Confluent
documentation
Get Started Free
  • Get Started Free
  • Stream
      Confluent Cloud

      Fully-managed data streaming platform with a cloud-native Kafka engine (KORA) for elastic scaling, with enterprise security, stream processing, governance.

      Confluent Platform

      An on-premises enterprise-grade distribution of Apache Kafka with enterprise security, stream processing, governance.

  • Connect
      Managed

      Use fully-managed connectors with Confluent Cloud to connect to data sources and sinks.

      Self-Managed

      Use self-managed connectors with Confluent Platform to connect to data sources and sinks.

  • Govern
      Managed

      Use fully-managed Schema Registry and Stream Governance with Confluent Cloud.

      Self-Managed

      Use self-managed Schema Registry and Stream Governance with Confluent Platform.

  • Process
      Managed

      Use Flink on Confluent Cloud to run complex, stateful, low-latency streaming applications.

      Self-Managed

      Use Flink on Confluent Platform to run complex, stateful, low-latency streaming applications.

Stream
Confluent Cloud

Fully-managed data streaming platform with a cloud-native Kafka engine (KORA) for elastic scaling, with enterprise security, stream processing, governance.

Confluent Platform

An on-premises enterprise-grade distribution of Apache Kafka with enterprise security, stream processing, governance.

Connect
Managed

Use fully-managed connectors with Confluent Cloud to connect to data sources and sinks.

Self-Managed

Use self-managed connectors with Confluent Platform to connect to data sources and sinks.

Govern
Managed

Use fully-managed Schema Registry and Stream Governance with Confluent Cloud.

Self-Managed

Use self-managed Schema Registry and Stream Governance with Confluent Platform.

Process
Managed

Use Flink on Confluent Cloud to run complex, stateful, low-latency streaming applications.

Self-Managed

Use Flink on Confluent Platform to run complex, stateful, low-latency streaming applications.

Learn
Get Started Free
  1. Home
  2. Cloud
  3. Confluent Cloud Clusters
  4. Copy and Share Data on Confluent Cloud
  5. Cluster Linking on Confluent Cloud
  6. Use Cases and Tutorials for Cluster Linking on Confluent Cloud

