Skip to content

Instantly share code, notes, and snippets.

@grdryn
Created August 25, 2021 17:55
Show Gist options
  • Save grdryn/cc3605b8a7f92b5145e061defcf161fb to your computer and use it in GitHub Desktop.
Save grdryn/cc3605b8a7f92b5145e061defcf161fb to your computer and use it in GitHub Desktop.
++ hostname
++ awk -F- '{print $NF}'
+ STRIMZI_BROKER_ID=1
+ export STRIMZI_BROKER_ID
+ echo STRIMZI_BROKER_ID=1
STRIMZI_BROKER_ID=1
+ export GC_LOG_ENABLED=false
+ GC_LOG_ENABLED=false
+ '[' -z '' ']'
+ export KAFKA_LOG4J_OPTS=-Dlog4j.configuration=file:/opt/kafka/custom-config/log4j.properties
+ KAFKA_LOG4J_OPTS=-Dlog4j.configuration=file:/opt/kafka/custom-config/log4j.properties
+ rm -f /var/opt/kafka/kafka-ready /var/opt/kafka/zk-connected
++ ls /opt/kafka/libs/kafka-agent.jar
+ KAFKA_OPTS=' -javaagent:/opt/kafka/libs/kafka-agent.jar=/var/opt/kafka/kafka-ready:/var/opt/kafka/zk-connected'
+ export KAFKA_OPTS
+ . ./set_kafka_jmx_options.sh '' '' ''
++ set -e
++ JMX_ENABLED=
++ JMX_USERNAME=
++ JMX_PASSWORD=
++ '[' '' = true ']'
+ '[' -n '' ']'
+ '[' true = true ']'
++ ls /opt/kafka/libs/jmx_prometheus_javaagent-0.14.0.redhat-00002.jar
+ KAFKA_OPTS=' -javaagent:/opt/kafka/libs/kafka-agent.jar=/var/opt/kafka/kafka-ready:/var/opt/kafka/zk-connected -javaagent:/opt/kafka/libs/jmx_prometheus_javaagent-0.14.0.redhat-00002.jar=9404:/opt/kafka/custom-config/metrics-config.yml'
+ export KAFKA_OPTS
+ export LOG_DIR=/opt/kafka
+ LOG_DIR=/opt/kafka
++ tr -dc _A-Z-a-z-0-9
++ head -c32
+ CERTS_STORE_PASSWORD=8lXZt-hkITT3EO3nKGKwH43jP7xATLqI
+ export CERTS_STORE_PASSWORD
+ mkdir -p /tmp/kafka
+ ./kafka_tls_prepare_certificates.sh
Preparing truststore for replication listener
Adding /opt/kafka/cluster-ca-certs/ca.crt to truststore /tmp/kafka/cluster.truststore.p12 with alias ca
Certificate was added to keystore
Preparing truststore for replication listener is complete
Looking for the right CA
Found the right CA: /opt/kafka/cluster-ca-certs/ca.crt
Preparing keystore for replication and clienttls listener
Preparing keystore for replication and clienttls listener is complete
Preparing store for oauth-external-9094 listener
Adding /opt/kafka/certificates/oauth-external-9094-certs/gryan-sso-cert-0/tls.crt to truststore /tmp/kafka/oauth-external-9094.truststore.p12 with alias oauth-0
Certificate was added to keystore
Preparing store for oauth external listener is complete
Preparing store for oauth-oauth-9095 listener
Adding /opt/kafka/certificates/oauth-oauth-9095-certs/gryan-sso-cert-0/tls.crt to truststore /tmp/kafka/oauth-oauth-9095.truststore.p12 with alias oauth-0
Certificate was added to keystore
Preparing store for oauth oauth listener is complete
Preparing truststore for client authentication
Adding /opt/kafka/client-ca-certs/ca.crt to truststore /tmp/kafka/clients.truststore.p12 with alias ca
Certificate was added to keystore
Preparing truststore for client authentication is complete
+ echo 'Starting Kafka with configuration:'
Starting Kafka with configuration:
+ ./kafka_config_generator.sh
+ tee /tmp/strimzi.properties
+ sed -e 's/sasl.jaas.config=.*/sasl.jaas.config=[hidden]/g' -e 's/password=.*/password=[hidden]/g'
