Configure a Java Producer for Google Cloud’s managed Apache Kafka service (step-by-step)

Google Cloud TechAbout 4 min readSep 14, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • Managed Kafka Cluster (Google Cloud): A Kafka service provided by Google, simplifying Kafka deployment and management.
  • Bootstrap URL: The address used to initially connect to a Kafka cluster.
  • SASL/OAUTHBEARER: A security protocol and mechanism for authenticating Kafka clients using OAuth 2.0 tokens.
  • Application Default Credentials (ADC): A Google Cloud mechanism that allows applications to automatically authenticate using the environment's credentials (e.g., Compute Engine VM).
  • Login Handler: A custom class that translates Google Cloud ADC into a format compatible with the Kafka client's SASL/OAUTHBEARER authentication.
  • Maven: A build automation tool primarily used for Java projects to manage dependencies and build processes.
  • pom.xml: The Project Object Model file in Maven, containing project metadata, dependencies, and build configurations.
  • Compute Engine Virtual Machine (VM): A virtual machine instance running on Google Cloud's Compute Engine.
  • GKE: Google Kubernetes Engine, a managed Kubernetes service.

Configuring a Kafka Producer Application for Google's Managed Kafka Service

This section details the steps to modify a generic Kafka producer application to connect to a managed Kafka cluster on Google Cloud.

  1. Modifying the Client Configuration:
    • The initial step involves updating the client.properties file, which contains the Kafka client's configuration.
    • The bootstrap.servers property, initially pointing to a local Kafka broker, needs to be changed to the Bootstrap URL of the managed Kafka cluster. This URL can be found in the cluster configuration UI within the Google Cloud console.
  2. Implementing Security Settings:
    • To establish a secure and authenticated connection, the application needs to use the SASL/OAUTHBEARER protocol.
    • This mechanism leverages Application Default Credentials (ADC) installed on Compute Engine VMs. ADC eliminates the need to manage explicit passwords or secrets.
    • The configuration requires setting security.protocol=SASL_SSL and sasl.mechanism=OAUTHBEARER.
  3. Using a Specialized Login Handler:
    • A custom login handler is required to translate the ADC into a format that the Kafka client understands for SASL/OAUTHBEARER authentication.
    • The login handler class needs to be specified in the sasl.login.callback.handler.class property within the client.properties file.
  4. Managing Dependencies with Maven:
    • To include the login handler class in the project, a dependency needs to be added to the pom.xml file.
    • The presenter uncommented a specific dependency in the pom.xml file to include the necessary package containing the login handler implementation. This allows Maven to download and manage the dependency.
  5. Deployment:
    • After configuring the application and managing dependencies, the project can be built and deployed on a Compute Engine VM or GKE.

Example Application and Configuration

  • The example application is a simple producer that reads configuration from a client.properties file and sends a "hello world" message to a Kafka topic.
  • The client.properties file is modified to point to the managed Kafka cluster's Bootstrap URL and configure SASL/OAUTHBEARER authentication using ADC.
  • The pom.xml file is updated to include the dependency containing the custom login handler.

Key Arguments and Perspectives

  • The video emphasizes the ease of using ADC for authentication, eliminating the need to manage passwords or secrets.
  • It highlights the importance of using a specialized login handler to translate ADC into a format compatible with the Kafka client.
  • The presenter advocates for using managed Kafka clusters to simplify Kafka deployment and management.

Notable Quotes

  • "We also need to change the security settings. We need an authenticated encrypted connection to connect to a managed Kafka cluster. For that, we'll use the SAS plane protocol and OOTH bearer mechanism."
  • "This will let us use application default credentials that are installed on compute engine virtual machines. This is great because we don't need to manage passwords or other secrets..."

Technical Terms and Concepts

  • Bootstrap URL: The initial connection point for a Kafka cluster.
  • SASL/OAUTHBEARER: A security protocol for authenticating Kafka clients using OAuth 2.0 tokens.
  • Application Default Credentials (ADC): A Google Cloud mechanism for automatic authentication.
  • Login Handler: A custom class that translates ADC into a Kafka-compatible format.
  • Maven: A build automation tool for Java projects.
  • pom.xml: The Maven project configuration file.

Logical Connections

The video logically connects the steps required to configure a Kafka producer application for a managed Kafka cluster. It starts with modifying the client configuration, then addresses security settings, introduces the login handler, explains dependency management using Maven, and concludes with deployment options.

Data, Research Findings, or Statistics

The video does not explicitly mention any specific data, research findings, or statistics.

Synthesis/Conclusion

The video provides a practical guide to configuring a Kafka producer application to connect to a managed Kafka cluster on Google Cloud. The key takeaways are the importance of using ADC for authentication, the need for a specialized login handler, and the benefits of using managed Kafka clusters for simplified deployment and management. The video encourages viewers to use the provided Java and Python quick starts for their own projects.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.