CLOUD

  • Overview
  • Get Started
    • Overview
    • Free Trial
    • Quick Start: Confluent Cloud
    • Quick Start: REST API
    • Manage Schemas
    • Tutorials and Examples
      • Overview
      • Tutorial: Use Replicator to Copy Kafka Data to Cloud
      • Example: Create Fully Managed Services
    • Use Docs with AI Tools
  • Use Kafka Clusters
    • Overview
    • Cloud Providers and Regions
    • Resilience
    • Cluster Deletion Protection
    • Multi-Tenancy and Client Quotas
      • Overview
      • Quick Start
    • Manage Clusters
      • Create a Cluster
      • View Clusters
      • Update a Cluster
      • Delete a Cluster
      • Resize a Dedicated Cluster
      • Manage Configuration Settings
    • Migrate Clusters
      • Migrate to Confluent Cloud
      • Migrate with kcp
    • Copy and Share Data
      • Cluster Linking
        • Overview
        • Quick Start
        • Configure, Manage, and Monitor
          • Configure and Manage Cluster Links
          • Manage Mirror Topics
          • Manage Private Networking
          • Manage Security
          • Monitor Metrics
        • Use Cases and Tutorials
          • Share Data Across Clusters, Regions, and Clouds
          • Disaster Recovery and Failover
          • Create Hybrid Cloud and Bridge-to-Cloud Deployments
          • Use Tiered Separation of Critical Workloads
          • Migrate Data
          • Manage Audit Logs
        • Troubleshooting
      • Replicator
        • Quick Start
        • Use Replicator to Migrate Topics
    • Connect Confluent Platform and Cloud Environments
      • Overview
      • Connect Self-Managed Gateway to Cloud
        • Confluent Cloud Gateway Overview
        • Configure and Deploy
          • Overview
          • Configure and Deploy using Docker
          • Configure and Deploy using CFK
          • Configure Security using Docker
          • Configure Security using CFK
        • Enforce Centralized Governance
          • Overview
          • Configure Centralized Governance
        • Migrate Kafka Clusters
        • Set up Network Isolation and Custom Domains
      • Connect Self-Managed Control Center to Cloud
      • Connect Self-Managed Clients to Cloud
      • Connect Self-Managed Connect to Cloud
      • Connect Self-Managed REST Proxy to Cloud
      • Connect Self-Managed ksqlDB to Cloud
      • Connect Self-Managed MQTT to Cloud
      • Connect Self-Managed Schema Registry to Cloud
      • Connect Self-Managed Streams to Cloud
      • Example: Autogenerate Self-Managed Component Configs for Cloud
    • Automate with Infrastructure as Code
      • Create Clusters with Terraform
      • Terraform Security Best Practices
      • Create Clusters with Pulumi
    • FAQ
  • Build Streaming Applications
    • Overview
    • Architectural Considerations
    • Client Quick Start
    • Configure Clients
      • Consumer
      • Share Consumers
      • Producer
      • Configuration Properties
    • Test and Monitor a Client
      • Test
      • Monitor
        • Overview
        • Monitoring with JMX
        • Configure JMX
        • Producer Metrics
        • Consumer Metrics
        • Share Consumer Metrics
      • Reset Offsets
    • Optimize and Tune
      • Overview
      • Throughput
      • Latency
      • Durability
      • Availability
      • Freight
    • Client Guides
      • Python
      • .NET Client
      • JavaScript Client
      • Go Client
      • C++ Client
      • Java Client
    • Kafka Client APIs for Confluent Cloud
      • Python Client API
      • .NET Client API
      • JavaScript Client API
      • Go Client API
      • C++ Client API
      • Java Client API
    • Deprecated Client APIs
    • Client Examples
      • Overview
      • Python Client
      • .NET Client
      • JavaScript Client
      • Go Client
      • C++ Client
      • Java
      • Spring Boot
      • KafkaProducer
      • REST
      • Clojure
      • Groovy
      • Kafka Connect Datagen
      • kafkacat
      • Kotlin
      • Ruby
      • Rust
      • Scala
    • Confluent Plugin for JetBrains IDEs
    • VS Code Extension
  • Build Kafka Streams Applications
    • Overview
    • Quick Start
    • Metrics
    • Monitor Applications
    • Upgrade Guide
    • ksqlDB
      • Create Stream Processing Apps with ksqlDB
      • Quick Start
      • Enable ksqlDB Integration with Schema Registry
      • ksqlDB Cluster API Quick Start
      • Monitor ksqlDB
      • Manage ksqlDB by using the CLI
      • Manage Connectors With ksqlDB
      • Develop ksqlDB Applications
      • Pull Queries
      • Grant Role-Based Access
      • Migrate ksqlDB Applications on Confluent Cloud
  • AI and ML
    • Overview
    • Build AI with Confluent Intelligence
      • Overview
      • Streaming Agents
        • Overview
        • Agent Runtime Guide
        • Call Tools
        • Create and Run Streaming Agents
        • Manage Agents in the Console
        • Reflection Workflows
        • Monitor Streaming Agents
        • Debug Streaming Agents
        • Examples
      • Real-Time Context Engine
        • Overview
        • Get Started
        • Manage
        • Query Data
        • Manage Access
        • Support and Limitations
      • Built-in AI/ML Functions
        • Overview
        • Analyze Sentiment
        • Detect Anomalies
        • Detect PII
        • Forecast Trends
        • Invoke a Tool in an AI Workflow
        • ML Preprocessing Functions
        • Model Inference Functions
      • Create Embeddings
        • Overview
        • Create Embeddings
      • Run a Managed AI Model
      • Run a Remote AI Model
      • Search External Tables
        • Overview
        • Key Search with External Sources
        • Text Search with External Sources
        • Vector Search with External Sources
      • FAQ
    • Use AI Tools with Confluent
      • Overview
      • Access Confluent Cloud with the Managed MCP Servers
      • Build with the Open-Source MCP Server
      • Build with Agent Skills
  • Manage Topics
    • Overview
    • Configuration Reference
    • Message Browser
    • Share Streams
      • Overview
      • Provide Stream Shares
      • Consume Stream Shares
    • Tableflow
      • Overview
      • Concepts
        • Overview
        • Storage
        • Schemas
        • Materialize Change Data Capture Streams
        • Billing
        • Write Modes
      • Get Started
        • Overview
        • Quick Start with Managed Storage
        • Quick Start Using Your Storage and AWS Glue
        • Quick Start with Delta Lake Tables
      • How-to Guides
        • Overview
        • Configure Storage
        • Encrypt Sensitive Fields
        • Integrate Catalogs
          • Overview
          • Integrate with AWS Glue Catalog
          • Integrate with Snowflake Open Catalog or Apache Polaris
          • Integrate with Unity Catalog
          • User-defined namespaces
        • Query Data
          • Overview
          • Query with AWS
          • Query with DuckDB
          • Query with Flink
          • Query with Snowflake
          • Query with Trino
      • Operate
        • Overview
        • Configure
        • Grant Role-Based Access
        • Monitor
        • Use Private Networking
        • Use Private Networking with Azure
        • Supported Cloud Regions
    • Real-Time Context Engine
    • FAQ
  • Manage and Monitor Resources with USM
    • Overview
    • Register Confluent Platform with USM
      • Overview
      • Set Up Payment Method
      • Configure Private Networking
      • Configure a Service Account
      • Deploy the USM Agent
      • Complete the Cluster Registration
    • Register Confluent Platform Connect Cluster with USM
    • Monitor Confluent Platform Resources
      • Overview
      • Clusters
      • Topics
      • Connectors
      • Consumer Lag
      • Clients
      • Kafka Streams
    • Data Governance for Confluent Platform
    • Remove the USM Agent
    • Troubleshoot
  • Govern Data Streams
    • Overview
    • Stream Governance
      • Manage Governance Packages
      • Data Portal
      • Track Data with Stream Lineage
      • Manage Stream Catalog
        • Stream Catalog User Guide
        • REST API Catalog Usage and Examples Guide
        • GraphQL API Catalog Usage and Examples Guide
    • Manage Schemas
      • Overview
      • Manage Schemas
      • Delete Schemas and Manage Storage
      • Use Broker-Side Schema ID Validation
      • Schema Linking
      • Schema Registry Tutorial
    • Fundamentals
      • Key Concepts
      • Schema Evolution and Compatibility
      • Schema Formats
        • Serializers and Deserializers Overview
        • Avro
        • Protobuf
        • JSON Schema
      • Data Contracts
      • Security Considerations
      • Enable Private Networking
        • Enable Private Networking with Schema Registry PrivateLink
        • Enable Private Networking for Schema Registry with a Public Endpoint
    • Reference
      • Overview
      • Configure Clients
      • Schema Registry C++ Client (libschemaregistry)
      • Maven Plugin
      • REST API Usage Examples
      • Use AsyncAPI to Describe Topics and Schemas
    • FAQ
  • Connect to External Services
    • Overview
    • Install Connectors
      • ActiveMQ Source
      • AlloyDB Sink
      • Amazon CloudWatch Logs Source
      • Amazon CloudWatch Metrics Sink
      • Amazon DocumentDB Sink
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
      • Amazon DynamoDB CDC Source
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
      • Amazon DynamoDB Sink
      • Amazon Kinesis Source
      • Amazon Redshift Sink
      • Amazon S3 Sink
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
      • Amazon S3 Source
      • Amazon SQS Source
      • AWS Lambda Sink
      • Azure Blob Storage Sink
        • Configure and Launch
        • Configure with Azure Egress Private Link Endpoints
      • Azure Blob Storage Source
      • Azure Cognitive Search Sink
      • Azure Cosmos DB Sink [Deprecated]
      • Azure Cosmos DB Sink V2
      • Azure Cosmos DB Source [Deprecated]
      • Azure Cosmos DB Source V2
      • Azure Data Lake Storage Gen2 Sink
      • Azure Event Hubs Source
      • Azure Functions Sink
      • Azure Log Analytics Sink
      • Azure Log Analytics Sink V2
      • Azure Service Bus Source
      • Azure Synapse Analytics Sink
      • ClickHouse Sink
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Azure Egress Private Link Endpoints
        • Configure with Google Cloud Private Service Connect Endpoints
      • Couchbase Source
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Azure Egress Private Link Endpoints
        • Configure with GCP Egress Private Service Connect Endpoints
      • Couchbase Sink
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Azure Egress Private Link Endpoints
        • Configure with GCP Egress Private Service Connect Endpoints
      • Databricks Delta Lake Sink
        • Set up Databricks Delta Lake (AWS) Sink Connector for Confluent Cloud
        • Configure and launch the connector
      • Datadog Metrics Sink
      • Datagen Source (development and testing)
      • Elasticsearch Service Sink [Deprecated]
      • Elasticsearch Service Sink V2
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Google Cloud Private Service Connect Endpoints
        • Configure with Azure Egress Private Link Endpoints
      • GitHub Source
      • Google BigQuery Sink [End of Life]
      • Google BigQuery Sink V2
      • Google Cloud BigTable Sink
      • Google Cloud Dataproc Sink [End of Life]
      • Google Cloud Firestore Sink
      • Google Cloud Functions Gen 2 Sink
      • Google Cloud Functions Sink [End of Life]
      • Google Cloud Pub/Sub Source
      • Google Cloud Spanner CDC Source (Debezium)
      • Google Cloud Spanner Sink
      • Google Cloud Storage Sink
      • Google Cloud Storage Source
      • HTTP Sink
      • HTTP Sink V2
      • HTTP Source
      • HTTP Source V2
      • IBM Db2 Source (JDBC)
      • IBM MQ Sink
      • IBM MQ Source
      • InfluxDB 2 Sink
      • InfluxDB 2 Source
      • InfluxDB 3 Sink
      • Jira Source
      • MariaDB CDC Source (Debezium)
      • Microsoft SQL Server CDC Source (Debezium) [End of Life]
      • Microsoft SQL Server CDC Source V2 (Debezium)
        • Configure and launch the connector
        • Backward incompatibility considerations
      • Microsoft SQL Server Sink (JDBC)
      • Microsoft SQL Server Source (JDBC)
      • MongoDB Atlas Sink
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Azure Egress Private Link Endpoints
        • Configure with Google Cloud Egress Private Service Connect Endpoints
      • MongoDB Atlas Source
      • MongoDB CDC Source (Debezium)
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Azure Egress Private Link Endpoints
        • Configure with Google Cloud Egress Private Service Connect Endpoints
      • MQTT Sink
      • MQTT Source
      • MySQL CDC Source (Debezium) [End of Life]
      • MySQL CDC Source V2 (Debezium)
        • Configure and Launch the connector
        • Backward Incompatible Changes
      • MySQL Sink (JDBC)
      • MySQL Source (JDBC)
      • Neo4j Sink
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Google Cloud Private Service Connect Endpoints
      • New Relic Metrics Sink
      • OpenSearch Sink
      • Oracle XStream CDC Source
        • Overview
        • Configure and Launch the connector
        • Oracle Database Prerequisites
        • Downstream Capture
        • Cascading Downstream Capture
        • Change Events
        • Signals and Actions
        • Examples
        • Troubleshooting
        • Monitoring
      • Oracle CDC Source
        • Overview
        • Configure and Launch the connector
        • Horizontal Scaling
        • Oracle Database Prerequisites
        • SMT Examples
        • DDL Changes
        • Troubleshooting
      • Oracle Database Sink (JDBC)
      • Oracle Database Source (JDBC)
      • PagerDuty Sink [End of Life]
      • Pinecone Sink
      • PostgreSQL CDC Source (Debezium) [End of Life]
      • PostgreSQL CDC Source V2 (Debezium)
        • Configure and Launch the connector
        • Backward Incompatible Changes
      • PostgreSQL Sink (JDBC)
      • PostgreSQL Source (JDBC)
      • RabbitMQ Sink
      • RabbitMQ Source
      • Redis Sink [Deprecated]
      • Redis Kafka Sink
      • Redis Kafka Source
      • Salesforce Bulk API 2.0 Sink
      • Salesforce Bulk API 2.0 Source
      • Salesforce Bulk API Source
      • Salesforce CDC Source
      • Salesforce Platform Event Sink
      • Salesforce Platform Event Source
      • Salesforce PushTopic Source
      • Salesforce SObject Sink
      • Salesforce Source V2
      • ServiceNow Sink
      • ServiceNow Source (Legacy) [Deprecated]
      • ServiceNow Source V2
      • SFTP Sink
      • SFTP Source
      • Snowflake Sink
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Azure Egress Private Link Endpoints
        • Configure with Google Cloud Private Service Connect Endpoints
      • Snowflake Source
        • Configure and Launch
        • Configure with AWS Egress PrivateLink Endpoints
        • Configure with Azure Egress Private Link Endpoints
        • Configure with Google Cloud Private Service Connect Endpoints
      • Solace Sink
      • Solace Source
      • Splunk Sink
      • Zendesk Source
    • Confluent Marketplace
      • Overview
      • Component Archive Specification
      • Contribute
    • Install Custom Plugins and Custom Connectors
      • Overview
      • Quick Start
      • Manage Custom Connectors
      • Limitations and Support
      • API and CLI
    • Manage Client-Side Encryption
    • Manage Provider Integration
    • Secret Manager Integration
      • Overview
      • Azure Key Vault Integration
      • AWS Secrets Manager Integration
      • Google Cloud Secret Manager Integration
