1 TLS Encryption

Apache Kafka & Strimzi · 3:07

Listen on 93

Lyrics

[Verse 1]
In the world of Kafka streams and queues
Strimzi brings security we can use
Built-in Certificate Authority stands guard
Making TLS encryption less hard
Auto-generates what your cluster needs
Certificates planted like digital seeds

[Chorus]
CA creates, auto-renews, trust the flow
Bring your own or let Strimzi grow
Validity periods, configure with care
Truststore holds the keys you share
TLS encryption, lock it down tight
Kafka security shining bright

[Verse 2]
Renewal cycles happen behind the scene
Thirty days before expiry, fresh and clean
Default validity lasts three-sixty-five
But you can customize to keep certs alive
Set your own periods in the YAML config
Certificate lifecycle running like clockwork

[Chorus]
CA creates, auto-renews, trust the flow
Bring your own or let Strimzi grow
Validity periods, configure with care
Truststore holds the keys you share
TLS encryption, lock it down tight
Kafka security shining bright

[Bridge]
When you bring your own CA to the table
Custom certificates, strong and stable
Import your secrets to the cluster space
Replace the defaults with your own embrace
Client truststore needs the public key
Authentication flowing seamlessly

[Verse 3]
Configure clients with the truststore path
SSL context follows the security math
Certificate chain validation on every call
Mutual TLS protecting it all
From producer to broker, consumer to cluster
Encrypted connections growing stronger

[Chorus]
CA creates, auto-renews, trust the flow
Bring your own or let Strimzi grow
Validity periods, configure with care
Truststore holds the keys you share
TLS encryption, lock it down tight
Kafka security shining bright

[Outro]
Trust the process, trust the chain
Strimzi TLS breaking through the pain
Certificates rotating, security never sleeps
Your Kafka cluster safely keeps

← 4 Encrypting Data at Rest | 5 Lab: Securing a Strimzi Cluster →