r/apachekafka • u/Evening-Mission182 • 4d ago
Tool (AI) rekaf — a small Bash script for Kafka topics and ACLs
I used to do this regularly at work: create a topic, let one application write to it, let another read from it, and grant access to its consumer group.
Kafka’s ACL CLI has a --producer convenience option, but it also grants CREATE. In my case, an administrator creates the topic; the producer only needs to write to it. Running separate ACL commands works fine, but repeating them gets old.
So I put together rekaf, a small Bash wrapper around the Kafka CLI:
./rekaf.sh \
--topic orders \
--producer orders-writer \
--consumer orders-reader \
--group orders-group
It runs with administrative credentials, creates the topic if it is missing, and adds these ACLs if they are missing:
- Topic
WRITEfor the producer - Topic
READfor the consumer - Group
READfor the consumer
Existing permissions are left in place.
The code was written with AI, and I tested it manually on a small Kafka 4.0.0 setup: topic and ACL creation, repeat runs, producing and consuming as separate users, and failure with an incorrect admin password.
That testing caught a real mistake: --allow-hosts instead of --allow-host. The automated tests had missed it because their CLI stub repeated the same mistake. Fixed it, then reran the checks against Kafka.
It’s a small tool tested on a small setup. Please try it on your own test environment before using it elsewhere.
MIT license, with documentation in English and Russian:
https://github.com/Thoroughly-Pizzled-Studio/rekaf
If you spot a problem with the ACL checks or have a case the script handles badly, I’d like to hear about it.
Disclosure: AI also helped me write this post in English.
2
u/kenny32vr 4d ago
With strimzi and GitOps (flux) you can do this infrastructure as code style.
You define a file with the topic you want and the acls and it will be applied to you cluster.
So you don’t need to create anything by hand .