    • Networking and DNS
      • Overview
      • AWS Egress PrivateLink Endpoints for First-Party Services
      • AWS Egress PrivateLink Endpoints for Self-Managed Services
      • AWS Egress PrivateLink Endpoints for Amazon RDS
      • AWS Egress PrivateLink Endpoints for Amazon DocumentDB
      • Azure Egress Private Link Endpoints for First-Party Services
      • Azure Egress Private Link Endpoints for Self-Managed Services
      • Google Cloud Private Service Connect Endpoints for First-Party Services
      • Google Cloud Private Service Connect Endpoints for Self-Managed Services
    • Connect API Usage
    • Manage Public Egress IP Addresses
    • Sample Connector Output
    • Configure Single Message Transformations
    • Configure Custom SMTs
      • Quick Start
      • Manage Custom SMT APIs
      • Limitations and Support
    • View Connector Events
    • Interpret Connector Statuses
    • Manage Service Accounts
    • Configure RBAC
    • View Errors in the Dead Letter Queue
    • Connector Limits
    • Manage Offsets
    • Migrate Self-Managed Connectors
    • Transforms List
      • Overview
      • AdjustPrecisionAndScale
      • BytesToString
      • Cast
      • ChangeTopicCase
      • Drop
      • DropHeaders
      • EventRouter
      • ExtractField
      • ExtractNestedField
      • ExtractTimeStamp
      • ExtractTopic
      • Filter (Kafka)
      • Filter (Confluent)
      • Flatten (Kafka)
      • Flatten (Confluent)
      • HeaderFrom
      • HeaderToValue
      • HoistField
      • InsertField
      • InsertHeader
      • KeyToValue
      • MaskField
      • MessageTimestampRouter
      • ReplaceField (Kafka)
      • ReplaceField (Confluent)
      • SetMaximumPrecision
      • SetSchemaMetadata
      • TimestampConverter
      • TimestampNow
      • TimestampNowField
      • TimestampRouter
      • TimescaleDB
      • TimezoneConverter
      • TombstoneHandler
      • TopicRegexRouter
      • ValueToKey
    • Reference
      • Additional Connector Configuration
      • Confluent AI-Assisted Troubleshooting
  • Integrate with Confluent Cloud
    • Overview
    • Connect with Confluent Program
    • Reuse Connections with External Services
      • Overview
      • Supported External Services
      • Manage Connections
    • Integrate with Cloud Service Providers
      • Overview
      • Create an AWS Provider Integration
      • Create an Azure Provider Integration
      • Create a Google Cloud Provider Integration
      • Manage a Provider Integration
  • Process Data with Flink
    • Overview
    • Get Started
      • Overview
      • Quick Start with Cloud Console
      • Quick Start with SQL Shell in Confluent CLI
      • Quick Start with Java Table API
      • Quick Start with Python Table API
    • Concepts
      • Overview
      • Autopilot
      • Batch and Stream Processing
      • Billing
      • Comparison with Apache Flink
      • Compute Pools
      • Delivery Guarantees and Latency
      • Determinism
      • External Tables
      • Materialized Tables
      • Private Networking
      • Process Table Functions
      • Schema and Statement Evolution
      • Security Controls
      • Snapshot Queries
      • Statements
      • Statement CFU Metrics
      • Tables and Topics
      • Time and Watermarks
      • User-defined Functions
    • How-To Guides
      • Overview
      • Aggregate a Stream in a Tumbling Window
      • Combine Streams and Track Most Recent Records
      • Compare Current and Previous Values in a Stream
      • Configure a Dead Letter Queue
      • Convert the Serialization Format of a Topic
      • Create a Process Table Function
      • Create a UDF
      • Deduplicate Rows in a Table
      • Deploy a Statement with CI/CD
      • Evolve a Streaming Pipeline
      • Generate Custom Sample Data
      • Handle Late-Arriving Data
      • Handle Multiple Event Types
      • Log Debug Messages in UDFs
      • Mask Fields in a Table
      • Read and Write Custom Changelog Formats
      • Read Records without a Schema ID Prefix
      • Profile a Query
      • Resolve Statement Issues
      • Scan and Summarize Tables
      • Run a Snapshot Query
      • Transform a Topic
      • Use Client-Side Field Level Encryption
      • View Time Series Data
    • Operate and Deploy
      • Overview
      • Carry-over Offsets
      • Deploy with dbt
      • Deploy Table API Programs
      • Development Lifecycle
      • Enable Private Networking
      • Generate a Flink API Key
      • Grant Role-Based Access
      • Manage Compute Pools
      • Manage Connections
      • Manage with Terraform
      • Monitor and Manage Statements
      • Move SQL Statements to Production
      • Use the Query Profiler
      • REST API
    • Flink Reference
      • Overview
      • SQL Syntax
      • DDL Statements
        • Statements Overview
        • ALTER AGENT
        • ALTER CONNECTION
        • ALTER MODEL
        • ALTER MATERIALIZED TABLE
        • ALTER TABLE
        • ALTER TOOL
        • ALTER VIEW
        • CREATE AGENT
        • CREATE CONNECTION
        • CREATE FUNCTION
        • CREATE MATERIALIZED TABLE
        • CREATE MODEL
        • CREATE OR ALTER MATERIALIZED TABLE
        • CREATE TABLE
        • CREATE TOOL
        • CREATE VIEW
        • DESCRIBE
        • DROP AGENT
        • DROP CONNECTION
        • DROP FUNCTION
        • DROP MATERIALIZED TABLE
        • DROP MODEL
        • DROP TABLE
        • DROP TOOL
        • DROP VIEW
        • HINTS
        • EXPLAIN
        • RESET
        • SET
        • SHOW
        • USE CATALOG
        • USE database_name
      • DML Statements
        • Queries Overview
        • Deduplication
        • Group Aggregation
        • INSERT INTO FROM SELECT
        • INSERT VALUES
        • Joins
        • LIMIT
        • Pattern Recognition
        • ORDER BY
        • OVER Aggregation
        • SELECT
        • Set Logic
        • EXECUTE STATEMENT SET
        • Top-N
        • Window Aggregation
        • Window Deduplication
        • Window Join
        • Window Top-N
        • Window Table-Valued Function
        • WITH
      • Functions
        • AI Model Inference
        • Aggregate
        • Built-in PTFs
        • Collections
        • Comparison
        • Conditional
        • Datetime
        • Flink SQL Functions
        • Hashing
        • JSON
        • ML Preprocessing
        • Numeric
        • Search
        • String
        • Table API
      • Data Types
      • Data Type Mappings
      • Time Zone
      • Keywords
      • Information Schema
      • Example Streams
      • Supported Cloud Regions
      • SQL Examples
      • Table API
      • CLI Reference
    • Get Help
    • FAQ
  • Manage Networking
    • Confluent Cloud Networking Overview
    • Networking on AWS
      • AWS Networking Overview
      • Public Networking on AWS
      • Confluent Cloud Network on AWS
      • PrivateLink on AWS
        • PrivateLink Overview
        • Inbound PrivateLink for Dedicated Clusters
        • Inbound PrivateLink for Serverless Products
        • Outbound PrivateLink for Dedicated Clusters
        • Outbound PrivateLink for Serverless Products
      • VPC Peering on AWS
      • Transit Gateway on AWS
      • Private Network Interface on AWS
      • DNS Forwarding on AWS
    • Networking on Azure
      • Azure Networking Overview
      • Public Networking on Azure
      • Confluent Cloud Network on Azure
      • Private Link on Azure
        • Private Link Overview
        • Inbound Private Link for Dedicated Clusters
        • Inbound Private Link for Serverless Products
        • Outbound Private Link for Dedicated Clusters
        • Outbound Private Link for Serverless Products
      • VNet Peering on Azure
    • Networking on Google Cloud
      • Google Cloud Networking Overview
      • Public Networking on Google Cloud
      • Confluent Cloud Network on Google Cloud
      • Private Service Connect on Google Cloud
        • Private Service Connect Overview
        • Inbound Private Service Connect for Dedicated Clusters
        • Inbound Private Service Connect for Serverless Products
        • Outbound Private Service Connect for Dedicated Clusters
      • VPC Peering on Google Cloud
    • Connectivity for Confluent Resources
      • Overview
      • Public Egress IP Address for Connectors and Cluster Linking
      • Cluster Linking using AWS PrivateLink
      • Follower Fetching using AWS VPC Peering
    • Use the Confluent Cloud Console with Private Networking
    • Test Connectivity
    • Networking FAQ
  • Log and Monitor
    • Metrics
    • Integrate Third-Party Monitoring Tools
    • Manage Notifications
    • Monitor Consumer Lag
    • Monitor Dedicated Clusters
      • Manage Performance and Expansion
      • Track Usage by Team
    • Export Logs to Third-Party Tools
    • Tutorials and Examples
      • Run Example Queries
      • Observability for Kafka Clients
    • FAQ
  • Manage Security
    • Overview
    • Manage Authentication
      • Overview
      • Manage User Identities
        • Overview
        • Manage User Accounts
          • Overview
          • Authentication Security Protections
          • Manage Local User Accounts
          • Multi-factor Authentication
          • Manage SSO User Accounts
        • Manage User Identity Providers
          • Overview
          • Use Single Sign-On (SSO)
          • Manage SAML Single Sign-On (SSO)
          • Manage Azure Marketplace SSO
          • Just-in-time User Provisioning
          • Group Mapping
            • Overview
            • Enable Group Mapping
            • Manage Group Mappings
            • Troubleshooting
            • Best Practices
          • Manage Trusted Domains
          • Manage SSO provider
          • Troubleshoot SSO
      • Manage Workload Identities
        • Overview
        • Manage Workload Identities
        • Manage Service Accounts and API Keys
          • Overview
          • Create Service Accounts
          • Manage Service Accounts
          • Manage API Keys
            • Overview
            • Manage API keys
            • Best Practices
            • Troubleshoot
        • Manage OAuth/OIDC Identity Providers
          • Overview
          • Add an OIDC Identity Provider
          • Use OAuth Identity Pools and Filters
          • Manage Identity Provider Configurations
          • Manage the JWKS URI
          • Configure OAuth Clients
            • Overview
            • Go Clients
            • Java Clients
            • JavaScript Clients
            • .NET Clients
            • Python Clients
            • Configuration Reference
            • Configure UAMI
            • Configure AWS IAM Java Client Plugin
            • Configure AWS IAM Python Client Plugin
            • Configure AWS IAM .NET Client Plugin
          • Access Kafka REST APIs
          • Use Confluent STS Tokens with REST APIs
          • Best Practices
          • Troubleshoot OAuth Issues
        • Manage mTLS Identity Providers
          • Overview
          • Configure mTLS
          • Manage Certificate Authorities
          • Manage Certificate Identity Pools
          • Create CEL Filters for mTLS
          • Create JSON payloads for mTLS
          • Manage Certificate Revocation
          • Troubleshoot mTLS Issues
    • Control Access
      • Overview
      • Resource Hierarchy
        • Overview
        • Organizations
          • Overview
          • Manage Multiple Organizations
        • Environments
        • Confluent Resource Names (CRNs)
      • Manage Role-Based Access Control
        • Overview
        • Predefined RBAC Roles
        • Manage Role Bindings
        • Use ACLs with RBAC
      • Manage IP Filtering
        • Overview
        • Manage IP Groups
        • Manage IP Filters
        • Best Practices
      • Manage Access Control Lists
        • Overview
        • Operations
        • Examples
        • Troubleshoot
        • Reference
      • Use the Confluent CLI with multiple credentials on Confluent Cloud
    • Encrypt and Protect Data
      • Overview
      • Manage Data in Transit With TLS
      • Use Self-Managed Encryption Keys
        • Overview
        • Use Self-Managed Encryption Keys on AWS
        • Use Self-Managed Encryption Keys on Azure
        • Use Self-Managed Encryption Keys on Google Cloud
        • Manage Key Policies
          • Overview
          • AWS
          • Azure
          • Google Cloud
        • Use Self-Managed Encryption Keys with Tableflow
        • Use Pre-BYOK-API-V1 Self-Managed Encryption Keys
        • Use Confluent CLI for Self-Managed Encryption Keys
        • Use BYOK API for Self-Managed Encryption Keys
        • Revoke Access to Data at Rest
        • Best Practices
        • Troubleshoot Key Policy Issues
      • Use Client-Side Field Level Encryption
        • Overview
        • Manage CSFLE using Confluent Cloud Console
        • Use Client-side Field Level Encryption
        • Configuration Settings
        • Manage Encryption Keys
        • Quick Start
        • Implement a Custom KMS Driver
        • Process Encrypted Data with Apache Flink
        • Code examples
        • Troubleshoot
        • FAQ
      • Use Client-Side Payload Encryption
    • Monitor Activity
      • Concepts
      • Audit Log Event Categories
      • Audit Log Event Records
      • Audit Log Event Schema
      • Auditable Event Methods
        • Access Transparency
        • Connector
        • Custom Connector Plugin
        • Endpoints
        • Flink Management and Operations
        • Flink Authentication and Authorization
        • IP Filter Authorization
        • Kafka Cluster Management and Operations
        • Kafka Cluster Authentication and Authorization
        • ksqlDB Cluster Authentication and Authorization
        • Networking
        • Notifications Service
        • OAuth-OIDC Identity Provider and Identity Pool
        • Organization
        • Role-Based Access Control
        • Real-Time Context Engine
        • Schema Registry Management and Operations
        • Schema Registry Authentication and Authorization
        • Tableflow Control Plane
        • Tableflow Data Plane
        • Unified Stream Manager Control Plane
      • Access and Consume Audit Logs
      • Access Transparency
      • Retain Audit Logs
      • Best Practices
      • Troubleshoot
    • Access Management Tutorial
  • Manage Billing
    • Overview
    • Billing Dimensions
    • Invoices and Costs
    • Cost Allocation
    • Amazon Web Services
      • Pay As You Go
      • Commitments
    • Google Cloud
      • Pay as you Go
      • Commitments
      • Professional Services
    • Microsoft Azure
      • Pay As You Go
      • Commitments
      • Jio Commitments
      • Professional Services
    • Marketplace Organization Suspension and Deactivation
    • Troubleshoot Billing
    • FAQ
    • Legacy Billing Reference
  • Manage Service Quotas
    • Overview
    • Service Quotas
    • View Service Quotas Using Confluent CLI
    • Service Quotas API
  • APIs
    • Overview
    • Confluent Cloud API Usage and Reference
      • Overview
      • Confluent Cloud API Reference
      • Metrics API Reference
      • Admin and Produce REST API Usage
      • Connect API Usage
      • Provider Integration API Usage
      • Stream Catalog REST API Usage
      • Service Quotas API Usage
    • Kafka Client API Reference
      • Overview
      • .NET Client API Reference
      • C++ Client API Reference
      • Go Client API Reference
      • Java Client API Reference
      • JavaScript Client API Reference
      • Python Client API Reference
    • Flink Client API Usage and Reference
    • GraphQL API Usage and Reference
  • Confluent CLI
  • Release Notes & FAQ
    • Release Notes
    • FAQ
    • Upgrade Policy
    • Compliance
    • Generate a HAR file for Troubleshooting
    • AI Assistant
  • Support
  • Glossary