##############################
##############################
# This file is automatically generated by the Strimzi Cluster Operator
# Any changes to this file will be ignored and overwritten!
##############################
##############################
##########
# Broker ID
##########
broker.id=1
##########
# Rack ID
##########
broker.rack=us-east-2c
##########
# Zookeeper
##########
zookeeper.connect=gryan-zookeeper-client:2181
zookeeper.clientCnxnSocket=org.apache.zookeeper.ClientCnxnSocketNetty
zookeeper.ssl.client.enable=true
zookeeper.ssl.keystore.location=/tmp/kafka/cluster.keystore.p12
zookeeper.ssl.keystore.password=[hidden]
zookeeper.ssl.keystore.type=PKCS12
zookeeper.ssl.truststore.location=/tmp/kafka/cluster.truststore.p12
zookeeper.ssl.truststore.password=[hidden]
zookeeper.ssl.truststore.type=PKCS12
##########
# Kafka message logs configuration
##########
log.dirs=/var/lib/kafka/data-0/kafka-log1
##########
# Control Plane listener
##########
listener.name.controlplane-9090.ssl.keystore.location=/tmp/kafka/cluster.keystore.p12
listener.name.controlplane-9090.ssl.keystore.password=[hidden]
listener.name.controlplane-9090.ssl.keystore.type=PKCS12
listener.name.controlplane-9090.ssl.truststore.location=/tmp/kafka/cluster.truststore.p12
listener.name.controlplane-9090.ssl.truststore.password=[hidden]
listener.name.controlplane-9090.ssl.truststore.type=PKCS12
listener.name.controlplane-9090.ssl.client.auth=required
##########
# Replication listener
##########
listener.name.replication-9091.ssl.keystore.location=/tmp/kafka/cluster.keystore.p12
listener.name.replication-9091.ssl.keystore.password=[hidden]
listener.name.replication-9091.ssl.keystore.type=PKCS12
listener.name.replication-9091.ssl.truststore.location=/tmp/kafka/cluster.truststore.p12
listener.name.replication-9091.ssl.truststore.password=[hidden]
listener.name.replication-9091.ssl.truststore.type=PKCS12
listener.name.replication-9091.ssl.client.auth=required
##########
# Listener configuration: TLS-9093
##########
listener.name.tls-9093.ssl.keystore.location=/tmp/kafka/cluster.keystore.p12
listener.name.tls-9093.ssl.keystore.password=[hidden]
listener.name.tls-9093.ssl.keystore.type=PKCS12
##########
# Listener configuration: EXTERNAL-9094
##########
listener.name.external-9094.oauthbearer.sasl.server.callback.handler.class=io.strimzi.kafka.oauth.server.JaasServerOauthValidatorCallbackHandler
listener.name.external-9094.oauthbearer.sasl.jaas.config=[hidden]
listener.name.external-9094.plain.sasl.server.callback.handler.class=io.strimzi.kafka.oauth.server.plain.JaasServerOauthOverPlainValidatorCallbackHandler
listener.name.external-9094.plain.sasl.jaas.config=[hidden]
listener.name.external-9094.sasl.enabled.mechanisms=OAUTHBEARER,PLAIN
listener.name.external-9094.max.connections=33
listener.name.external-9094.max.connection.creation.rate=33
listener.name.external-9094.ssl.keystore.location=/tmp/kafka/cluster.keystore.p12
listener.name.external-9094.ssl.keystore.password=[hidden]
listener.name.external-9094.ssl.keystore.type=PKCS12
##########
# Listener configuration: OAUTH-9095
##########
listener.name.oauth-9095.oauthbearer.sasl.server.callback.handler.class=io.strimzi.kafka.oauth.server.JaasServerOauthValidatorCallbackHandler
listener.name.oauth-9095.oauthbearer.sasl.jaas.config=[hidden]
listener.name.oauth-9095.sasl.enabled.mechanisms=OAUTHBEARER
##########
# Listener configuration: SRE-9096
##########
principal.builder.class=io.strimzi.kafka.oauth.server.OAuthKafkaPrincipalBuilder
##########
# Common listener configuration
##########
listeners=CONTROLPLANE-9090://0.0.0.0:9090,REPLICATION-9091://0.0.0.0:9091,TLS-9093://0.0.0.0:9093,EXTERNAL-9094://0.0.0.0:9094,OAUTH-9095://0.0.0.0:9095,SRE-9096://0.0.0.0:9096
advertised.listeners=CONTROLPLANE-9090://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9090,REPLICATION-9091://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9091,TLS-9093://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9093,EXTERNAL-9094://broker-1-gryan-c-j--qsqpjo-t--mhs-a.mk.gryan-3az.nvee.s1.devshift.org:443,OAUTH-9095://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9095,SRE-9096://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9096
listener.security.protocol.map=CONTROLPLANE-9090:SSL,REPLICATION-9091:SSL,TLS-9093:SSL,EXTERNAL-9094:SASL_SSL,OAUTH-9095:SASL_PLAINTEXT,SRE-9096:PLAINTEXT
inter.broker.listener.name=REPLICATION-9091
sasl.enabled.mechanisms=
ssl.secure.random.implementation=SHA1PRNG
ssl.endpoint.identification.algorithm=HTTPS
##########
# Authorization
##########
authorizer.class.name=io.bf2.kafka.authorizer.GlobalAclAuthorizer
super.users=User:CN=gryan-kafka,O=io.strimzi;User:CN=gryan-entity-operator,O=io.strimzi;User:CN=gryan-kafka-exporter,O=io.strimzi;User:CN=gryan-cruise-control,O=io.strimzi;User:CN=cluster-operator,O=io.strimzi
##########
# User provided configuration
##########
auto.create.topics.enable=false
client.quota.callback.class=io.strimzi.kafka.quotas.StaticQuotaCallback
client.quota.callback.static.disable-quota-anonymous=true
client.quota.callback.static.fetch=699050
client.quota.callback.static.produce=699050
client.quota.callback.static.storage.check-interval=30
client.quota.callback.static.storage.hard=30601641984
client.quota.callback.static.storage.soft=28991029248
default.replication.factor=3
inter.broker.protocol.version=2.7.0
leader.imbalance.per.broker.percentage=0
log.message.format.version=2.7.0
min.insync.replicas=2
offsets.topic.replication.factor=3
quota.window.num=30
quota.window.size.seconds=2
ssl.enabled.protocols=TLSv1.3,TLSv1.2
ssl.protocol=TLS
strimzi.authorization.global-authorizer.acl.1=permission=allow;topic=*;operations=all
strimzi.authorization.global-authorizer.acl.2=permission=allow;group=*;operations=all
strimzi.authorization.global-authorizer.acl.3=permission=allow;transactional_id=*;operations=all
strimzi.authorization.global-authorizer.allowed-listeners=TLS-9093,SRE-9096
transaction.state.log.min.isr=2
transaction.state.log.replication.factor=3+ echo ''
+ '[' -z '-Xms3G -Xmx3G' ']'
+ . ./set_kafka_gc_options.sh
++ set -e
++ '[' false == true ']'
++ export 'KAFKA_GC_LOG_OPTS= '
++ KAFKA_GC_LOG_OPTS=' '
++ export GC_LOG_ENABLED=false
++ GC_LOG_ENABLED=false
+ exec /usr/bin/tini -w -e 143 -- /opt/kafka/bin/kafka-server-start.sh /tmp/strimzi.properties
2021-08-25T17:52:42Z INFO [main] [KafkaAgent:197] Starting KafkaAgent with brokerReadyFile=/var/opt/kafka/kafka-ready and sessionConnectedFile=/var/opt/kafka/zk-connected
2021-08-25T17:52:42Z INFO [main] [KafkaAgent:64] Starting metrics registry
2021-08-25T17:52:42Z INFO [main] [KafkaAgent:55] KafkaYammerMetrics found and will be used.
