Configure OAuth for Schema Registry in Confluent Platform
Configure the Schema Registry server to use OAuth to secure its services. The following sections cover the OAuth configurations for the Kafka broker, Schema Registry server, and Schema Registry clients, depending on your use case.
Configure the Kafka broker to connect to Schema Registry
When broker-side schema validation is enabled on
topics, the Kafka broker attempts to connect to Schema Registry. To allow the broker to
connect to Schema Registry for validation, provide the following configurations in the
broker properties file. For example, with KRaft,
configure these in one of $CONFLUENT_HOME/etc/kafka/broker.properties,
controller.properties, or server.properties, depending on your
KRaft setup.
If role-based access control (RBAC) is enabled, the principal defined here should have appropriate permissions.
# Schema registry configurations
confluent.schema.registry.url=<your-schema-registry-URL>
# If Broker validation is enabled for topics
confluent.bearer.auth.credentials.source=OAUTHBEARER
confluent.bearer.auth.issuer.endpoint.url=<token-end-point>
confluent.bearer.auth.client.id=<client-id>
confluent.bearer.auth.client.secret=<client-secret>
Tip
These configurations are required only when Schema Registry itself has server-side
OAuth. When the broker has OAuth and Schema Registry has Basic Authentication, the
broker uses confluent.basic.auth.credentials.source for Schema Registry validation.
For more about authenticating with HTTP Basic Authentication, see
Schema Registry in the Security documentation.
Enable OAuth on the Schema Registry server
To specify OAuth requirements for clients that connect to the Schema Registry server,
configure the following properties in the Schema Registry properties file, for example
$CONFLUENT_HOME/etc/schema-registry/schema-registry.properties.
rest.servlet.initializor.classes=io.confluent.common.security.jetty.initializer.AuthenticationHandler
oauthbearer.jwks.endpoint.url=https://my-good-idp.com/oauth2/keys
oauthbearer.expected.issuer=<idp-issuer>
oauthbearer.expected.audience=<target-audience>
oauthbearer.sub.claim.name=<sub-claim-name>
oauthbearer.groups.claim.name=<groups-claim-name>
Tip
The URL shown for
oauthbearer.jwks.endpoint.urlis a generic example. Use the URL that points to your OAuth server and keys.The default value for the optional
oauthbearer.sub.claim.nameissub.The default value for the optional
oauthbearer.groups.claim.nameisgroups.
Configure OAuth on the Schema Registry client
If OAuth is enabled on the Schema Registry server, configure Schema Registry clients accordingly. In Confluent Platform 7.7 and later, you can configure Schema Registry for both OAuth and LDAP, so one Schema Registry client can use LDAP Basic Authentication to connect while another client uses the OAuth configurations and workflow to connect to the same Schema Registry server.
A Schema Registry client can use an explicit configuration to connect to the Schema Registry server over OAuth, as shown in the following example.
bearer.auth.credentials.source=OAUTHBEARER
bearer.auth.issuer.endpoint.url=<idp-token-end-point>
bearer.auth.client.id=<client-id>
bearer.auth.client.secret=<client-secret>
bearer.auth.scope=<groups>
A Schema Registry client can also reuse the configurations that it uses to connect to the Kafka broker. In this case, the client inherits the “endpoint” and “client” properties from the Kafka client, so they’re optional. If you provide the properties in the client configuration, they take precedence.
bearer.auth.credentials.source=SASL_OAUTHBEARER_INHERIT
# Configs below are optional
bearer.auth.issuer.endpoint.url=<idp-token-end-point>
bearer.auth.client.id=<client-id>
bearer.auth.client.secret=<client-secret>
bearer.auth.scope=<groups>
For details on each configuration option, see Configuration Reference for Schema Registry Clients on Confluent Platform.
For more about configuring clients with HTTP Basic Authentication, see Schema Registry in the Security documentation.