Link Self-Managed and Confluent Cloud Clusters for Hybrid Cloud and Bridge-to-Cloud Deployments

This tutorial shows how to use Cluster Linking for hybrid use cases that link Confluent Platform and Confluent Cloud clusters.

What the tutorial covers

By the end of this tutorial, you have configured two clusters, one on Confluent Platform and one on Confluent Cloud, and used Cluster Linking to share topic data bidirectionally across the clusters, without opening your firewall to Confluent Cloud.

You create a deployment with data flowing in both directions:

  • From Confluent Cloud to Confluent Platform.

  • From Confluent Platform to Confluent Cloud.

    • If you mirror from Confluent Platform to Confluent Cloud, you need a source-initiated cluster link: a cluster link where Confluent Platform initiates the connection to Confluent Cloud, so you don’t have to open your firewall to Confluent Cloud. Source-initiated links require Confluent Platform 7.1.0 or later.

      Diagram of a source-initiated cluster link, in which Confluent Platform initiates the connection to Confluent Cloud

In both cases, Confluent Platform brokers initiate the connection to Confluent Cloud brokers, so you don’t have to open your firewall to let Confluent Cloud connect to your Confluent Platform brokers.

In the process, you create security credentials and configuration files to use with the Confluent Platform and Confluent Cloud commands. For a list of these, see the Configuration summary at the end of this tutorial.

To see what clusters can use Cluster Linking, see Supported Cluster Types.

Diagram of bidirectional Cluster Linking between a Confluent Platform cluster and a Confluent Cloud cluster

Install Confluent Platform and configure environment variables

  1. Download and extract Confluent Platform version 7.1.0 or later. For install options, see Install instructions for self-managed deployments.

  2. Configure environment variables.

    The rest of the tutorial uses the following environment variables for KRaft mode:

    export CONFLUENT_HOME=<cp_installation_directory>
    
    export CONFLUENT_CONFIG=$CONFLUENT_HOME/etc/kafka
    

    Important

    Add the preceding two exports to your .bashrc or .bash_profile file so that your shell runs them whenever you open a new terminal window.

About prerequisites and command examples

Note

As a general guideline that applies beyond this tutorial, any customer-owned firewall that allows the cluster link connection from source cluster brokers to destination cluster brokers must allow the Transmission Control Protocol (TCP) connection to persist for Cluster Linking to work.

Before you start, make sure that you meet the following requirements:

  • These instructions assume you have a local installation of Confluent Platform 7.1.0 or later. Confluent Platform requires Java 8, 11, or 17. Java 17 is the recommended version. The documentation provides Install instructions for self-managed deployments. If you are new to Confluent Platform, first work through the Quick Start for Apache Kafka using Confluent Platform or the basic Cluster Linking tutorial, and then return to this tutorial.

  • This tutorial and the source-initiated link feature require Confluent Enterprise, and are not supported in Confluent Community or Apache Kafka®.

  • With a default installation of Confluent Platform, the Confluent CLI and Cluster Linking commands are available in $CONFLUENT_HOME/bin, and properties files are in the $CONFLUENT_CONFIG directory ($CONFLUENT_HOME/etc/kafka/). You must have Confluent Platform running to access these commands. After you configure and start Confluent Platform, you can type any command with no arguments to get help (for example, kafka-cluster-links).

  • This tutorial requires a Confluent Cloud login and the Confluent CLI. To learn more, see Get the latest version of Confluent Cloud in the Confluent Cloud Cluster Linking Quick Start and Migrate Confluent CLI. If you are new to Confluent Cloud, walk through that quick start first, and then return to this tutorial.

  • This tutorial requires that you run a Dedicated cluster in Confluent Cloud, which incurs Confluent Cloud charges.

  • The parameter password.encoder.secret encrypts the credentials that Confluent Platform stores in the cluster link. ZooKeeper, as supported on Confluent Platform versions earlier than 8.0, requires this parameter, as does migrating from ZooKeeper to KRaft, as described in What’s supported. To learn more about this parameter, see Multi-Region Clusters.

KRaft and ZooKeeper support in this tutorial

The metadata mode you can run depends on your Confluent Platform version.

Important

As of Confluent Platform 8.0, ZooKeeper is no longer available for new deployments. As a best practice, migrate to KRaft mode for new deployments. To learn more about running Kafka in KRaft mode, see KRaft Overview and the KRaft steps in the Platform Quick Start. To learn about migrating from older versions, see Migrate from ZooKeeper to KRaft on Confluent Platform. This tutorial covers KRaft mode only.

Earlier versions of this documentation provide examples for both KRaft and ZooKeeper.

For KRaft, the examples show a combined mode configuration, where for each cluster the broker and controller run on the same server. Combined mode is not intended for production use, but this tutorial uses it for simplicity. If you want to run controllers and brokers on separate servers, use KRaft in isolated mode. To learn more, see KRaft Overview and KRaft mode under Configure Confluent Platform for production.

Configure Kafka brokers and controllers

Create and update the following configuration files. A summary of server configurations and files appears at the end of this topic.

Make sure you have set the environment variables as described in Install Confluent Platform and configure environment variables. The rest of the tutorial uses these variables.

Port mapping

The example deployment in this tutorial uses the following default port and feature configurations, and assumes that services run on localhost.

