User Authorization


Kpow supports two methods of controlling user access to User Actions.

User Actions

Note: User Actions apply to specific Domains. This is important when configuring RBAC.

The following actions are supported by both methods of access control.

DomainActionControl (when TRUE)
CLUSTERTOPIC_INSPECTAllow users to read topic key and value data
TOPIC_PRODUCEAllow users to write new messages to topics
TOPIC_CREATEAllow users to create new topics
TOPIC_EDITAllow users to edit topic configuration
TOPIC_DELETEAllow users to delete topics
TOPIC_TRUNCATEAllow users to truncate topics
GROUP_EDITAllow users to delete consumer groups and reset consumer offsets
BROKER_EDITAllow users to edit broker configuration
ACL_EDITAllow users to create and delete Kafka ACLs
SCHEMASCHEMA_CREATEAllow users to create new schemas and subjects
SCHEMA_EDITAllow users to edit schemas and subjects
CONNECTCONNECT_CREATEAllow users to create new connectors
CONNECT_EDITAllow users to edit, pause, stop, and restart connectors and tasks

User Permissions

Users are denied permissions on all actions by default.

To give permission to a specific action you must configure it true.

In most cases where the user is denied permission to an particular action the UI will show that denial directly to the user. In some cases the permission is determined on the back end and the user is informed after the fact that they do not have the ability to take the requested action.

Keycloak Integration