2021-08-25T17:52:42Z INFO [main] [Log4jControllerRegistration$:31] Registered kafka:type=kafka.Log4jController MBean
2021-08-25T17:52:43Z INFO [main] [X509Util:79] Setting -D jdk.tls.rejectClientInitiatedRenegotiation=true to disable client-initiated TLS renegotiation
2021-08-25T17:52:43Z INFO [main] [LoggingSignalHandler:72] Registered signal handlers for TERM, INT, HUP
2021-08-25T17:52:43Z INFO [main] [KafkaServer:66] starting
2021-08-25T17:52:43Z INFO [main] [KafkaServer:66] Connecting to zookeeper on gryan-zookeeper-client:2181
2021-08-25T17:52:43Z INFO [main] [ZooKeeperClient:66] [ZooKeeperClient Kafka server] Initializing a new session to gryan-zookeeper-client:2181.
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:zookeeper.version=3.5.9-4386ddd75741a3466e897d1c8e6ce172edbfa68a, built on 08/11/2021 09:10 GMT
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:host.name=gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc.cluster.local
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:java.version=11.0.12
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:java.vendor=Red Hat, Inc.
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:java.home=/usr/lib/jvm/java-11-openjdk-11.0.12.0.7-0.el7_9.x86_64
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:java.class.path=/opt/kafka/bin/../libs/accessors-smart-1.2.0.redhat-00001.jar:/opt/kafka/bin/../libs/activation-1.1.1.redhat-5.jar:/opt/kafka/bin/../libs/annotations-13.0.jar:/opt/kafka/bin/../libs/aopalliance-repackaged-2.6.1.redhat-00001.jar:/opt/kafka/bin/../libs/argparse4j-0.7.0.redhat-00003.jar:/opt/kafka/bin/../libs/audience-annotations-0.5.0.redhat-00002.jar:/opt/kafka/bin/../libs/checker-qual-3.5.0.jar:/opt/kafka/bin/../libs/commons-cli-1.4.0.redhat-00001.jar:/opt/kafka/bin/../libs/commons-lang-2.6.0.redhat-7.jar:/opt/kafka/bin/../libs/commons-lang3-3.5.0.redhat-00002.jar:/opt/kafka/bin/../libs/commons-math3-3.6.1.redhat-00001.jar:/opt/kafka/bin/../libs/connect-api-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/connect-basic-auth-extension-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/connect-file-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/connect-json-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/connect-mirror-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/connect-mirror-client-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/connect-runtime-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/connect-transforms-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/cruise-control-metrics-reporter-2.5.37.redhat-00003.jar:/opt/kafka/bin/../libs/error_prone_annotations-2.2.0.redhat-00001.jar:/opt/kafka/bin/../libs/failureaccess-1.0.1.redhat-00001.jar:/opt/kafka/bin/../libs/group-authorizer.jar:/opt/kafka/bin/../libs/gson-2.8.6.jar:/opt/kafka/bin/../libs/guava-30.0.0.jre-redhat-00002.jar:/opt/kafka/bin/../libs/hamcrest-core-1.3-redhat-1.jar:/opt/kafka/bin/../libs/hk2-api-2.6.1.redhat-00001.jar:/opt/kafka/bin/../libs/hk2-locator-2.6.1.redhat-00001.jar:/opt/kafka/bin/../libs/hk2-utils-2.6.1.redhat-00001.jar:/opt/kafka/bin/../libs/j2objc-annotations-1.1.0.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-annotations-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-core-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-databind-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-dataformat-csv-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-datatype-jdk8-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-jaxrs-base-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-jaxrs-json-provider-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-module-jaxb-annotations-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-module-paranamer-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jackson-module-scala_2.12-2.11.3.redhat-00001.jar:/opt/kafka/bin/../libs/jaeger-client-1.3.2.jar:/opt/kafka/bin/../libs/jaeger-core-1.3.2.jar:/opt/kafka/bin/../libs/jaeger-thrift-1.3.2.jar:/opt/kafka/bin/../libs/jaeger-tracerresolver-1.3.2.jar:/opt/kafka/bin/../libs/jakarta.activation-api-1.2.1.redhat-00002.jar:/opt/kafka/bin/../libs/jakarta.annotation-api-1.3.5.redhat-00002.jar:/opt/kafka/bin/../libs/jakarta.inject-2.6.1.redhat-00001.jar:/opt/kafka/bin/../libs/jakarta.validation-api-2.0.2.redhat-00001.jar:/opt/kafka/bin/../libs/jakarta.ws.rs-api-2.1.6.redhat-00001.jar:/opt/kafka/bin/../libs/jakarta.xml.bind-api-2.3.2.redhat-00001.jar:/opt/kafka/bin/../libs/javassist-3.26.0.GA-redhat-00001.jar:/opt/kafka/bin/../libs/javax.servlet-api-3.1.0.redhat-1.jar:/opt/kafka/bin/../libs/javax.ws.rs-api-2.1.1.redhat-00002.jar:/opt/kafka/bin/../libs/jaxb-api-2.3.0.redhat-00003.jar:/opt/kafka/bin/../libs/jcip-annotations-1.0.1.redhat-00001.jar:/opt/kafka/bin/../libs/jersey-client-2.31.0.redhat-00001.jar:/opt/kafka/bin/../libs/jersey-common-2.34.0.redhat-00001.jar:/opt/kafka/bin/../libs/jersey-container-servlet-2.31.0.redhat-00001.jar:/opt/kafka/bin/../libs/jersey-container-servlet-core-2.31.0.redhat-00001.jar:/opt/kafka/bin/../libs/jersey-hk2-2.34.0.redhat-00001.jar:/opt/kafka/bin/../libs/jersey-media-jaxb-2.31.0.redhat-00001.jar:/opt/kafka/bin/../libs/jersey-server-2.31.0.redhat-00001.jar:/opt/kafka/bin/../libs/jetty-client-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-continuation-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-http-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-io-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-security-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-server-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-servlet-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-servlets-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-util-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jetty-util-ajax-9.4.41.v