Component

Confluent Platform

Kafka broker

9092

KRaft controller

9093

  • This tutorial uses these example ports. Cluster Linking does not require you to use these ports. Confluent Cloud assigns its own endpoints.

  • If you have other processes using these ports, either quit the other processes or change the tutorial steps to use different ports.

Configure ports, data directories, authentication, and cluster links

The following steps describe how to set up your Kafka brokers and controllers for KRaft mode. Configure the following files in $CONFLUENT_CONFIG to set up the Confluent Platform cluster.

  1. Copy $CONFLUENT_CONFIG/server.properties to use as a basis for server-clusterlinking.properties:

    cp $CONFLUENT_CONFIG/server.properties $CONFLUENT_CONFIG/server-clusterlinking.properties
    
  2. Change the listeners and advertised.listeners configurations to use SASL_PLAINTEXT instead of the default PLAINTEXT. You can update both of these configurations simultaneously with the following command:

    sed -i '' -e "s/listeners=PLAINTEXT/listeners=SASL_PLAINTEXT/g" $CONFLUENT_CONFIG/server-clusterlinking.properties
    
  3. Change the inter.broker.listener.name configuration to use SASL_PLAINTEXT instead of the default PLAINTEXT:

    sed -i '' -e "s/inter.broker.listener.name=PLAINTEXT/inter.broker.listener.name=SASL_PLAINTEXT/g" $CONFLUENT_CONFIG/server-clusterlinking.properties
    
  4. Make the following update to the advertised.listeners port configuration:

    sed -i '' -e "s/your.host.name:9092/:9092/g" $CONFLUENT_CONFIG/server-clusterlinking.properties
    
  5. Update Kafka data directories:

    sed -i '' -e "s/kraft-combined-logs/kraft-combined-logs-1/g" $CONFLUENT_CONFIG/server-clusterlinking.properties
    
  6. Append the following lines to the end of the server properties file to set the configurations specific to Cluster Linking.

    The last configuration option, password.encoder.secret, is required only for the ZooKeeper mode that earlier versions of Confluent Platform support. KRaft does not need it, as explained in What’s supported.

    echo "sasl.enabled.mechanisms=SCRAM-SHA-512" >> $CONFLUENT_CONFIG/server-clusterlinking.properties
    
    echo "sasl.mechanism.inter.broker.protocol=SCRAM-SHA-512" >> $CONFLUENT_CONFIG/server-clusterlinking.properties
    
    echo "listener.name.sasl_plaintext.scram-sha-512.sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required username="kafka" password="kafka-secret";" >> $CONFLUENT_CONFIG/server-clusterlinking.properties
    
    echo "confluent.reporters.telemetry.auto.enable=false" >> $CONFLUENT_CONFIG/server-clusterlinking.properties
    
    echo "confluent.cluster.link.metadata.topic.replication.factor=1" >> $CONFLUENT_CONFIG/server-clusterlinking.properties
    
    echo "confluent.cluster.link.enable=true" >> $CONFLUENT_CONFIG/server-clusterlinking.properties
    
    echo "password.encoder.secret=encoder-secret" >> $CONFLUENT_CONFIG/server-clusterlinking.properties
    

Tip

  • If you check your server-clusterlinking.properties file after these edits, you should see the preceding lines indicating security protocols at the end of the file, and the other configurations updated per the previous steps.

  • This example configures only one Confluent Server broker, secured with SASL/SCRAM authentication, along with one KRaft controller. The local listener uses SASL_PLAINTEXT, so traffic to it is authenticated but not encrypted. This configuration works for local testing. In a production setting, use more brokers and the requisite KRaft controllers, spread across different machines for fault tolerance and high availability. Secure all of them with authentication and encryption.

  • This example sets the replication factors for the internal topics that the tutorial creates to 1, because this is a testing setup with only one broker. For production deployments, do not set the replication factor of these topics to 1. Set the replication factor to three or more, depending on the number of brokers.

  • On Confluent Platform versions earlier than 8.0 that use ZooKeeper, the parameter password.encoder.secret encrypts the credentials that Confluent Platform stores in the cluster link. The ZooKeeper mode that these earlier versions support requires this parameter, as does migrating from ZooKeeper to KRaft, as described in What’s supported. KRaft mode in Confluent Platform 8.0 or later does not require it. To learn more, see Multi-Region Clusters.

Format storage and create cluster credentials

This section formats the log directories for the server, creates SASL/SCRAM credentials on the Confluent Platform cluster, and creates the CP-command.config file that authenticates the commands you run against the cluster. To learn more about authenticating to Confluent Platform clusters, see Configure SASL/SCRAM authentication for Confluent Platform.

  1. Change directories to $CONFLUENT_HOME, the top of your Confluent Platform installation directory. You must run the kafka-storage commands in the following steps from this directory.

    cd $CONFLUENT_HOME
    
  2. Generate a random-uuid using the kafka-storage tool:

    KAFKA_CLUSTER_ID="$(bin/kafka-storage random-uuid)"
    
  3. Format log directories for this server and create SASL/SCRAM credentials on the cluster: a kafka user for the Kafka cluster itself and an admin user for running commands against the cluster. For KRaft, you must apply both credentials together in a single command.

    bin/kafka-storage format -t $KAFKA_CLUSTER_ID -c $CONFLUENT_CONFIG/server-clusterlinking.properties -S 'SCRAM-SHA-512=[name=kafka,iterations=8192,password=kafka-secret]' -S 'SCRAM-SHA-512=[name=admin,iterations=8192,password=admin-secret]' --ignore-formatted --standalone
    

    Tip

    The kafka-storage command runs only once per broker or controller. You cannot use this command to update an existing cluster. If you configure something incorrectly here, you must recreate the directories from scratch and work through the steps again.

  4. Create a file with the admin credentials to authenticate when you run commands against the Confluent Platform cluster.

    Open a text editor, create a file called $CONFLUENT_CONFIG/CP-command.config, and paste the following content:

    sasl.mechanism=SCRAM-SHA-512
    security.protocol=SASL_PLAINTEXT
    sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required \
          username="admin" \
          password="admin-secret";
    

Start the Confluent Platform cluster

Run the following commands in separate command windows.

The commands that run the KRaft controller and Kafka brokers do not complete until you stop them, so these windows must stay open while the applications are running.

Use another command window as your main terminal, in which you run commands that you expect to complete. Examples of these commands are kafka-configs, kafka-topics, and kafka-cluster-links, and in some cases kafka-console-producer and kafka-console-consumer, although you can leave those last two running.

Diagram of the command windows used in this tutorial, showing which windows stay open and which serve as the main terminal
  1. In a new command window, start a Confluent Server broker for the Confluent Platform cluster, passing the credentials as part of the command:

    kafka-server-start $CONFLUENT_CONFIG/server-clusterlinking.properties
    
  2. Get the Confluent Platform cluster ID:

    kafka-cluster cluster-id --bootstrap-server localhost:9092 --config $CONFLUENT_CONFIG/CP-command.config
    

    Your output should resemble the following:

    Cluster ID: G1pnOMOxSjWYIX8xuR2cfQ
    

    In this case, G1pnOMOxSjWYIX8xuR2cfQ is the Confluent Platform cluster ID, referred to in these examples as $CP_CLUSTER_ID.

    Optionally, set an environment variable in the local shell or in a zsh or bash profile so you can copy and paste commands in later steps:

    export CP_CLUSTER_ID=<cp_cluster_id>
    

Create or select a Confluent Cloud cluster

As noted in About prerequisites and command examples, this tutorial requires a Dedicated Confluent Cloud cluster with public internet access, which incurs charges. You can create one for this tutorial and then delete it when you finish the tutorial.

  1. Log in to Confluent Cloud with the Confluent CLI:

    confluent login
    
  2. View environments and select the one you want to use by environment ID:

    confluent environment list
    

    An asterisk in the list indicates the currently selected environment. You can select a different environment as follows:

    confluent environment use <environment_id>
    
  3. Use an existing Dedicated cluster in Confluent Cloud, or create a new one either in the Confluent Cloud Console (log in to Confluent Cloud) or directly with the Confluent CLI, as shown in the following command:

    confluent kafka cluster create CLOUD-DEMO --type dedicated --cloud aws --region us-east-1 --cku 1 --availability single-zone
    

    Your output should resemble the following:

    It may take up to 5 minutes for the Kafka cluster to be ready.
    +--------------+---------------+
    | Id           | lkc-59oyn     |
    | Name         | CLOUD-DEMO    |
    | Type         | DEDICATED     |
    | Ingress      |            50 |
    | Egress       |           150 |
    | Storage      | Infinite      |
    | Provider     | aws           |
    | Availability | single-zone   |
    | Region       | us-east-1     |
    | Status       | PROVISIONING  |
    | Endpoint     |               |
    | ApiEndpoint  |               |
    | RestEndpoint |               |
    | ClusterSize  |             1 |
    +--------------+---------------+
    

    If you created a new Confluent Cloud cluster, wait for Confluent Cloud to provision the cluster. Provisioning typically takes a few minutes, but can take longer. Confluent notifies you by email when the cluster is ready to use.

  4. View your clusters:

    confluent kafka cluster list
    

    An asterisk indicates the currently selected cluster. You can select a different cluster as follows:

    confluent kafka cluster use <cc_cluster_id>
    

    Tip

    To act on a cluster that is not currently selected, specify its cluster ID. For example, confluent kafka cluster describe <cluster_id>.

