Configure a Resource-based Policy: Kafka
How to add a new policy to an existing Kafka service.
On the Service Manager page, select an existing Kafka service.
The List of Policies page appears.
Click Add New Policy.
The Create Policy page appears.
Complete the Create Policy page as follows:
Table 1. Policy Details Field Description Policy Name Enter an appropriate policy name. This name cannot be duplicated across the system. This field is mandatory. normal/override Enables you to specify an override policy. When override is selected, the access permissions in the policy override the access permissions in existing policies. This feature can be used with Add Validity Period to create temporary access policies that override existing policies. Policy Label Specify a label for this policy. You can search reports and filter policies based on these labels. Topic Kafka resource type. A topic is a category or feed name to which messages are published. Transactional ID Kafka resource type, uniquely identifies producers in a persistent way. Cluster Kafka resource type. Delegation Token Kafka resource type for authentication. Description (Optional) Describe the purpose of the policy. Audit Logging Specify whether this policy is audited. (De-select to disable auditing). Add Validity Period Specify a start and end time for the policy. Policy Conditions (applied at the policy level) Click the + icon, then specify an IP address range. Table 2. Allow Conditions
Specify the groups to which this policy applies.
To designate a group as an Administrator, select the Delegate Admin check box. Administrators can edit or delete the policy, and can also create child policies based on the original policy.
The public group contains all users, so granting access to the public group grants access to all users.
Specify the users to which this policy applies.
To designate a user as an Administrator, select the Delegate Admin check box. Administrators can edit or delete the policy, and can also create child policies based on the original policy.
Policy Conditions (applied at the item level) Specify an IP address range. Permissions Add or edit permissions: Publish, Consume,Configure,Describe, Create, Delete, Describe Configs, Alter Configs, Select/Deselect All. Delegate Admin You can use Delegate Admin to assign administrator privileges to the users or groups specified in the policy. Administrators can edit or delete the policy, and can also create child policies based on the original policy.
- You can use the Plus (+) symbol to add additional conditions. Conditions are evaluated in the order listed in the policy. The condition at the top of the list is applied first, then the second, then the third, and so on.
- Click Add.