.protocol=SCRAM-SHA-512" "$KAFKA_CONF_FILE"; then
|
||||
args+=("--add-scram" "SCRAM-SHA-512=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")
|
||||
local scram_file
|
||||
scram_file="$(credential_to_temp_file "SCRAM-SHA-512=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")"
|
||||
args+=("--add-scram" "$(<"$scram_file")")
|
||||
fi
|
||||
# Add controller credentials
|
||||
if grep -Eq "^sasl.mechanism.controller.protocol=SCRAM-SHA-256" "$KAFKA_CONF_FILE"; then
|
||||
args+=("--add-scram" "SCRAM-SHA-256=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")
|
||||
local scram_file
|
||||
scram_file="$(credential_to_temp_file "SCRAM-SHA-256=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")"
|
||||
args+=("--add-scram" "$(<"$scram_file")")
|
||||
elif grep -Eq "^sasl.mechanism.controller.protocol=SCRAM-SHA-512" "$KAFKA_CONF_FILE"; then
|
||||
args+=("--add-scram" "SCRAM-SHA-512=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")
|
||||
local scram_file
|
||||
scram_file="$(credential_to_temp_file "SCRAM-SHA-512=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")"
|
||||
args+=("--add-scram" "$(<"$scram_file")")
|
||||
fi
|
||||
fi
|
||||
if kafka_is_dynamic_controller_quorum_supported && [[ "${KAFKA_CFG_PROCESS_ROLES:-}" =~ "controller" ]] && [[ "${KAFKA_KRAFT_VERSION:-}" -eq "1" ]]; then
|
||||
|
||||
@@ -98,15 +98,15 @@ The following tables list the main variables you can set.
|
||||
| `KAFKA_ZOOKEEPER_TLS_TRUSTSTORE_PASSWORD` | Kafka Zookeeper truststore file password. | `nil` |
|
||||
| `KAFKA_ZOOKEEPER_TLS_VERIFY_HOSTNAME` | Verify Zookeeper hostname on TLS certificates. | `true` |
|
||||
| `KAFKA_INTER_BROKER_USER` | Kafka inter broker communication user. | `user` |
|
||||
| `KAFKA_INTER_BROKER_PASSWORD` | Kafka inter broker communication password. | `bitnami` |
|
||||
| `KAFKA_INTER_BROKER_PASSWORD` | Kafka inter broker communication password. | `nil` |
|
||||
| `KAFKA_CONTROLLER_USER` | Kafka control plane communication user. | `controller_user` |
|
||||
| `KAFKA_CONTROLLER_PASSWORD` | Kafka control plane communication password. | `bitnami` |
|
||||
| `KAFKA_CONTROLLER_PASSWORD` | Kafka control plane communication password. | `nil` |
|
||||
| `KAFKA_CERTIFICATE_PASSWORD` | Password for certificates. | `nil` |
|
||||
| `KAFKA_TLS_TRUSTSTORE_FILE` | Kafka truststore file location. | `nil` |
|
||||
| `KAFKA_TLS_TYPE` | Choose the TLS certificate format to use. | `JKS` |
|
||||
| `KAFKA_TLS_CLIENT_AUTH` | Configures kafka broker to request client authentication. | `required` |
|
||||
| `KAFKA_CLIENT_USERS` | List of users that will be created when using `SASL_SCRAM` for client communications. Separated by commas, semicolons or whitespaces. | `user` |
|
||||
| `KAFKA_CLIENT_PASSWORDS` | Passwords for the users specified at `KAFKA_CLIENT_USERS`. Separated by commas, semicolons or whitespaces. | `bitnami` |
|
||||
| `KAFKA_CLIENT_USERS` | List of users that will be created when using `SASL_SCRAM` for client communications. Separated by commas, semicolons or whitespaces. | `nil` |
|
||||
| `KAFKA_CLIENT_PASSWORDS` | Passwords for the users specified at `KAFKA_CLIENT_USERS`. Separated by commas, semicolons or whitespaces. | `nil` |
|
||||
| `KAFKA_HEAP_OPTS` | Kafka heap options for Java. | `-Xmx1024m -Xms1024m` |
|
||||
| `JAVA_TOOL_OPTIONS` | Java tool options. | `nil` |
|
||||
|
||||
|
||||
Reference in New Issue
Block a user