[Verse 1]
When clients knock on Kafka's door
Three ways to prove who they are for sure
TLS certificates shake hands both ways
Mutual trust in encrypted displays
SCRAM with SHA takes username and pass
Hashed five-twelve times to make security last
OAuth tokens from providers you know
Keycloak, Azure, Okta's the flow
[Chorus]
Three ways in, three ways to authenticate
TLS mutual, SCRAM, OAuth delegate
Per listener config, you choose the gate
KafkaUser CRD seals their fate
Lock it down, lock it tight
Authentication done right
[Verse 2]
TLS client auth needs certificates paired
Server checks client, both sides are prepared
Private keys and public certs align
X-five-oh-nine format by design
SCRAM-SHA-512 salts and iterates
Password never travels, security validates
Store the credentials in Kubernetes secrets
User management that never retreats
[Chorus]
Three ways in, three ways to authenticate
TLS mutual, SCRAM, OAuth delegate
Per listener config, you choose the gate
KafkaUser CRD seals their fate
Lock it down, lock it tight
Authentication done right
[Bridge]
Listener by listener you decide the method
Plain or TLS or SASL connected
KafkaUser custom resource defines
Who gets access across the lines
Strimzi operator handles the rest
Certificate authority puts trust to test
[Verse 3]
OAuth brings external identity providers
Keycloak tokens, Azure suppliers
JWT validation at the broker door
Centralized auth you can't ignore
Each listener in your Kafka spec
Choose your method, earn respect
Authentication mechanisms three
Secure your streaming technology
[Chorus]
Three ways in, three ways to authenticate
TLS mutual, SCRAM, OAuth delegate
Per listener config, you choose the gate
KafkaUser CRD seals their fate
Lock it down, lock it tight
Authentication done right
[Outro]
Strimzi makes it simple to configure and deploy
Authentication layers that hackers can't destroy
Three methods strong, your choice to make
Kafka security for your data's sake