  5. Note the cluster ID for your Dedicated cluster, referred to as $CC_CLUSTER_ID in this tutorial.

    Optionally, set an environment variable in the local shell or in a zsh or bash profile so you can copy and paste commands in later steps:

    export CC_CLUSTER_ID=<cc_cluster_id>
    

Populate the Confluent Platform cluster

With both clusters running, this section creates a topic on the Confluent Platform cluster, produces sample messages to it, and consumes them to verify data flow. These steps use the Kafka command-line tools bundled with Confluent Platform.

  1. Create a topic on the Confluent Platform cluster with a single partition so ordering is easier to see:

    kafka-topics --create --topic from-on-prem --partitions 1 --replication-factor 1 --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

    You should get confirmation that the topic was created.

    Created topic from-on-prem.
    

    You can get a list of existing topics as follows:

    kafka-topics --list --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

    To get detailed information about a topic, use the --describe option:

    kafka-topics --describe --topic from-on-prem --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    
  2. Produce messages to the from-on-prem topic on the source cluster:

    seq 1 5 | kafka-console-producer --topic from-on-prem --bootstrap-server localhost:9092 --producer.config $CONFLUENT_CONFIG/CP-command.config
    

    The command should terminate without any output.

  3. Consume from the topic on the source cluster.

    Run a consumer to read messages from the from-on-prem topic:

    kafka-console-consumer --topic from-on-prem --from-beginning --bootstrap-server localhost:9092 --consumer.config $CONFLUENT_CONFIG/CP-command.config
    

    If the consumer reads the messages, your output resembles the following:

    1
    2
    3
    4
    5
    

    Press Ctrl+C to return to the prompt.

Create an API key for the Confluent Cloud cluster

Create an API key so that Confluent Platform can authenticate to your Confluent Cloud cluster when it mirrors data to it.

  1. Create a user API key for the Confluent Cloud cluster that acts as the destination for Confluent Platform to Confluent Cloud topic data mirroring:

    confluent api-key create --resource $CC_CLUSTER_ID
    
  2. Save the resulting API key and secret in a safe place. This tutorial refers to these as <cc_link_api_key> and <cc_link_api_secret>. Use this API key and secret, which belong to the Confluent Cloud cluster, to create the Confluent Platform to Confluent Cloud link. You add these to a configuration file in the next step.

    Important

    If you are setting this up in production, use a service account API key instead of a user-associated key.

    The topic data sharing tutorial explains how to set up privileges to access Confluent Cloud clusters with a service account. For source-initiated links, the only access control list (ACL) your service account needs is ALTER on the destination cluster (Cluster: Alter ACL). To learn more about ACLs for cluster linking, see Security for Cluster Linking on Confluent Platform and Security for Cluster Linking on Confluent Cloud.

Mirror data from Confluent Platform to Confluent Cloud

The following sections set up and test a cluster link that mirrors data from Confluent Platform to Confluent Cloud.

Tip

To mirror consumer group offsets, you must enable consumer offset sync and pass in a JSON file that identifies which groups to sync, excluding any groups already used on the destination. This tutorial does not show that configuration.

Create the Confluent Platform to Confluent Cloud link

Set up the cluster link that mirrors data from Confluent Platform to Confluent Cloud.

Tip

This tutorial shows how to create a cluster link from Confluent Platform to Confluent Cloud. You can use the same general configuration if the destination is Confluent Platform 7.0 or later. You would create the cluster link in the same way.

This is a source-initiated link, meaning that its connection comes from Confluent Platform and goes to Confluent Cloud, so you don’t have to open your on-premises firewall.

To create this source-initiated link, you must create both halves of the cluster link: the first half on Confluent Cloud and the second half on Confluent Platform.

  1. Create a cluster link on the Confluent Cloud cluster.

    1. Create a link configuration file $CONFLUENT_CONFIG/clusterlink-hybrid-dst.config with the following entries:

      link.mode=DESTINATION
      connection.mode=INBOUND
      

      The combination of the configurations link.mode=DESTINATION and connection.mode=INBOUND tells the cluster link that it is the destination half of a source-initiated cluster link. You must use these two configurations together.

      This example assumes a single listener. If you configure multiple listeners (for example, INTERNAL, REPLICATION, and EXTERNAL) and want to switch to a listener other than the default, add one more parameter to the configuration: local.listener.name=EXTERNAL. To learn more, see the Confluent Platform documentation on Configuration Options and Understanding Listeners in Cluster Linking.

      If you want to add any configurations to your cluster link, such as consumer offset sync or auto-create mirror topics, add them to clusterlink-hybrid-dst.config. Cluster link configurations are always set on the destination cluster link, not the source cluster link.

    2. Create the destination cluster link on Confluent Cloud:

      confluent kafka link create from-on-prem-link --cluster $CC_CLUSTER_ID \
        --source-cluster $CP_CLUSTER_ID \
        --config-file $CONFLUENT_CONFIG/clusterlink-hybrid-dst.config
      

      Tip

      --source-cluster-id was replaced with --source-cluster in version 3 of confluent CLI, as described in the command reference for confluent kafka link create.

      The output from this command should indicate that the link was created.

      Created cluster link "from-on-prem-link".
      

      Tip

      You can list the cluster links and their configurations on Confluent Cloud with the following commands:

      confluent kafka link list --cluster $CC_CLUSTER_ID
      
      confluent kafka --cluster $CC_CLUSTER_ID link configuration list <link_name>
      
  2. Create a security credential for the cluster link on Confluent Platform. Confluent Platform uses this credential to read topic data and metadata from the source cluster.

    kafka-configs --bootstrap-server localhost:9092 --alter --add-config \
      'SCRAM-SHA-512=[iterations=8192,password=1LINK2RUL3TH3MALL]' \
      --entity-type users --entity-name cp-to-cloud-link \
      --command-config $CONFLUENT_CONFIG/CP-command.config
    

    Your output should resemble the following:

    Completed updating config for user cp-to-cloud-link.
    
  3. Create a link configuration file $CONFLUENT_CONFIG/clusterlink-CP-src.config for the source cluster link on Confluent Platform with the following entries:

    link.mode=SOURCE
    connection.mode=OUTBOUND
    
    bootstrap.servers=<cc_bootstrap_server>
    ssl.endpoint.identification.algorithm=https
    security.protocol=SASL_SSL
    sasl.mechanism=PLAIN
    sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username='<cc_link_api_key>' password='<cc_link_api_secret>';
    
    local.listener.name=SASL_PLAINTEXT
    local.security.protocol=SASL_PLAINTEXT
    local.sasl.mechanism=SCRAM-SHA-512
    local.sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required username="cp-to-cloud-link" password="1LINK2RUL3TH3MALL";
    
    • The combination of the configurations link.mode=SOURCE and connection.mode=OUTBOUND tells the cluster link that it is the source half of a source-initiated cluster link. You must use these configurations together.

    • The middle section tells the cluster link the bootstrap.servers of the Confluent Cloud destination cluster to reach out to, and the authentication credentials to use. Cluster Linking to Confluent Cloud uses TLS and SASL_PLAIN. The Confluent Cloud cluster requires these credentials to accept the incoming request. The Confluent Cloud bootstrap server appears as the Endpoint in the output of confluent kafka cluster describe $CC_CLUSTER_ID, or in the cluster settings in the Confluent Cloud Console. If you use the Endpoint from the Confluent CLI output, remove the protocol prefix. For example, if the endpoint shows as SASL_SSL://pkc-r2ymk.us-east-1.aws.confluent.cloud:9092, your entry in $CONFLUENT_CONFIG/clusterlink-CP-src.config is bootstrap.servers=pkc-r2ymk.us-east-1.aws.confluent.cloud:9092.

    • The last section, where each line starts with local, contains the security credentials that the source Confluent Platform cluster uses to read data.

    • The authentication mechanisms and security protocols for Confluent Platform map to what you define for the brokers and controllers. Those for Confluent Cloud map to what you define in a file called clusterlink-cloud-to-CP.config in a later step (see Create the Confluent Cloud to Confluent Platform link). To learn more about the authentication and security protocols used, see Configure SASL/SCRAM authentication for Confluent Platform, and the JAAS section in particular.

    Caution

    Do not add cluster link configurations, such as consumer offset sync or auto-create mirror topics, to clusterlink-CP-src.config. Set these configurations on the destination cluster link, not the source cluster link.

  4. Create the source cluster link on Confluent Platform by running the following command with the configuration file from the previous step:

    kafka-cluster-links --bootstrap-server localhost:9092 \
         --create --link from-on-prem-link \
         --config-file $CONFLUENT_CONFIG/clusterlink-CP-src.config \
         --cluster-id $CC_CLUSTER_ID --command-config $CONFLUENT_CONFIG/CP-command.config
    

    Your output should resemble the following:

    Cluster link 'from-on-prem-link' creation successfully completed.
    

    Tip

    • You can list cluster links on Confluent Platform with this command:

      kafka-cluster-links --list --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
      
    • To create the cluster link on Confluent Platform, you use the kafka-cluster-links tool rather than the Confluent CLI that you used for Confluent Cloud.

Create a mirror topic and verify data on Confluent Cloud

While logged in to Confluent Cloud, create a mirror topic of the Confluent Platform from-on-prem topic, and then verify that the mirrored data arrives.

Note

  • When you use Schema Linking with a mirror topic that has a schema, and you want to use that topic with Confluent Cloud ksqlDB, broker-side schema ID validation, or the topic viewer, make sure that Schema Linking puts the schema in the default context of the Confluent Cloud Schema Registry. To learn more, see How Schemas work with Mirror Topics.