20210516-redhat-00001.jar:/opt/kafka/bin/../libs/jmx_prometheus_javaagent-0.14.0.redhat-00002.jar:/opt/kafka/bin/../libs/jopt-simple-5.0.4.redhat-00002.jar:/opt/kafka/bin/../libs/json-path-2.6.0.redhat-00002.jar:/opt/kafka/bin/../libs/json-smart-2.3.0.redhat-00001.jar:/opt/kafka/bin/../libs/jsonevent-layout-1.7.0.redhat-00002.jar:/opt/kafka/bin/../libs/jsr305-3.0.2.redhat-00008.jar:/opt/kafka/bin/../libs/junit-4.13.1.redhat-00001.jar:/opt/kafka/bin/../libs/kafka-agent.jar:/opt/kafka/bin/../libs/kafka-clients-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/kafka-log4j-appender-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/kafka-oauth-client-0.8.1.redhat-00003.jar:/opt/kafka/bin/../libs/kafka-oauth-common-0.8.1.redhat-00003.jar:/opt/kafka/bin/../libs/kafka-oauth-keycloak-authorizer-0.8.1.redhat-00003.jar:/opt/kafka/bin/../libs/kafka-oauth-server-0.8.1.redhat-00003.jar:/opt/kafka/bin/../libs/kafka-oauth-server-plain-0.8.1.redhat-00003.jar:/opt/kafka/bin/../libs/kafka-raft-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/kafka-static-quota-plugin.jar:/opt/kafka/bin/../libs/kafka-streams-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/kafka-streams-scala_2.12-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/kafka-tools-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/kafka_2.12-2.7.0.managedsvc-redhat-00004-sources.jar:/opt/kafka/bin/../libs/kafka_2.12-2.7.0.managedsvc-redhat-00004.jar:/opt/kafka/bin/../libs/kotlin-stdlib-1.3.50.jar:/opt/kafka/bin/../libs/kotlin-stdlib-common-1.3.50.jar:/opt/kafka/bin/../libs/libthrift-0.13.0.jar:/opt/kafka/bin/../libs/listenablefuture-9999.0.0.empty-to-avoid-conflict-with-guava-redhat-00001.jar:/opt/kafka/bin/../libs/log4j-1.2.17.redhat-3.jar:/opt/kafka/bin/../libs/lz4-java-1.7.1.redhat-00002.jar:/opt/kafka/bin/../libs/maven-artifact-3.6.0.redhat-00001.jar:/opt/kafka/bin/../libs/metrics-core-2.2.0.redhat-00003.jar:/opt/kafka/bin/../libs/mirror-maker-2-extensions-0.1.0.redhat-00002.jar:/opt/kafka/bin/../libs/mirror-maker-agent.jar:/opt/kafka/bin/../libs/netty-buffer-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/netty-codec-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/netty-common-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/netty-handler-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/netty-resolver-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/netty-transport-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/netty-transport-native-epoll-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/netty-transport-native-unix-common-4.1.65.Final-redhat-00001.jar:/opt/kafka/bin/../libs/nimbus-jose-jwt-9.10.0.redhat-00002.jar:/opt/kafka/bin/../libs/okhttp-4.2.2.jar:/opt/kafka/bin/../libs/okio-2.2.2.jar:/opt/kafka/bin/../libs/opa-authorizer-0.4.2.redhat-00002.jar:/opt/kafka/bin/../libs/opentracing-api-0.33.0.redhat-00001.jar:/opt/kafka/bin/../libs/opentracing-kafka-client-0.1.15.redhat-00001.jar:/opt/kafka/bin/../libs/opentracing-noop-0.33.0.redhat-00001.jar:/opt/kafka/bin/../libs/opentracing-tracerresolver-0.1.8.jar:/opt/kafka/bin/../libs/opentracing-util-0.33.0.redhat-00001.jar:/opt/kafka/bin/../libs/osgi-resource-locator-1.0.3.redhat-00001.jar:/opt/kafka/bin/../libs/paranamer-2.8.0.redhat-00001.jar:/opt/kafka/bin/../libs/plexus-utils-3.1.0.redhat-00002.jar:/opt/kafka/bin/../libs/reflections-0.9.12.redhat-00001.jar:/opt/kafka/bin/../libs/rocksdbjni-5.18.3.redhat-00002.jar:/opt/kafka/bin/../libs/scala-collection-compat_2.12-2.2.0.redhat-00001.jar:/opt/kafka/bin/../libs/scala-java8-compat_2.12-0.9.0.redhat-00001.jar:/opt/kafka/bin/../libs/scala-library-2.12.13.redhat-00002.jar:/opt/kafka/bin/../libs/scala-logging_2.12-3.9.0.redhat-00008.jar:/opt/kafka/bin/../libs/scala-reflect-2.12.13.redhat-00002.jar:/opt/kafka/bin/../libs/slf4j-api-1.7.26.redhat-00001.jar:/opt/kafka/bin/../libs/slf4j-api-1.7.30.redhat-00001.jar:/opt/kafka/bin/../libs/slf4j-log4j12-1.7.30.redhat-00001.jar:/opt/kafka/bin/../libs/snappy-java-1.1.8.4-redhat-00001.jar:/opt/kafka/bin/../libs/tracing-agent.jar:/opt/kafka/bin/../libs/zookeeper-3.5.9.managedsvc-redhat-00003.jar:/opt/kafka/bin/../libs/zookeeper-jute-3.5.9.managedsvc-redhat-00003.jar:/opt/kafka/bin/../libs/zstd-jni-1.4.3.1-redhat-00002.jar
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:java.library.path=/usr/java/packages/lib:/usr/lib64:/lib64:/lib:/usr/lib
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:java.io.tmpdir=/tmp
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:java.compiler=<NA>
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:os.name=Linux
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:os.arch=amd64
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:os.version=4.18.0-305.10.2.el8_4.x86_64
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:user.name=1000980000
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:user.home=/
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:user.dir=/opt/kafka
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:os.memory.free=3010MB
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:os.memory.max=3072MB
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:109] Client environment:os.memory.total=3072MB
2021-08-25T17:52:43Z INFO [main] [ZooKeeper:868] Initiating client connection, connectString=gryan-zookeeper-client:2181 sessionTimeout=18000 watcher=kafka.zookeeper.ZooKeeperClient$ZooKeeperClientWatcher$@1cbf6e72
2021-08-25T17:52:43Z INFO [main] [ClientCnxnSocket:237] jute.maxbuffer value is 4194304 Bytes
2021-08-25T17:52:43Z INFO [main] [ClientCnxn:1653] zookeeper.request.timeout value is 0. feature enabled=
2021-08-25T17:52:43Z INFO [main] [KafkaAgent:93] Starting poller
2021-08-25T17:52:43Z INFO [main] [ZooKeeperClient:66] [ZooKeeperClient Kafka server] Waiting until connected.
