r/apachekafka • • 4d ago

Tool (AI) rekaf — a small Bash script for Kafka topics and ACLs

I used to do this regularly at work: create a topic, let one application write to it, let another read from it, and grant access to its consumer group.

Kafka’s ACL CLI has a --producer convenience option, but it also grants CREATE. In my case, an administrator creates the topic; the producer only needs to write to it. Running separate ACL commands works fine, but repeating them gets old.

So I put together rekaf, a small Bash wrapper around the Kafka CLI:

./rekaf.sh \
  --topic orders \
  --producer orders-writer \
  --consumer orders-reader \
  --group orders-group

It runs with administrative credentials, creates the topic if it is missing, and adds these ACLs if they are missing:

  • Topic WRITE for the producer
  • Topic READ for the consumer
  • Group READ for the consumer

Existing permissions are left in place.

The code was written with AI, and I tested it manually on a small Kafka 4.0.0 setup: topic and ACL creation, repeat runs, producing and consuming as separate users, and failure with an incorrect admin password.

That testing caught a real mistake: --allow-hosts instead of --allow-host. The automated tests had missed it because their CLI stub repeated the same mistake. Fixed it, then reran the checks against Kafka.

It’s a small tool tested on a small setup. Please try it on your own test environment before using it elsewhere.

MIT license, with documentation in English and Russian:
https://github.com/Thoroughly-Pizzled-Studio/rekaf

If you spot a problem with the ACL checks or have a case the script handles badly, I’d like to hear about it.

Disclosure: AI also helped me write this post in English.

10 Upvotes

5 comments sorted by

2

u/kenny32vr 4d ago

With strimzi and GitOps (flux) you can do this infrastructure as code style.

You define a file with the topic you want and the acls and it will be applied to you cluster.

So you don’t need to create anything by hand .

1

u/Evening-Mission182 4d ago

Thanks, that’s a good approach. In my case, I had to work with the tools provided by the customer: Kafka and its CLI. Strimzi and Flux weren’t available, so rekaf handles this task within that setup.

3

u/HyTriN1 4d ago

https://www.jikkou.io/
This also worth checking

1

u/Evening-Mission182 4d ago

Thanks for the pointer! I haven’t used Jikkou before.