[Verse 1]
In the cluster where the data flows
Security must guide where traffic goes
Network policies stand as guards
Protecting Kafka from outside cards
Three key rules we need to know
To keep our message streams secure below
[Chorus]
Lock the brokers, shield the Zoo
Allow the ones you trust to get through
Network policies three by three
Kafka safety, that's the key
Lock the brokers, shield the Zoo
Only trusted pods break through
[Verse 2]
First restriction, broker traffic tight
Only designated pods get sight
Port nine zero nine two stays closed
Unless your label's been exposed
Ingress rules with selectors clean
Keep unwanted clients from the scene
[Chorus]
Lock the brokers, shield the Zoo
Allow the ones you trust to get through
Network policies three by three
Kafka safety, that's the key
Lock the brokers, shield the Zoo
Only trusted pods break through
[Verse 3]
ZooKeeper needs its private space
Coordination in a sacred place
Port two one eight one locked down tight
Internal cluster traffic only right
No external access to the state
Where Kafka's metadata finds its fate
[Bridge]
Namespace labels, pod selectors too
Define exactly who gets through
Match expressions tell the tale
Of which connections will not fail
[Verse 4]
Third policy allows with care
Specific namespaces to share
Label matching makes it clear
Which applications can draw near
Production separate from test
Access control at its best
[Chorus]
Lock the brokers, shield the Zoo
Allow the ones you trust to get through
Network policies three by three
Kafka safety, that's the key
Lock the brokers, shield the Zoo
Only trusted pods break through
[Outro]
Three network policies stand guard
Kafka security won't be marred
Strimzi makes the config clean
Safest streaming you've ever seen