[bitnami/kafka] Release 4.3.0-debian-12-r1 (#93992)

Signed-off-by: Bitnami Bot <bitnami.bot@broadcom.com>
This commit is contained in:
Bitnami Bot
2026-05-26 08:30:00 +02:00
committed by GitHub
parent f6617d3935
commit da685fd8fa
6 changed files with 72 additions and 17 deletions
+2 -2
View File
@@ -8,7 +8,7 @@ ARG JAVA_EXTRA_SECURITY_DIR="/bitnami/java/extra-security"
ARG TARGETARCH
LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \
org.opencontainers.image.created="2026-05-25T10:47:50Z" \
org.opencontainers.image.created="2026-05-26T06:11:00Z" \
org.opencontainers.image.description="Application packaged by Broadcom, Inc." \
org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/kafka/README.md" \
org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/kafka" \
@@ -53,7 +53,7 @@ RUN /opt/bitnami/scripts/java/postunpack.sh
RUN /opt/bitnami/scripts/kafka/postunpack.sh
ENV APP_VERSION="4.3.0" \
BITNAMI_APP_NAME="kafka" \
IMAGE_REVISION="0" \
IMAGE_REVISION="1" \
JAVA_HOME="/opt/bitnami/java" \
PATH="/opt/bitnami/java/bin:/opt/bitnami/kafka/bin:$PATH"
@@ -139,3 +139,40 @@ wait_for_log_entry() {
return 1
fi
}
########################
# Creates a secure temporary file containing the provided secret
# Arguments:
# $1 - secret to write to the temporary file
# Returns:
# String
#########################
credential_to_temp_file() {
local secret="$1"
local tmp_file
# Use mktemp with a specific prefix for easier debugging if something lingers
if ! tmp_file=$(mktemp "${TMPDIR:-/tmp}/at.cred.XXXXXXXX"); then
echo "Error: Failed to create temp file" >&2
return 1
fi
# Restrict permissions before writing the secret
chmod 0600 "$tmp_file"
# Write secret and ensure it's flushed to disk
printf "%s" "$secret" > "$tmp_file"
# Output the filename so the caller can capture it
echo "$tmp_file"
}
########################
# Cleans up temporary files created by credential_to_temp_file
# Arguments:
# None
# Returns:
# None
#########################
cleanup_credentials() {
debug "Cleaning up temporary files containing credentials"
rm -rf "${TMPDIR:-/tmp}"/at.cred.*
}
@@ -110,15 +110,15 @@ export KAFKA_ZOOKEEPER_TLS_VERIFY_HOSTNAME="${KAFKA_ZOOKEEPER_TLS_VERIFY_HOSTNAM
# Authentication
export KAFKA_INTER_BROKER_USER="${KAFKA_INTER_BROKER_USER:-user}"
export KAFKA_INTER_BROKER_PASSWORD="${KAFKA_INTER_BROKER_PASSWORD:-bitnami}"
export KAFKA_INTER_BROKER_PASSWORD="${KAFKA_INTER_BROKER_PASSWORD:-}"
export KAFKA_CONTROLLER_USER="${KAFKA_CONTROLLER_USER:-controller_user}"
export KAFKA_CONTROLLER_PASSWORD="${KAFKA_CONTROLLER_PASSWORD:-bitnami}"
export KAFKA_CONTROLLER_PASSWORD="${KAFKA_CONTROLLER_PASSWORD:-}"
export KAFKA_CERTIFICATE_PASSWORD="${KAFKA_CERTIFICATE_PASSWORD:-}"
export KAFKA_TLS_TRUSTSTORE_FILE="${KAFKA_TLS_TRUSTSTORE_FILE:-}"
export KAFKA_TLS_TYPE="${KAFKA_TLS_TYPE:-JKS}"
export KAFKA_TLS_CLIENT_AUTH="${KAFKA_TLS_CLIENT_AUTH:-required}"
export KAFKA_CLIENT_USERS="${KAFKA_CLIENT_USERS:-user}"
export KAFKA_CLIENT_PASSWORDS="${KAFKA_CLIENT_PASSWORDS:-bitnami}"
export KAFKA_CLIENT_USERS="${KAFKA_CLIENT_USERS:-}"
export KAFKA_CLIENT_PASSWORDS="${KAFKA_CLIENT_PASSWORDS:-}"
