Configure OAuth for Schema Registry in Confluent Platform

Configure the Schema Registry server to use OAuth to secure its services. The following sections cover the OAuth configurations for the Kafka broker, Schema Registry server, and Schema Registry clients, depending on your use case.

Configure the Kafka broker to connect to Schema Registry

When broker-side schema validation is enabled on topics, the Kafka broker attempts to connect to Schema Registry. To allow the broker to connect to Schema Registry for validation, provide the following configurations in the broker properties file. For example, with KRaft, configure these in one of $CONFLUENT_HOME/etc/kafka/broker.properties, controller.properties, or server.properties, depending on your KRaft setup.

If role-based access control (RBAC) is enabled, the principal defined here should have appropriate permissions.

# Schema registry configurations
confluent.schema.registry.url=<your-schema-registry-URL>
# If Broker validation is enabled for topics
confluent.bearer.auth.credentials.source=OAUTHBEARER
confluent.bearer.auth.issuer.endpoint.url=<token-end-point>
confluent.bearer.auth.client.id=<client-id>
confluent.bearer.auth.client.secret=<client-secret>

Tip

These configurations are required only when Schema Registry itself has server-side OAuth. When the broker has OAuth and Schema Registry has Basic Authentication, the broker uses confluent.basic.auth.credentials.source for Schema Registry validation. For more about authenticating with HTTP Basic Authentication, see Schema Registry in the Security documentation.

Enable OAuth on the Schema Registry server

To specify OAuth requirements for clients that connect to the Schema Registry server, configure the following properties in the Schema Registry properties file, for example $CONFLUENT_HOME/etc/schema-registry/schema-registry.properties.

rest.servlet.initializor.classes=io.confluent.common.security.jetty.initializer.AuthenticationHandler
oauthbearer.jwks.endpoint.url=https://my-good-idp.com/oauth2/keys
oauthbearer.expected.issuer=<idp-issuer>
oauthbearer.expected.audience=<target-audience>
oauthbearer.sub.claim.name=<sub-claim-name>
oauthbearer.groups.claim.name=<groups-claim-name>

Tip

  • The URL shown for oauthbearer.jwks.endpoint.url is a generic example. Use the URL that points to your OAuth server and keys.

  • The default value for the optional oauthbearer.sub.claim.name is sub.

  • The default value for the optional oauthbearer.groups.claim.name is groups.

Configure OAuth on the Schema Registry client

If OAuth is enabled on the Schema Registry server, configure Schema Registry clients accordingly. In Confluent Platform 7.7 and later, you can configure Schema Registry for both OAuth and LDAP, so one Schema Registry client can use LDAP Basic Authentication to connect while another client uses the OAuth configurations and workflow to connect to the same Schema Registry server.

A Schema Registry client can use an explicit configuration to connect to the Schema Registry server over OAuth, as shown in the following example.

bearer.auth.credentials.source=OAUTHBEARER
bearer.auth.issuer.endpoint.url=<idp-token-end-point>
bearer.auth.client.id=<client-id>
bearer.auth.client.secret=<client-secret>
bearer.auth.scope=<groups>

A Schema Registry client can also reuse the configurations that it uses to connect to the Kafka broker. In this case, the client inherits the “endpoint” and “client” properties from the Kafka client, so they’re optional. If you provide the properties in the client configuration, they take precedence.

bearer.auth.credentials.source=SASL_OAUTHBEARER_INHERIT
# Configs below are optional
bearer.auth.issuer.endpoint.url=<idp-token-end-point>
bearer.auth.client.id=<client-id>
bearer.auth.client.secret=<client-secret>
bearer.auth.scope=<groups>

For details on each configuration option, see Configuration Reference for Schema Registry Clients on Confluent Platform.

For more about configuring clients with HTTP Basic Authentication, see Schema Registry in the Security documentation.