  • Before you run the first command in the following steps, make sure that you are still logged in to Confluent Cloud and have the appropriate environment and cluster selected. To list and select these resources, use the commands confluent environment list, confluent environment use, confluent kafka cluster list, and confluent kafka cluster use. An asterisk in the output of the list commands indicates the selected environment or cluster. If you select no resources, or the wrong ones, the commands don’t work.

  1. Create a mirror topic.

    A mirror topic is a read-only copy of a source topic that a cluster link keeps continuously in sync. The following command establishes a mirror of the original from-on-prem topic, using the cluster link from-on-prem-link:

    confluent kafka mirror create from-on-prem --link from-on-prem-link
    

    Your output should resemble the following:

    Created mirror topic "from-on-prem".
    
    • The mirror topic name must match the original topic name. To learn more, see Known Limitations.

    • A mirror topic must specify the link to its source topic at creation time. Specifying the link at creation time ensures that the mirror topic starts as a clean slate, with no conflicting data or metadata.

  2. List the mirror topics on the link:

    confluent kafka mirror list --cluster $CC_CLUSTER_ID
    

    Your output should resemble the following:

          Link Name     | Mirror Topic Name | Num Partition | Max Per Partition Mirror Lag | Source Topic Name | Mirror Status | Status Time Ms
    +-------------------+-------------------+---------------+------------------------------+-------------------+---------------+----------------+
      from-on-prem-link | from-on-prem      |             1 |                            0 | from-on-prem      | ACTIVE        |  1633640214250
    
  3. Consume from the mirror topic on the destination cluster to verify that mirroring works.

    Still on Confluent Cloud, run a consumer on the mirror topic to read the messages you originally produced to the Confluent Platform topic:

    confluent kafka topic consume from-on-prem --from-beginning
    

    Your output should resemble the following:

    1
    2
    3
    4
    5
    

    Note

    If you get a no API key selected for resource error when you run the consumer, run the following command to specify the <cc_api_key> for the Confluent Cloud destination cluster, and then run the consumer command again: confluent api-key use <cc_api_key> --resource $CC_CLUSTER_ID. You can also follow the instructions that the Confluent CLI provides with the error message.

Mirror data from Confluent Cloud to Confluent Platform

The following sections set up and test a cluster link that mirrors data from Confluent Cloud to Confluent Platform.

Tip

To mirror consumer group offsets, you must enable consumer offset sync and pass in a JSON file that identifies which groups to sync, excluding any groups already used on the destination. This tutorial does not show that configuration.

Create the Confluent Cloud to Confluent Platform link

  1. Create another user API key for this cluster link on your Confluent Cloud cluster:

    confluent api-key create --resource $CC_CLUSTER_ID
    

    The same cluster that served as the destination in the previous steps serves as the source cluster in the following steps, so you create a different API key and secret for the same cluster to serve in this new role.

  2. Save the resulting API key and secret in a safe place. This tutorial refers to these as <cc_src_api_key> and <cc_src_api_secret>. You add these to a configuration file in the next step.

    Important

    If you are setting this up in production, use a service account API key instead of a user-associated key. To do this, create a service account for your cluster link, give the service account the requisite ACLs, and then create an API key for the service account. As a best practice, give each cluster link its own API key and service account. The topic data sharing tutorial explains how to set up privileges to access Confluent Cloud clusters with a service account.

  3. Use confluent kafka cluster describe to get the Confluent Cloud cluster endpoint URL:

    confluent kafka cluster describe $CC_CLUSTER_ID
    

    The following steps refer to this endpoint URL as <cc_bootstrap_server>.

  4. Open a text editor and save your API key and secret, along with the following configuration entries, in a file called $CONFLUENT_CONFIG/clusterlink-cloud-to-CP.config that the Confluent Platform commands use to authenticate to Confluent Cloud.

    Add the following configuration entries:

    bootstrap.servers=<cc_bootstrap_server>
    security.protocol=SASL_SSL
    sasl.mechanism=PLAIN
    sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required username='<cc_src_api_key>' password='<cc_src_api_secret>';
    

    Tip

    • When you paste this content into a text editor, keep each statement on a single line. The last line, which starts with sasl.jaas.config=, must appear on a single line, as must the others. Supply values for your Confluent Cloud bootstrap server, API key, and secret, and then save the file.

    • The values for security.protocol and sasl.mechanism map to what you defined for Confluent Cloud in clusterlink-CP-src.config.

  5. Create the cluster link to Confluent Platform.

    If you want to follow this example exactly, name the cluster link from-cloud-link, although you can use any name. You use the cluster link name to create and manipulate mirror topics. You cannot rename a cluster link after you create it.

    The following command passes the Confluent Platform admin credentials with --command-config, as described in Setting Properties on a Cluster Link.

    kafka-cluster-links --bootstrap-server localhost:9092 \
          --create --link from-cloud-link \
          --config-file $CONFLUENT_CONFIG/clusterlink-cloud-to-CP.config \
          --cluster-id $CC_CLUSTER_ID --command-config $CONFLUENT_CONFIG/CP-command.config
    

    Your output should resemble the following:

    Cluster link 'from-cloud-link' creation successfully completed.
    
  6. Check that the link exists with the kafka-cluster-links --list command:

    kafka-cluster-links --list --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

    Your output should resemble the following, showing the from-on-prem-link link you created earlier along with the new from-cloud-link link:

    Link name: 'from-on-prem-link', link ID: '7eb4304e-b513-41d2-903e-147dea62a01c', remote cluster ID: 'lkc-1vgo6', local cluster ID: 'G1pnOMOxSjWYIX8xuR2cfQ'
    Link name: 'from-cloud-link', link ID: 'b1a56076-4d6f-45e0-9013-ff305abd0e54', remote cluster ID: 'lkc-1vgo6', local cluster ID: 'G1pnOMOxSjWYIX8xuR2cfQ'
    

Create topics and mirror data to Confluent Platform

  1. In Confluent Cloud, use the Confluent CLI to create a topic named cloud-topic with one partition:

    confluent kafka topic create cloud-topic --partitions 1
    
  2. In another command window on Confluent Cloud, start a producer that sends data to the cloud-topic topic:

    confluent kafka topic produce cloud-topic --cluster $CC_CLUSTER_ID
    
    • Verify that the producer has started. The following output indicates that the producer is ready:

      confluent kafka topic produce cloud-topic --cluster lkc-1vgo6
      Starting Kafka Producer. Use Ctrl-C or Ctrl-D to exit.
      
    • Type entries into the producer window and press Enter after each one:

      Riesling
      Pinot Blanc
      Verdejo
      
  3. Mirror the cloud-topic topic on Confluent Platform with the command kafka-mirrors --create --mirror-topic <topic_name>.

    The following command establishes a mirror of the original cloud-topic topic, using the cluster link from-cloud-link:

    kafka-mirrors --create --mirror-topic cloud-topic --link from-cloud-link --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

    You should get confirmation that the mirror topic was created.

    Created topic cloud-topic.
    
  4. On Confluent Platform, check the mirror topic status by running kafka-mirrors --describe on the from-cloud-link link:

    kafka-mirrors --describe --link from-cloud-link --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

    The output shows the status of any mirror topics on the specified link.

    Topic: cloud-topic        LinkName: from-cloud-link       LinkId: b1a56076-4d6f-45e0-9013-ff305abd0e54    MirrorTopic: cloud-topic        State: ACTIVE   StateTime: 2021-10-07 16:36:20
              Partition: 0    State: ACTIVE   DestLogEndOffset: 2     LastFetchSourceHighWatermark: 2 Lag: 0  TimeSinceLastFetchMs: 384566
    
  5. Consume the data from the on-premises mirror topic:

    kafka-console-consumer --topic cloud-topic --from-beginning --bootstrap-server localhost:9092 --consumer.config $CONFLUENT_CONFIG/CP-command.config
    

    Your output should match the entries you typed into the Confluent Cloud producer.

    Terminal windows showing messages produced on Confluent Cloud and consumed from the mirror topic on Confluent Platform
  6. View the configuration of your cluster link:

    kafka-configs --describe --cluster-link from-cloud-link --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

    The command lists the cluster link configurations. The following example shows part of the output.

    Dynamic configs for cluster-link from-cloud-link are:
    metadata.max.age.ms=300000 sensitive=false synonyms={}
    reconnect.backoff.max.ms=1000 sensitive=false synonyms={}
    auto.create.mirror.topics.filters= sensitive=false synonyms={}
    ssl.engine.factory.class=null sensitive=false synonyms={}
    sasl.kerberos.ticket.renew.window.factor=0.8 sensitive=false synonyms={}
    reconnect.backoff.ms=50 sensitive=false synonyms={}
    consumer.offset.sync.ms=30000 sensitive=false synonyms={}
    
    ...
    
    link.mode=DESTINATION sensitive=false synonyms={}
    security.protocol=SASL_SSL sensitive=false synonyms={}
    acl.sync.ms=5000 sensitive=false synonyms={}
    ssl.keymanager.algorithm=SunX509 sensitive=false synonyms={}
    sasl.login.callback.handler.class=null sensitive=false synonyms={}
    replica.fetch.max.bytes=5242880 sensitive=false synonyms={}
    availability.check.consecutive.failure.threshold=5 sensitive=false synonyms={}
    sasl.login.refresh.window.jitter=0.05 sensitive=false synonyms={}
    

Tear down the tutorial environment

When you finish the tutorial, clean up the environment in this order: stop the clients, promote the mirror topics, delete the topics, delete the cluster links, and stop Confluent Platform.

Stop consumers and producers

Stop consumers and producers with Ctrl+C in their command windows.

