> For the complete documentation index, see [llms.txt](https://docs.livestreamiq.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.livestreamiq.com/readme/3.-guide-to-navigation/3.4-cluster-overview/3.4.7-access-control-list-acl.md).

# 3.4.7 Access Control List (ACL)

The section will provide the overview of the Access Control List (ACL) functionality.

Access Control Lists (ACLs) provide a secure mechanism for managing access to Apache Kafka resources and data. Within LivestreamIQ, permissions are assigned to specific principals, ensuring that they can access only the resources for which they have been explicitly granted authorization.\
\
The operations available to a principal are determined by the permissions assigned to the resources they are authorized to access. When configuring an ACL, it is important to carefully define the resources and operations permitted for each principal. Based on the access requirements of specific principals, multiple ACLs may be configured to provide the appropriate level of access and meet security requirements.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-a52299e903216cf687fe5e58c97d1407ac727b98%2Funknown%20\(137\).png?alt=media)

{% hint style="info" %}
**Note:** ACL details will automatically display only when Kafka authentication is enabled.
{% endhint %}

The following components are:

1. **Access Control List:** The ACL List section provides a comprehensive overview of all Access Control Lists (ACLs) configured for the selected Kafka cluster.
   1. Principal: Specifies the user or service account to which the ACL applies, such as `User:admin` or `User:app-user` .
   2. Resource:

#### To Access ACL Management

The following steps are:

**Step 1:** From the **Select Clusters** list at the bottom of the Dashboard, select the Kafka cluster for which you want to manage Access Control Lists (ACLs).

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-5dfa7d5d10959160251cb9d197aa5cdbdbf1c60b%2Funknown%20\(138\).png?alt=media)

Step 2: Click the ACL tab. It will display all available topics within the selected Kafka cluster.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-ae9524e53ed8a5910de96559460e6add685e9c58%2Funknown%20\(139\).png?alt=media)

**The Following Components are:**

1. **Access Control List:**\
   The ACL page provides a complete overview of all Kafka ACl available in the selected cluster.<br>

   ![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-ae9524e53ed8a5910de96559460e6add685e9c58%2Funknown%20\(139\).png?alt=media)

   1. **Principal:** The user or service account to which the ACL applies, for example `User:admin` or `User:app-user`.
   2. **Resource:** The Kafka resource that the ACL controls, such as a Topic, Group, Cluster, Transactional ID, or Delegation Token.
   3. **Pattern:** Defines how the resource name is matched. Common patterns include `LITERAL` for an exact resource name match, `PREFIXED` for resources whose names begin with the specified value, and `ANY`/`MATCH` for viewing or filtering ACLs.
   4. **Host:** Specifies the host or IP address from which the principal is allowed or denied access. `*` indicates that access is allowed or denied from **any host**.
   5. **Permission:** Defines the actions that the principal is allowed or denied to perform on the resource, such as **ALLOW/DENY** combined with operations like `READ`, `WRITE`, `CREATE`, `DELETE`, `ALTER`, `DESCRIBE`, or `ALL`.
2. **Access Control List (ACL) – Filter:**\
   The Access Control List page provides filters to quickly find ACL entries based on the resource type, pattern type, and resource name.<br>

   ![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-1268f0f68d68db5bf4bb915ba24b602a190e2903%2Funknown%20\(141\).png?alt=media)

   \
   **Components of ACL Filter:**

   1. <p align="center"><strong>Resource Type:</strong> Select the type of Kafka resource to filter ACLs. Examples include Topic, Group, Cluster, Transactional ID, and other supported Kafka resource types.</p>
   2. **Pattern Type:** Select the pattern used to match the resource name. Common options include LITERAL and PREFIXED.
   3. **Resource Name:** Enter the name of the Kafka resource you want to search for, such as a topic name or group name.
   4. **Reset:** Clears all selected filters and restores the default ACL list.

   **How to Filter ACLs:**

   1. Select the required Pattern Type.
   2. Enter the Resource Name in the search field.
   3. The ACL list will be filtered based on the selected criteria.
   4. Click Reset to clear the filters and view the complete ACL list.

#### **To Creating a New ACL:**

Step 1 :Click on the Create ACL button.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-d9fd46b978bbe96d63bc617af6c6137bdb0424fd%2Funknown%20\(142\).png?alt=media)

Step 2 : After clicking the button, the following page opens.

Step 3 : The Create ACL page allows users to create an Access Control List based on a selected ACL type. Select the required ACL Type from the drop down. The configuration fields displayed on the page depend on the selected ACL type.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-4c2bc518afaa4799d8269b6001e216517ab0abc2%2Funknown%20\(143\).png?alt=media)

1. **ACL Types:**
   1. **Produce ACL :** Creates permissions required by a Kafka producer to publish messages to selected topics.
   2. **Consume ACL :** Creates permissions required by a Kafka consumer to read messages from selected topics and consumer groups.
   3. **Kafka Stream Apps :** Creates the ACL configuration required for a Kafka Streams application, including source topics, destination topics, principal, host restriction, and application ID.
   4. **Custom ACL :** Allows users to define ACL permissions manually by selecting the Kafka resource, operation, pattern, principal, host, and permission.

