Configure a service account

The Unified Stream Manager (USM) Agent requires a service account to securely authenticate with Confluent Cloud and collect metadata from your Confluent Platform cluster. The service account must have both the USMAgent and DataSteward roles. Additionally, it requires the following API keys:

  • An API key with Schema Registry scope.
  • An API key with Cloud resource management scope.

Use separate service accounts for each logically separate Confluent Platform environments that connects to Confluent Cloud though USM. For example, if you have development and production environments, use a separate service account for each.

You have two options for configuration: creating a new service account dedicated to this purpose or using an existing service account.

  • When you create a new account in the wizard, the roles USMAgent and DataSteward and API keys schema registry and Cloud resource management with the necessary permissions are assigned automatically.
  • If you choose to use an existing account, you must manually verify that it has the USMAgent and DataSteward roles assigned. If these roles are not assigned, the registration fails. To add role bindings to a principal, see Add role bindings to a principal. Also, verify the service account has required API keys schema registry and Cloud resource management for the USM Agent to use. For details, see Add an API key.

Create a new service account

To create a new service account:

  1. Select Create new service account.
  2. Enter a Name and Description for the USM service account.
  3. From the Account type drop-down, select the account type and then select the account.
  4. Click Create service account, and then click Next.

Use an existing service account

To use an existing service account:

  1. From the Service account drop-down menu, select your existing account.

Important

Ensure that the selected service account has both the USMAgent and DataSteward roles and the required API keys schema registry and Cloud resource management. If these roles or API keys are not assigned, the registration fails.

  1. Click Next.

After you configure the service account, the wizard directs you to the Deploy Unified Stream Manager Agent page.

What’s next