# Java settings
export KAFKA_HEAP_OPTS="${KAFKA_HEAP_OPTS:--Xmx1024m -Xms1024m}"
@@ -10,6 +10,7 @@ set -o pipefail
# set -o xtrace # Uncomment this line for debugging purposes
# Load libraries
. /opt/bitnami/scripts/libfile.sh
. /opt/bitnami/scripts/libfs.sh
. /opt/bitnami/scripts/libos.sh
. /opt/bitnami/scripts/libkafka.sh
@@ -20,6 +21,8 @@ set -o pipefail
# Map Kafka environment variables
kafka_create_alias_environment_variables
# Ensure we clean up temporary files when this script ends
trap cleanup_credentials EXIT
# Dynamically set node.id/broker.id/controller.quorum.bootstrap.servers if the _COMMAND environment variable is set
kafka_dynamic_environment_variables
# Set the default truststore locations before validation
@@ -731,8 +731,11 @@ kafka_zookeeper_create_sasl_scram_users() {
fi
for ((i = 0; i < ${#users[@]}; i++)); do
debug "Creating user ${users[i]} in zookeeper"
# Avoid passing credentials as arguments to kafka-configs.sh, to avoid leaking them given a local observer with /proc read access can read them
local config_file
config_file="$(credential_to_temp_file "SCRAM-SHA-256=[iterations=8192,password=${passwords[i]}],SCRAM-SHA-512=[password=${passwords[i]}]")"
# Ref: https://docs.confluent.io/current/kafka/authentication_sasl/authentication_sasl_scram.html#sasl-scram-overview
debug_execute kafka-configs.sh --zookeeper "$zookeeper_connect" --alter --add-config "SCRAM-SHA-256=[iterations=8192,password=${passwords[i]}],SCRAM-SHA-512=[password=${passwords[i]}]" --entity-type users --entity-name "${users[i]}"
debug_execute kafka-configs.sh --zookeeper "$zookeeper_connect" --alter --add-config "$(<"$config_file")" --entity-type users --entity-name "${users[i]}"
done
}
@@ -892,26 +895,38 @@ kafka_kraft_storage_initialize() {
# Configure SCRAM-SHA-256 if enabled
if grep -Eq "^sasl.enabled.mechanisms=.*SCRAM-SHA-256" "$KAFKA_CONF_FILE"; then
for ((i = 0; i < ${#users[@]}; i++)); do
args+=("--add-scram" "SCRAM-SHA-256=[name=${users[i]},password=${passwords[i]}]")
local scram_file
scram_file="$(credential_to_temp_file "SCRAM-SHA-256=[name=${users[i]},password=${passwords[i]}]")"
args+=("--add-scram" "$(<"$scram_file")")
done
fi
# Configure SCRAM-SHA-512 if enabled
if grep -Eq "^sasl.enabled.mechanisms=.*SCRAM-SHA-512" "$KAFKA_CONF_FILE"; then
for ((i = 0; i < ${#users[@]}; i++)); do
args+=("--add-scram" "SCRAM-SHA-512=[name=${users[i]},password=${passwords[i]}]")
local scram_file
scram_file="$(credential_to_temp_file "SCRAM-SHA-512=[name=${users[i]},password=${passwords[i]}]")"
args+=("--add-scram" "$(<"$scram_file")")
done
fi
# Add interbroker credentials
if grep -Eq "^sasl.mechanism.inter.broker.protocol=SCRAM-SHA-256" "$KAFKA_CONF_FILE"; then
args+=("--add-scram" "SCRAM-SHA-256=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")
local scram_file
scram_file="$(credential_to_temp_file "SCRAM-SHA-256=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")"
args+=("--add-scram" "$(<"$scram_file")")
elif grep -Eq "^sasl.mechanism.inter.broker.protocol=SCRAM-SHA-512" "$KAFKA_CONF_FILE"; then