1.1 **Kafka Custom ACL:**\
Based on the selected ACL type, the user must fill in the corresponding parameters.<br>

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-4c2bc518afaa4799d8269b6001e216517ab0abc2%2Funknown%20\(143\).png?alt=media)

When Custom ACL is selected, users can configure the ACL by specifying the principal, host restriction, resource type, operation, and matching pattern.

1. **Principal \* :** Specifies the Kafka user or service account to which the ACL applies. Use the format User:, for example User : alice.
2. **Host restriction \* :** Specifies the client host or IP address from which the principal can access the resource. Use \* to allow access from any host, or specify a particular IP address.
3. **Resource Type \* :** Specifies the type of Kafka resource to which the ACL applies, such as Topic, Group, Cluster, Transactional ID, or Delegation Token.
4. **Operations \* :** Specifies the Kafka operation that the principal is allowed or denied to perform, such as Read, Write, Create, Delete, Alter, Describe, or All.
5. **Matching Pattern \* :** Specifies how the resource name is matched. For example, LITERAL applies to an exact resource name, while PREFIXED applies to resources whose names start with the specified value.

1.2 **Produce ACL :**\
Based on the selected ACL type, the user must fill in the corresponding parameters.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-115301d9efda6d9d0f3b1e7f0a55f29a82002439%2Funknown%20\(148\).png?alt=media)

1. **Principal \* :** Specifies the Kafka user or identity that is granted producer permissions.
2. **Host \* :** Specifies the host from which the principal is allowed to access the Kafka resources.
3. **To Topic(s) \* :** Specifies the Kafka topic(s) to which the producer is allowed to send messages.
4. **Transaction ID :** Specifies the Transaction ID associated with transactional message production.
5. **Idempotent :** Enables idempotent producer access to ensure that duplicate messages are not written to the Kafka topic due to retries.

1.3 **Consume ACL :**\
Based on the selected ACL type, the user must fill in the corresponding parameters.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-3f9c71a13061f0d44f389e81df7b1e58e3f2d014%2Funknown%20\(149\).png?alt=media)

{% hint style="info" %}
**Note:** If *Host* and *Principal* are common (top-level) fields for the Consumer ACL, they should be structured accordingly.
{% endhint %}

1. **Principal \* :** Specifies the Kafka user or identity that is granted the consumer permissions.
2. **Host \* :** Specifies the host from which the principal is allowed to access the Kafka resources.
3. **From Topic(s) \* :** Specifies the Kafka topic(s) from which the consumer is allowed to consume messages.
4. **Consumer Group(s) :** Specifies the consumer group(s) associated with the consumer.

1.4 **Kafka Stream Apps :**

Based on the selected ACL type, the user must fill in the corresponding parameters.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-d6262f71826e920fa08c76e284210387da20e910%2Funknown%20\(152\).png?alt=media)

When For Kafka Stream Apps is selected, the following fields are displayed:

1. **Principal\* :** Enter the Kafka user or service account to which the ACL applies. Use the format User:, for example User:alice or User:order-service.
2. **Host restriction\* :** Specify the client host or IP address from which the ACL applies. Enter \* to allow the rule from any host, or provide a specific IP address.
3. **From topic(s)\* :** Select the source topic(s) from which the Kafka Streams application reads messages.
4. **To topic(s)\*** **:** Select the destination topic(s) to which the Kafka Streams application writes messages.
5. **Application ID\* :** Enter the unique Kafka Streams application ID. This ID identifies the Kafka Streams application and is also associated with its consumer-group-related permissions.
6. **Cancel :** Cancels the ACL creation operation and returns to the previous page.
7. **Submit** : Validates the entered information and creates the ACL configuration.

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-8a983419c439e91e2a1f57204d592694e548733c%2Funknown%20\(153\).png?alt=media)

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-ac8847b6dcfd2396f88fd34bb033d69674aa8c08%2Funknown%20\(154\).png?alt=media)

#### Delete ACL :

Click delete delete icon and conform delete the acl records

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-86511b0bf82260fcd6794eb490d2757d55d4181f%2Funknown%20\(150\).png?alt=media)

![](https://1499573743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F6jSyTKzD9UG0uYLYFS7I%2Fuploads%2Fgit-blob-b530e00b548247f41824bf238dc11d2a78a11c5f%2Funknown%20\(151\).png?alt=media)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.livestreamiq.com/readme/3.-guide-to-navigation/3.4-cluster-overview/3.4.7-access-control-list-acl.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