2021-08-25T17:52:43Z INFO [main-SendThread(gryan-zookeeper-client:2181)] [ClientCnxn:1112] Opening socket connection to server gryan-zookeeper-client/172.30.171.47:2181. Will not attempt to authenticate using SASL (unknown error)
2021-08-25T17:52:43Z INFO [nioEventLoopGroup-2-1] [ClientCnxnSocketNetty:480] SSL handler added for channel: [id: 0xc6f9a6b7]
2021-08-25T17:52:43Z INFO [nioEventLoopGroup-2-1] [ClientCnxn:959] Socket connection established, initiating session, client: /10.131.0.35:43348, server: gryan-zookeeper-client/172.30.171.47:2181
2021-08-25T17:52:43Z INFO [nioEventLoopGroup-2-1] [ClientCnxnSocketNetty:196] channel is connected: [id: 0xc6f9a6b7, L:/10.131.0.35:43348 - R:gryan-zookeeper-client/172.30.171.47:2181]
2021-08-25T17:52:43Z INFO [nioEventLoopGroup-2-1] [ClientCnxn:1394] Session establishment complete on server gryan-zookeeper-client/172.30.171.47:2181, sessionid = 0x100006a0a7f0006, negotiated timeout = 18000
2021-08-25T17:52:43Z INFO [main] [ZooKeeperClient:66] [ZooKeeperClient Kafka server] Connected.
2021-08-25T17:52:43Z INFO [feature-zk-node-event-process-thread] [FinalizedFeatureChangeListener$ChangeNotificationProcessorThread:66] [feature-zk-node-event-process-thread]: Starting
2021-08-25T17:52:43Z INFO [feature-zk-node-event-process-thread] [FinalizedFeatureChangeListener:66] Feature ZK node at path: /feature does not exist
2021-08-25T17:52:43Z INFO [feature-zk-node-event-process-thread] [FinalizedFeatureCache:66] Cleared cache
2021-08-25T17:52:44Z INFO [main] [KafkaServer:66] Cluster ID = JZ6NL5y5QP6d8Av9nMmlHA
2021-08-25T17:52:44Z WARN [main] [BrokerMetadataCheckpoint:70] No meta.properties file under dir /var/lib/kafka/data-0/kafka-log1/meta.properties
2021-08-25T17:52:44Z INFO [main] [KafkaConfig:361] KafkaConfig values:
advertised.host.name = null
advertised.listeners = CONTROLPLANE-9090://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9090,REPLICATION-9091://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9091,TLS-9093://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9093,EXTERNAL-9094://broker-1-gryan-c-j--qsqpjo-t--mhs-a.mk.gryan-3az.nvee.s1.devshift.org:443,OAUTH-9095://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9095,SRE-9096://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9096
advertised.port = null
alter.config.policy.class.name = null
alter.log.dirs.replication.quota.window.num = 11
alter.log.dirs.replication.quota.window.size.seconds = 1
authorizer.class.name = io.bf2.kafka.authorizer.GlobalAclAuthorizer
auto.create.topics.enable = false
auto.leader.rebalance.enable = true
background.threads = 10
broker.id = 1
broker.id.generation.enable = true
broker.rack = us-east-2c
client.quota.callback.class = class io.strimzi.kafka.quotas.StaticQuotaCallback
compression.type = producer
connection.failed.authentication.delay.ms = 100
connections.max.idle.ms = 600000
connections.max.reauth.ms = 0
control.plane.listener.name = null
controlled.shutdown.enable = true
controlled.shutdown.max.retries = 3
controlled.shutdown.retry.backoff.ms = 5000
controller.quota.window.num = 11
controller.quota.window.size.seconds = 1
controller.socket.timeout.ms = 30000
create.topic.policy.class.name = null
default.replication.factor = 3
delegation.token.expiry.check.interval.ms = 3600000
delegation.token.expiry.time.ms = 86400000
delegation.token.master.key = null
delegation.token.max.lifetime.ms = 604800000
delete.records.purgatory.purge.interval.requests = 1
delete.topic.enable = true
fetch.max.bytes = 57671680
fetch.purgatory.purge.interval.requests = 1000
group.initial.rebalance.delay.ms = 3000
group.max.session.timeout.ms = 1800000
group.max.size = 2147483647
group.min.session.timeout.ms = 6000
host.name =
inter.broker.listener.name = REPLICATION-9091
inter.broker.protocol.version = 2.7.0
kafka.metrics.polling.interval.secs = 10
kafka.metrics.reporters = []
leader.imbalance.check.interval.seconds = 300
leader.imbalance.per.broker.percentage = 0
listener.security.protocol.map = CONTROLPLANE-9090:SSL,REPLICATION-9091:SSL,TLS-9093:SSL,EXTERNAL-9094:SASL_SSL,OAUTH-9095:SASL_PLAINTEXT,SRE-9096:PLAINTEXT
listeners = CONTROLPLANE-9090://0.0.0.0:9090,REPLICATION-9091://0.0.0.0:9091,TLS-9093://0.0.0.0:9093,EXTERNAL-9094://0.0.0.0:9094,OAUTH-9095://0.0.0.0:9095,SRE-9096://0.0.0.0:9096
log.cleaner.backoff.ms = 15000
log.cleaner.dedupe.buffer.size = 134217728
log.cleaner.delete.retention.ms = 86400000
log.cleaner.enable = true
log.cleaner.io.buffer.load.factor = 0.9
log.cleaner.io.buffer.size = 524288
log.cleaner.io.max.bytes.per.second = 1.7976931348623157E308
log.cleaner.max.compaction.lag.ms = 9223372036854775807
log.cleaner.min.cleanable.ratio = 0.5
log.cleaner.min.compaction.lag.ms = 0
log.cleaner.threads = 1
log.cleanup.policy = [delete]
log.dir = /tmp/kafka-logs
log.dirs = /var/lib/kafka/data-0/kafka-log1
log.flush.interval.messages = 9223372036854775807
log.flush.interval.ms = null