args+=("--add-scram" "SCRAM-SHA-512=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")
local scram_file
scram_file="$(credential_to_temp_file "SCRAM-SHA-512=[name=${KAFKA_INTER_BROKER_USER},password=${KAFKA_INTER_BROKER_PASSWORD}]")"
args+=("--add-scram" "$(<"$scram_file")")
fi
# Add controller credentials
if grep -Eq "^sasl.mechanism.controller.protocol=SCRAM-SHA-256" "$KAFKA_CONF_FILE"; then
args+=("--add-scram" "SCRAM-SHA-256=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")
local scram_file
scram_file="$(credential_to_temp_file "SCRAM-SHA-256=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")"
args+=("--add-scram" "$(<"$scram_file")")
elif grep -Eq "^sasl.mechanism.controller.protocol=SCRAM-SHA-512" "$KAFKA_CONF_FILE"; then
args+=("--add-scram" "SCRAM-SHA-512=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")
local scram_file
scram_file="$(credential_to_temp_file "SCRAM-SHA-512=[name=${KAFKA_CONTROLLER_USER},password=${KAFKA_CONTROLLER_PASSWORD}]")"
args+=("--add-scram" "$(<"$scram_file")")
fi
fi
if kafka_is_dynamic_controller_quorum_supported && [[ "${KAFKA_CFG_PROCESS_ROLES:-}" =~ "controller" ]] && [[ "${KAFKA_KRAFT_VERSION:-}" -eq "1" ]]; then
+4 -4
View File
@@ -98,15 +98,15 @@ The following tables list the main variables you can set.
| `KAFKA_ZOOKEEPER_TLS_TRUSTSTORE_PASSWORD` | Kafka Zookeeper truststore file password. | `nil` |
| `KAFKA_ZOOKEEPER_TLS_VERIFY_HOSTNAME` | Verify Zookeeper hostname on TLS certificates. | `true` |
| `KAFKA_INTER_BROKER_USER` | Kafka inter broker communication user. | `user` |
| `KAFKA_INTER_BROKER_PASSWORD` | Kafka inter broker communication password. | `bitnami` |
| `KAFKA_INTER_BROKER_PASSWORD` | Kafka inter broker communication password. | `nil` |
| `KAFKA_CONTROLLER_USER` | Kafka control plane communication user. | `controller_user` |
| `KAFKA_CONTROLLER_PASSWORD` | Kafka control plane communication password. | `bitnami` |
| `KAFKA_CONTROLLER_PASSWORD` | Kafka control plane communication password. | `nil` |
| `KAFKA_CERTIFICATE_PASSWORD` | Password for certificates. | `nil` |
| `KAFKA_TLS_TRUSTSTORE_FILE` | Kafka truststore file location. | `nil` |
| `KAFKA_TLS_TYPE` | Choose the TLS certificate format to use. | `JKS` |
| `KAFKA_TLS_CLIENT_AUTH` | Configures kafka broker to request client authentication. | `required` |
| `KAFKA_CLIENT_USERS` | List of users that will be created when using `SASL_SCRAM` for client communications. Separated by commas, semicolons or whitespaces. | `user` |
| `KAFKA_CLIENT_PASSWORDS` | Passwords for the users specified at `KAFKA_CLIENT_USERS`. Separated by commas, semicolons or whitespaces. | `bitnami` |
| `KAFKA_CLIENT_USERS` | List of users that will be created when using `SASL_SCRAM` for client communications. Separated by commas, semicolons or whitespaces. | `nil` |
| `KAFKA_CLIENT_PASSWORDS` | Passwords for the users specified at `KAFKA_CLIENT_USERS`. Separated by commas, semicolons or whitespaces. | `nil` |
| `KAFKA_HEAP_OPTS` | Kafka heap options for Java. | `-Xmx1024m -Xms1024m` |
| `JAVA_TOOL_OPTIONS` | Java tool options. | `nil` |