Install Confluent Platform with Ansible Playbooks
This topic describes the installation steps for Confluent Platform.
Install all Confluent Platform components
Configure required settings in the
hosts.ymlfile as described in Configure Ansible Playbooks for Confluent Platform.(Optional) Validate hosts before installing Confluent Platform:
ansible-playbook -i hosts.yml confluent.platform.validate_hosts
To validate hosts for an individual component, use the
--tagflag as below:ansible-playbook -i hosts.yml confluent.platform.validate_hosts --tags=<component-name>
<component-name>can bekafka_broker,kafka_controller,schema_registry,kafka_rest,kafka_connect,ksql, orcontrol_center_next_gen.Install or update Control Center.
Install or update all Confluent Platform:
ansible-playbook -i hosts.yml confluent.platform.all
Install individual Confluent Platform components
You can use the Ansible tags to install individual components. You must follow the correct order given below to satisfy the dependencies among the components. For example, Kafka brokers will not install until the certificate authority is generated and the KRaft controller is installed.
Similarly, when you update a component section in the hosts.yml file, you
can optionally update the component and the preceding components in the order.
Generate the certificate authority (CA) if TLS encryption is enabled and using self-signed certificates. Additionally, a key pair for the MDS token, a private key and a public certificate, will be generated.
ansible-playbook -i hosts.yml confluent.platform.all --tags=certificate_authority
Install Control Center.
Install KRaft controller.
ansible-playbook -i hosts.yml confluent.platform.all --tags=kafka_controller
Install Kafka.
ansible-playbook -i hosts.yml confluent.platform.all --tags=kafka_broker
Install Schema Registry, REST Proxy, Connect, and ksqlDB in any order.
ansible-playbook -i hosts.yml confluent.platform.all --tags=schema_registry ansible-playbook -i hosts.yml confluent.platform.all --tags=kafka_rest ansible-playbook -i hosts.yml confluent.platform.all --tags=kafka_connect ansible-playbook -i hosts.yml confluent.platform.all --tags=ksql
Install Confluent Control Center
Confluent Control Center is available as a separate package and follows independent versions.
Control Center requires the bcrypt function. Install bcrypt with the following command on the control node:
pip install bcrypt
After you prepare the host and configure, run the following command to install Control Center:
ansible-playbook -i hosts.yml confluent.platform.all --tags=control_center_next_gen
The Control Center package includes Prometheus and Alert Manager.
Now when you install Kafka and KRaft as described above in Install all Confluent Platform components or Install individual Confluent Platform components, Kafka and KRaft start sending metrics to Control Center, and you will see the metrics in Control Center.
Install Confluent Platform without root access
Ansible Playbooks for Confluent Platform (Confluent Ansible) can install and run Confluent Platform as an
unprivileged user. Set rootless_enabled: true in your inventory.
Note
Rootless deployment requires Confluent Ansible 7.6.14, 7.7.12, 7.8.11,
7.9.10, 8.0.8, 8.1.6, 8.2.4, 8.3.2, 8.4.0, or later. Use the latest
patch release for your Confluent Ansible minor version. Earlier patch
releases do not include rootless_enabled support. This requirement
is about the Confluent Ansible patch version and is independent of which
Confluent Platform version you install.
A rootless deployment has two phases:
A one-time, root-only bootstrap that creates the deploy user, enables
systemdlinger for that user, and optionally installs a JDK and the other prerequisite packages. Either Confluent Ansible or an administrator can perform this step. You do not grant Confluent Ansible root orsudoaccess again afterward.The rootless deploy, which runs entirely as the unprivileged deploy user and installs, configures, and starts Confluent Platform.
Note
FIPS setup and the Unified Stream Manager agent are out of scope for rootless deployment.
Complete the following steps to deploy Confluent Platform without root access:
Configure your inventory for a rootless deployment.
Start from the non-root sample inventory. At minimum, set:
all: vars: ansible_user: cp-user ansible_become: false rootless_enabled: true deployment_user: cp-user deployment_group: cp-user rootless_deployment_path: /home/cp-user/cp-data installation_method: archive
With
deployment_user,deployment_group, androotless_deployment_pathset, Confluent Ansible automatically derives every other user, group, and directory path underrootless_deployment_path. This includes logs, data, SSL, CLI, and the JMX exporter.Run the one-time bootstrap.
An administrator with root or
sudoaccess runs this step once, using either of the following options.Bootstrap with Confluent Ansible:
ansible-playbook -i hosts.yml confluent.platform.rootless_bootstrap -e ansible_user=ec2-user
ansible_useris thesudouser Confluent Ansible connects as to run the bootstrap and is unrelated todeployment_user, the unprivileged user the bootstrap creates. Add-e rootless_install_packages=trueto also install a JDK and the other prerequisite packages. This step is idempotent.Bootstrap manually, without Confluent Ansible: Use this option if your security policy does not allow granting Confluent Ansible
sudoaccess. An administrator withsudoperforms the following steps by hand, out of band, before you run the rootless deploy:# Create the deployment group and the deploy user with its home directory. sudo groupadd <deployment_group> sudo useradd -m -g <deployment_group> <deployment_user> # Install the authorized_keys file so Confluent Ansible can # connect as the deploy user. sudo mkdir -p /home/<deployment_user>/.ssh sudo cp ~/.ssh/authorized_keys /home/<deployment_user>/.ssh/authorized_keys sudo chown -R <deployment_user>:<deployment_group> /home/<deployment_user>/.ssh sudo chmod 700 /home/<deployment_user>/.ssh sudo chmod 600 /home/<deployment_user>/.ssh/authorized_keys # Create the deployment directory and give the deploy user ownership. sudo mkdir <rootless_deployment_path> sudo chown <deployment_user>:<deployment_group> <rootless_deployment_path> # Enable systemd linger so the deploy user's systemd --user units # keep running after logout and survive a reboot. sudo loginctl enable-linger <deployment_user> # Install a supported JDK (full JDK, not JRE). sudo dnf install java-17-openjdk # RHEL sudo apt-get install openjdk-17-jdk # Debian/Ubuntu # Or unpack any JDK tarball (OpenJDK, Zulu, Temurin, or Oracle) and # set custom_java_path in the inventory instead. # Install the certificate and Python tools the deploy needs. sudo dnf install openssl rsync unzip python3-pip python3-pyyaml # RHEL sudo apt-get install openssl rsync unzip python3-pip python3-yaml # Debian/Ubuntu # Debian/Ubuntu only: systemd --user requires a per-user D-Bus session. sudo apt-get install -y dbus-user-session
The rootless deploy in the next step does not care which of these two options created the deploy user, directory, and linger state, only that they exist.
Run the rootless deploy as the deploy user, with no root access:
ansible-playbook -i hosts.yml confluent.platform.all
Confluent Ansible generates and starts a
systemd --userunit for each component (cp-<component>.service) in dependency order.(Optional) Manage and verify the deployment as the deploy user:
export XDG_RUNTIME_DIR=/run/user/$(id -u) systemctl --user status 'cp-*' systemctl --user restart cp-kafka_broker journalctl --user -u cp-kafka_broker
For the full validated reference, including the preceding manual bootstrap steps and the tested configuration matrix, see Rootless (non-root) deployment in the Confluent Ansible repository.