kirktrue opened a new pull request #11284:
URL: https://github.com/apache/kafka/pull/11284


   This task is to provide a concrete implementation of the interfaces defined 
in KIP-255 to allow Kafka to connect to an OAuth/OIDC identity provider for 
authentication and token retrieval. While KIP-255 provides an unsecured JWT 
example for development, this will fill in the gap and provide a 
production-grade implementation.
   
   The OAuth/OIDC work will allow out-of-the-box configuration by any Apache 
Kafka users to connect to an external identity provider service (e.g. Okta, 
Auth0, Azure, etc.). The code will implement the standard OAuth 
clientcredentials grant type.
   
   The proposed change is largely composed of a pair of 
AuthenticateCallbackHandler implementations: one to login on the client and one 
to validate on the broker.
   
   See the following for more detail:
   
   * 
[KIP-768](https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=186877575)
   * [KAFKA-13202](https://issues.apache.org/jira/browse/KAFKA-13202)
   
   *More detailed description of your change,
   if necessary. The PR title and PR message become
   the squashed commit message, so use a separate
   comment to ping reviewers.*
   
   *Summary of testing strategy (including rationale)
   for the feature or bug fix. Unit and/or integration
   tests are expected for any behaviour change and
   system tests should be considered for larger changes.*
   
   ### Committer Checklist (excluded from commit message)
   - [ ] Verify design and implementation 
   - [ ] Verify test coverage and CI build status
   - [ ] Verify documentation (including upgrade notes)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: jira-unsubscr...@kafka.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Reply via email to