log.flush.offset.checkpoint.interval.ms = 60000
log.flush.scheduler.interval.ms = 9223372036854775807
log.flush.start.offset.checkpoint.interval.ms = 60000
log.index.interval.bytes = 4096
log.index.size.max.bytes = 10485760
log.message.downconversion.enable = true
log.message.format.version = 2.7.0
log.message.timestamp.difference.max.ms = 9223372036854775807
log.message.timestamp.type = CreateTime
log.preallocate = false
log.retention.bytes = -1
log.retention.check.interval.ms = 300000
log.retention.hours = 168
log.retention.minutes = null
log.retention.ms = null
log.roll.hours = 168
log.roll.jitter.hours = 0
log.roll.jitter.ms = null
log.roll.ms = null
log.segment.bytes = 1073741824
log.segment.delete.delay.ms = 60000
max.connection.creation.rate = 2147483647
max.connections = 2147483647
max.connections.per.ip = 2147483647
max.connections.per.ip.overrides =
max.incremental.fetch.session.cache.slots = 1000
message.max.bytes = 1048588
metric.reporters = []
metrics.num.samples = 2
metrics.recording.level = INFO
metrics.sample.window.ms = 30000
min.insync.replicas = 2
num.io.threads = 8
num.network.threads = 3
num.partitions = 1
num.recovery.threads.per.data.dir = 1
num.replica.alter.log.dirs.threads = null
num.replica.fetchers = 1
offset.metadata.max.bytes = 4096
offsets.commit.required.acks = -1
offsets.commit.timeout.ms = 5000
offsets.load.buffer.size = 5242880
offsets.retention.check.interval.ms = 600000
offsets.retention.minutes = 10080
offsets.topic.compression.codec = 0
offsets.topic.num.partitions = 50
offsets.topic.replication.factor = 3
offsets.topic.segment.bytes = 104857600
password.encoder.cipher.algorithm = AES/CBC/PKCS5Padding
password.encoder.iterations = 4096
password.encoder.key.length = 128
password.encoder.keyfactory.algorithm = null
password.encoder.old.secret = null
password.encoder.secret = null
port = 9092
principal.builder.class = class io.strimzi.kafka.oauth.server.OAuthKafkaPrincipalBuilder
producer.purgatory.purge.interval.requests = 1000
queued.max.request.bytes = -1
queued.max.requests = 500
quota.consumer.default = 9223372036854775807
quota.producer.default = 9223372036854775807
quota.window.num = 30
quota.window.size.seconds = 2
replica.fetch.backoff.ms = 1000
replica.fetch.max.bytes = 1048576
replica.fetch.min.bytes = 1
replica.fetch.response.max.bytes = 10485760
replica.fetch.wait.max.ms = 500
replica.high.watermark.checkpoint.interval.ms = 5000
replica.lag.time.max.ms = 30000
replica.selector.class = null
replica.socket.receive.buffer.bytes = 65536
replica.socket.timeout.ms = 30000
replication.quota.window.num = 11
replication.quota.window.size.seconds = 1
request.timeout.ms = 30000
reserved.broker.max.id = 1000
sasl.client.callback.handler.class = null
sasl.enabled.mechanisms = []
sasl.jaas.config = null
sasl.kerberos.kinit.cmd = /usr/bin/kinit
sasl.kerberos.min.time.before.relogin = 60000
sasl.kerberos.principal.to.local.rules = [DEFAULT]
sasl.kerberos.service.name = null
sasl.kerberos.ticket.renew.jitter = 0.05
sasl.kerberos.ticket.renew.window.factor = 0.8
sasl.login.callback.handler.class = null
sasl.login.class = null
sasl.login.refresh.buffer.seconds = 300
sasl.login.refresh.min.period.seconds = 60
sasl.login.refresh.window.factor = 0.8
sasl.login.refresh.window.jitter = 0.05
sasl.mechanism.inter.broker.protocol = GSSAPI
sasl.server.callback.handler.class = null
security.inter.broker.protocol = PLAINTEXT
security.providers = null
socket.connection.setup.timeout.max.ms = 127000
socket.connection.setup.timeout.ms = 10000
socket.receive.buffer.bytes = 102400
socket.request.max.bytes = 104857600
socket.send.buffer.bytes = 102400
ssl.cipher.suites = []
ssl.client.auth = none
ssl.enabled.protocols = [TLSv1.3, TLSv1.2]
ssl.endpoint.identification.algorithm = HTTPS
ssl.engine.factory.class = null
ssl.key.password = null
ssl.keymanager.algorithm = SunX509
ssl.keystore.certificate.chain = null
ssl.keystore.key = null
ssl.keystore.location = null
ssl.keystore.password = null
ssl.keystore.type = JKS
ssl.principal.mapping.rules = DEFAULT
ssl.protocol = TLS
ssl.provider = null
ssl.secure.random.implementation = SHA1PRNG
ssl.trustmanager.algorithm = PKIX
ssl.truststore.certificates = null
ssl.truststore.location = null
ssl.truststore.password = null
ssl.truststore.type = JKS
transaction.abort.timed.out.transaction.cleanup.interval.ms = 10000
transaction.max.timeout.ms = 900000
transaction.remove.expired.transaction.cleanup.interval.ms = 3600000
transaction.state.log.load.buffer.size = 5242880
transaction.state.log.min.isr = 2
transaction.state.log.num.partitions = 50
transaction.state.log.replication.factor = 3
transaction.state.log.segment.bytes = 104857600
transactional.id.expiration.ms = 604800000
unclean.leader.election.enable = false
zookeeper.clientCnxnSocket = org.apache.zookeeper.ClientCnxnSocketNetty
zookeeper.connect = gryan-zookeeper-client:2181
zookeeper.connection.timeout.ms = null