Promote mirror topics

Promote the mirror topics to regular topics.

  1. On Confluent Cloud, promote the mirror topic called from-on-prem:

    confluent kafka mirror promote from-on-prem --link from-on-prem-link --cluster $CC_CLUSTER_ID
    

    Your output should resemble the following:

     Mirror Topic Name | Partition | Partition Mirror Lag | Error Message | Error Code | Last Source Fetch Offset
    +-------------------+-----------+----------------------+---------------+------------+--------------------------+
     from-on-prem      |         0 |                    0 |               |            |                        9
    

    To verify that the mirroring stopped, run the preceding command again. You should get a message in the Error Message column saying that Topic 'from-on-prem' has already stopped its mirror from 'from-on-prem-link'.

  2. On Confluent Platform, promote the mirror topic called cloud-topic:

    kafka-mirrors --promote --topics cloud-topic --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

    Your output should resemble the following:

    Calculating max offset and ms lag for mirror topics: [cloud-topic]
    Finished calculating max offset lag and max lag ms for mirror topics: [cloud-topic]
    Request for stopping topic cloud-topics mirror was successfully scheduled. Please use the describe command with the --pending-stopped-only option to monitor progress.
    

    If you retry this command, you get an error indicating that the Topic 'cloud-topic' has already stopped its mirror 'from-cloud-link'.

Delete the source and mirror topics

Delete the topics that you created on both clusters.

Tip

  • To list the topics on Confluent Cloud: confluent kafka topic list

  • To list the topics on Confluent Platform: kafka-topics --list --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config

  1. Delete the topics on Confluent Cloud:

    confluent kafka topic delete cloud-topic
    
    confluent kafka topic delete from-on-prem
    
  2. Delete the topics on Confluent Platform:

    kafka-topics --delete --topic cloud-topic --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    
    kafka-topics --delete --topic from-on-prem --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
    

Delete the cluster links

  1. Delete the cluster links on Confluent Platform.

    • List the cluster links on Confluent Platform:

      kafka-cluster-links --list --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
      

      The output lists two links: one for the source-initiated link and one that acts as the destination for Confluent Cloud data:

      Link name: 'from-on-prem-link', link ID: '7eb4304e-b513-41d2-903e-147dea62a01c', remote cluster ID: 'lkc-1vgo6' local cluster ID: ', local cluster ID: 'G1pnOMOxSjWYIX8xuR2cfQ'' remote cluster available: 'true'
      Link name: 'from-cloud-link', link ID: 'b1a56076-4d6f-45e0-9013-ff305abd0e54', remote cluster ID: 'lkc-1vgo6' local cluster ID: ', local cluster ID: 'G1pnOMOxSjWYIX8xuR2cfQ'' remote cluster available: 'true'
      
    • Delete the cluster links on Confluent Platform with kafka-cluster-links --delete <link_name>:

      kafka-cluster-links --delete --link from-on-prem-link --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
      
      kafka-cluster-links --delete --link from-cloud-link --bootstrap-server localhost:9092 --command-config $CONFLUENT_CONFIG/CP-command.config
      

      Each command outputs confirmation that the link is deleted.

  2. Delete the cluster link on Confluent Cloud. Confluent Cloud holds only the destination half of the source-initiated link, so only one link appears here.

    • List the cluster links on Confluent Cloud:

      confluent kafka link list
      

      Your output should resemble the following:

            Link Name     |   Source Cluster Id
      +-------------------+------------------------+
        from-on-prem-link | G1pnOMOxSjWYIX8xuR2cfQ
      
    • Delete the cluster link on Confluent Cloud with confluent kafka link delete <link_name>:

      confluent kafka link delete from-on-prem-link
      

      The Confluent CLI confirms that the link is deleted.

Stop Confluent Platform

Stop the remaining components with Ctrl+C in their command windows, in the reverse order in which you started them. Stop the Kafka broker last. In KRaft combined mode, that completes the cleanup.

Configuration summary

Configure the following environment variables in every terminal window so that the tutorial works with KRaft mode. For more information, see Install Confluent Platform and configure environment variables.

  • CONFLUENT_HOME=<cp_installation_directory>

  • CONFLUENT_CONFIG=$CONFLUENT_HOME/etc/kafka

The tutorial also directs you to export CP_CLUSTER_ID and CC_CLUSTER_ID. These two variables are optional conveniences that let you copy and paste the later commands without editing them.

File

Purpose

server-clusterlinking.properties

Configuration file used for the Confluent Platform cluster startup, as described in Configure Kafka brokers and controllers

CP-command.config

  • Created in the steps to Format storage and create cluster credentials

  • Contains the admin user credentials to authenticate when you run commands against the Confluent Platform cluster

  • Used with the --command-config flag in Confluent Platform commands

clusterlink-hybrid-dst.config

  • Created in the steps to Create the Confluent Platform to Confluent Cloud link

  • Specifies the link configuration for the Confluent Cloud cluster to serve as the destination

  • Used to create the cluster link from-on-prem-link on the Confluent Cloud side

clusterlink-CP-src.config

  • Created in the steps to Create the Confluent Platform to Confluent Cloud link

  • Specifies the link configuration for the Confluent Platform cluster that serves as the source, and includes credentials and connection information for Confluent Platform to authenticate to Confluent Cloud

  • Used to create the cluster link from-on-prem-link on the Confluent Platform side

clusterlink-cloud-to-CP.config

  • Created in the steps to Create the Confluent Cloud to Confluent Platform link

  • Contains security credentials and connection information that the Confluent Platform commands use to authenticate to Confluent Cloud

  • Used to create the from-cloud-link on the Confluent Platform side

For a step-by-step guide to configuring all server properties, see Configure Kafka brokers and controllers.

Add the following configurations to the Kafka server properties file:

  • inter.broker.listener.name=SASL_PLAINTEXT

  • sasl.enabled.mechanisms=SCRAM-SHA-512

  • sasl.mechanism.inter.broker.protocol=SCRAM-SHA-512

  • listener.name.sasl_plaintext.scram-sha-512.sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required username="kafka" password="kafka-secret";

  • confluent.reporters.telemetry.auto.enable=false

  • confluent.cluster.link.enable=true

  • password.encoder.secret=encoder-secret — required when you use ZooKeeper on earlier versions of Confluent Platform where ZooKeeper is supported. Confluent Platform 8.0 and later running in KRaft mode does not require this configuration. To learn more, see What’s supported.

  • confluent.cluster.link.metadata.topic.replication.factor=1 — KRaft mode requires this explicit configuration.

Change the following configurations from their defaults in the Kafka server properties file:

  • listeners=SASL_PLAINTEXT://:9092

  • advertised.listeners=SASL_PLAINTEXT://:9092

  • log.dirs=/tmp/kafka-logs-1

Related content

  • Confluent Blog: The Link To Cloud: How to Build a Seamless and Secure Hybrid Data Bridge with Cluster Linking

  • Cloud Cluster Linking Quick Start (Confluent Cloud)

  • Security Considerations for Cluster Linking (Confluent Cloud)

  • Cluster Linking Security (Confluent Platform)

  • Share Data Across Clusters, Regions, and Clouds (Confluent Cloud) (In-depth tutorial, including how to set up service accounts for cluster links, a best practice for production-level deployments)

  • Cluster Linking Configuration, Commands, and Management (Confluent Cloud)

  • Tutorial: Using Cluster Linking for Topic Data Sharing (Confluent Platform)

  • Cluster Linking Commands Reference (Confluent Platform)

Was this doc page helpful?

Give us feedback

Do you still need help?

Confluent support portalAsk the community
Thank you. We'll be in touch!
Be the first to get updates and new content

By clicking "SIGN UP" you agree that your personal data will be processed in accordance with our Privacy Policy.

  • Confluent
  • About
  • Careers
  • Contact
  • Professional Services
  • Product
  • Confluent Cloud
  • Confluent Platform
  • Connectors
  • Flink
  • Stream Governance
  • Developer
  • Free Courses
  • Tutorials
  • Event Streaming Patterns
  • Documentation
  • Blog
  • Podcast
  • Community
  • Forum
  • Meetups
  • Kafka Summit
  • Catalysts
Terms & ConditionsPrivacy PolicyDo Not Sell My InformationModern Slavery PolicyCookie SettingsFeedback

Copyright © Confluent, Inc. 2014- Apache®️, Apache Kafka®️, Kafka®️, Apache Flink®️, Flink®️, Apache Iceberg®️, Iceberg®️ and associated open source project names are trademarks of the Apache Software Foundation

On this page:
  • What the tutorial covers
  • Install Confluent Platform and configure environment variables
  • About prerequisites and command examples
  • KRaft and ZooKeeper support in this tutorial
  • Configure Kafka brokers and controllers
  • Port mapping
  • Configure ports, data directories, authentication, and cluster links
  • Format storage and create cluster credentials
  • Start the Confluent Platform cluster
  • Create or select a Confluent Cloud cluster
  • Populate the Confluent Platform cluster
  • Create an API key for the Confluent Cloud cluster
  • Mirror data from Confluent Platform to Confluent Cloud
  • Create the Confluent Platform to Confluent Cloud link
  • Create a mirror topic and verify data on Confluent Cloud
  • Mirror data from Confluent Cloud to Confluent Platform
  • Create the Confluent Cloud to Confluent Platform link
  • Create topics and mirror data to Confluent Platform
  • Tear down the tutorial environment
  • Stop consumers and producers
  • Promote mirror topics
  • Delete the source and mirror topics
  • Delete the cluster links
  • Stop Confluent Platform
  • Configuration summary
  • Related content