Plan Security
Before you deploy Confluent Platform with Confluent for Kubernetes, plan how you handle authentication, authorization, network encryption, and sensitive configuration data.
Confluent supports the following processes to enforce security:
Authentication
Authorization
Network encryption
Sensitive configuration data
Authentication
Choose one of the following methods for Apache Kafka® client authentication:
mTLS
Simple Authentication and Security Layer (SASL)/PLAIN
SASL/PLAIN with Lightweight Directory Access Protocol (LDAP), where the identity can come from your LDAP server
Network encryption
Use Transport Layer Security (TLS) to encrypt both of the following:
Internal traffic between Confluent Platform components
External traffic from clients to Confluent Platform components
Sensitive configuration data
Manage credentials, certificates, and other sensitive configuration values using Kubernetes Secrets. For details, see Provide and Manage Sensitive Data for Confluent Platform in Confluent for Kubernetes.
Production best practices
As a best practice for security, enable mTLS or SASL/PLAIN with LDAP for authentication, RBAC for authorization, and TLS encryption for both internal and external traffic in production deployments.
For a tutorial scenario to configure these security settings, see Production recommended secure setup.