zookeeper.max.in.flight.requests = 10
zookeeper.session.timeout.ms = 18000
zookeeper.set.acl = false
zookeeper.ssl.cipher.suites = null
zookeeper.ssl.client.enable = true
zookeeper.ssl.crl.enable = false
zookeeper.ssl.enabled.protocols = null
zookeeper.ssl.endpoint.identification.algorithm = HTTPS
zookeeper.ssl.keystore.location = /tmp/kafka/cluster.keystore.p12
zookeeper.ssl.keystore.password = [hidden]
zookeeper.ssl.keystore.type = PKCS12
zookeeper.ssl.ocsp.enable = false
zookeeper.ssl.protocol = TLSv1.2
zookeeper.ssl.truststore.location = /tmp/kafka/cluster.truststore.p12
zookeeper.ssl.truststore.password = [hidden]
zookeeper.ssl.truststore.type = PKCS12
zookeeper.sync.time.ms = 2000
2021-08-25T17:52:44Z INFO [main] [KafkaConfig:361] KafkaConfig values:
advertised.host.name = null
advertised.listeners = CONTROLPLANE-9090://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9090,REPLICATION-9091://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9091,TLS-9093://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9093,EXTERNAL-9094://broker-1-gryan-c-j--qsqpjo-t--mhs-a.mk.gryan-3az.nvee.s1.devshift.org:443,OAUTH-9095://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9095,SRE-9096://gryan-kafka-1.gryan-kafka-brokers.mk-c4j84qsqpjo5t62mhs30.svc:9096
advertised.port = null
alter.config.policy.class.name = null
alter.log.dirs.replication.quota.window.num = 11
alter.log.dirs.replication.quota.window.size.seconds = 1
authorizer.class.name = io.bf2.kafka.authorizer.GlobalAclAuthorizer
auto.create.topics.enable = false
auto.leader.rebalance.enable = true
background.threads = 10
broker.id = 1
broker.id.generation.enable = true
broker.rack = us-east-2c
client.quota.callback.class = class io.strimzi.kafka.quotas.StaticQuotaCallback
compression.type = producer
connection.failed.authentication.delay.ms = 100
connections.max.idle.ms = 600000
connections.max.reauth.ms = 0
control.plane.listener.name = null
controlled.shutdown.enable = true
controlled.shutdown.max.retries = 3
controlled.shutdown.retry.backoff.ms = 5000
controller.quota.window.num = 11
controller.quota.window.size.seconds = 1
controller.socket.timeout.ms = 30000
create.topic.policy.class.name = null
default.replication.factor = 3
delegation.token.expiry.check.interval.ms = 3600000
delegation.token.expiry.time.ms = 86400000
delegation.token.master.key = null
delegation.token.max.lifetime.ms = 604800000
delete.records.purgatory.purge.interval.requests = 1
delete.topic.enable = true
fetch.max.bytes = 57671680
fetch.purgatory.purge.interval.requests = 1000
group.initial.rebalance.delay.ms = 3000
group.max.session.timeout.ms = 1800000
group.max.size = 2147483647
group.min.session.timeout.ms = 6000
host.name =
inter.broker.listener.name = REPLICATION-9091
inter.broker.protocol.version = 2.7.0
kafka.metrics.polling.interval.secs = 10
kafka.metrics.reporters = []
leader.imbalance.check.interval.seconds = 300
leader.imbalance.per.broker.percentage = 0
listener.security.protocol.map = CONTROLPLANE-9090:SSL,REPLICATION-9091:SSL,TLS-9093:SSL,EXTERNAL-9094:SASL_SSL,OAUTH-9095:SASL_PLAINTEXT,SRE-9096:PLAINTEXT
listeners = CONTROLPLANE-9090://0.0.0.0:9090,REPLICATION-9091://0.0.0.0:9091,TLS-9093://0.0.0.0:9093,EXTERNAL-9094://0.0.0.0:9094,OAUTH-9095://0.0.0.0:9095,SRE-9096://0.0.0.0:9096
log.cleaner.backoff.ms = 15000
log.cleaner.dedupe.buffer.size = 134217728
log.cleaner.delete.retention.ms = 86400000
log.cleaner.enable = true
log.cleaner.io.buffer.load.factor = 0.9
log.cleaner.io.buffer.size = 524288
log.cleaner.io.max.bytes.per.second = 1.7976931348623157E308
log.cleaner.max.compaction.lag.ms = 9223372036854775807
log.cleaner.min.cleanable.ratio = 0.5
log.cleaner.min.compaction.lag.ms = 0
log.cleaner.threads = 1
log.cleanup.policy = [delete]
log.dir = /tmp/kafka-logs
log.dirs = /var/lib/kafka/data-0/kafka-log1
log.flush.interval.messages = 9223372036854775807
log.flush.interval.ms = null
log.flush.offset.checkpoint.interval.ms = 60000
log.flush.scheduler.interval.ms = 9223372036854775807
log.flush.start.offset.checkpoint.interval.ms = 60000
log.index.interval.bytes = 4096
log.index.size.max.bytes = 10485760
log.message.downconversion.enable = true
log.message.format.version = 2.7.0
log.message.timestamp.difference.max.ms = 9223372036854775807
log.message.timestamp.type = CreateTime
log.preallocate = false
log.retention.bytes = -1
log.retention.check.interval.ms = 300000
log.retention.hours = 168
log.retention.minutes = null
log.retention.ms = null
log.roll.hours = 168
log.roll.jitter.hours = 0
log.roll.jitter.ms = null
log.roll.ms = null
log.segment.bytes = 1073741824
log.segment.delete.delay.ms = 60000
max.connection.creation.rate = 2147483647
max.connections = 2147483647
max.connections.per.ip = 2147483647
max.connections.per.ip.overrides =
max.incremental.fetch.session.cache.slots = 1000
message.max.bytes = 1048588
metric.reporters = []
metrics.num.samples = 2
metrics.recording.level = INFO
metrics.sample.window.ms = 30000
min.insync.replicas = 2
num.io.threads = 8
num.network.threads = 3
num.partitions = 1
num.recovery.threads.per.data.dir = 1
num.replica.alter.log.dirs.threads = null
num.replica.fetchers = 1
offset.metadata.max.bytes = 4096
offsets.commit.required.acks = -1
offsets.commit.timeout.ms = 5000
offsets.load.buffer.size = 5242880
offsets.retention.check.interval.ms = 600000
offsets.retention.minutes = 10080
offsets.topic.compression.codec = 0
offsets.topic.num.partitions = 50
offsets.topic.replication.factor = 3
offsets.topic.segment.bytes = 104857600
password.encoder.cipher.algorithm = AES/CBC/PKCS5Padding
password.encoder.iterations = 4096
password.encoder.key.length = 128
password.encoder.keyfactory.algorithm = null
password.encoder.old.secret = null
password.encoder.secret = null
port = 9092
principal.builder.class = class io.strimzi.kafka.oauth.server.OAuthKafkaPrincipalBuilder
producer.purgatory.purge.interval.requests = 1000
queued.max.request.bytes = -1
queued.max.requests = 500
quota.consumer.default = 9223372036854775807
quota.producer.default = 9223372036854775807
quota.window.num = 30
quota.window.size.seconds = 2
replica.fetch.backoff.ms = 1000
replica.fetch.max.bytes = 1048576
replica.fetch.min.bytes = 1
replica.fetch.response.max.bytes = 10485760
replica.fetch.wait.max.ms = 500
replica.high.watermark.checkpoint.interval.ms = 5000
replica.lag.time.max.ms = 30000
replica.selector.class = null
replica.socket.receive.buffer.bytes = 65536
replica.socket.timeout.ms = 30000
replication.quota.window.num = 11
replication.quota.window.size.seconds = 1
request.timeout.ms = 30000
reserved.broker.max.id = 1000
sasl.client.callback.handler.class = null
sasl.enabled.mechanisms = []
sasl.jaas.config = null
sasl.kerberos.kinit.cmd = /usr/bin/kinit
sasl.kerberos.min.time.before.relogin = 60000
sasl.kerberos.principal.to.local.rules = [DEFAULT]
sasl.kerberos.service.name = null
sasl.kerberos.ticket.renew.jitter = 0.05
sasl.kerberos.ticket.renew.window.factor = 0.8
sasl.login.callback.handler.class = null
sasl.login.class = null
sasl.login.refresh.buffer.seconds = 300
sasl.login.refresh.min.period.seconds = 60
sasl.login.refresh.window.factor = 0.8
sasl.login.refresh.window.jitter = 0.05
sasl.mechanism.inter.broker.protocol = GSSAPI
sasl.server.callback.handler.class = null
security.inter.broker.protocol = PLAINTEXT
security.providers = null
socket.connection.setup.timeout.max.ms = 127000
socket.connection.setup.timeout.ms = 10000
socket.receive.buffer.bytes = 102400
socket.request.max.bytes = 104857600
socket.send.buffer.bytes = 102400
ssl.cipher.suites = []
ssl.client.auth = none
ssl.enabled.protocols = [TLSv1.3, TLSv1.2]
ssl.endpoint.identification.algorithm = HTTPS
ssl.engine.factory.class = null
ssl.key.password = null
ssl.keymanager.algorithm = SunX509
ssl.keystore.certificate.chain = null
ssl.keystore.key = null
ssl.keystore.location = null
ssl.keystore.password = null
ssl.keystore.type = JKS
ssl.principal.mapping.rules = DEFAULT
ssl.protocol = TLS
ssl.provider = null
ssl.secure.random.implementation = SHA1PRNG
ssl.trustmanager.algorithm = PKIX
ssl.truststore.certificates = null
ssl.truststore.location = null
ssl.truststore.password = null
ssl.truststore.type = JKS
transaction.abort.timed.out.transaction.cleanup.interval.ms = 10000
transaction.max.timeout.ms = 900000
transaction.remove.expired.transaction.cleanup.interval.ms = 3600000
transaction.state.log.load.buffer.size = 5242880
transaction.state.log.min.isr = 2
transaction.state.log.num.partitions = 50
transaction.state.log.replication.factor = 3
transaction.state.log.segment.bytes = 104857600
transactional.id.expiration.ms = 604800000
unclean.leader.election.enable = false
zookeeper.clientCnxnSocket = org.apache.zookeeper.ClientCnxnSocketNetty
zookeeper.connect = gryan-zookeeper-client:2181
zookeeper.connection.timeout.ms = null
zookeeper.max.in.flight.requests = 10
zookeeper.session.timeout.ms = 18000
zookeeper.set.acl = false
zookeeper.ssl.cipher.suites = null
zookeeper.ssl.client.enable = true
zookeeper.ssl.crl.enable = false
zookeeper.ssl.enabled.protocols = null
zookeeper.ssl.endpoint.identification.algorithm = HTTPS
zookeeper.ssl.keystore.location = /tmp/kafka/cluster.keystore.p12
zookeeper.ssl.keystore.password = [hidden]
zookeeper.ssl.keystore.type = PKCS12
zookeeper.ssl.ocsp.enable = false
zookeeper.ssl.protocol = TLSv1.2
zookeeper.ssl.truststore.location = /tmp/kafka/cluster.truststore.p12
zookeeper.ssl.truststore.password = [hidden]
zookeeper.ssl.truststore.type = PKCS12
zookeeper.sync.time.ms = 2000
2021-08-25T17:52:44Z INFO [main] [StaticQuotaConfig:361] StaticQuotaConfig values:
client.quota.callback.static.disable-quota-anonymous = true
client.quota.callback.static.fetch = 699050.0
client.quota.callback.static.produce = 699050.0
client.quota.callback.static.request = 1.7976931348623157E308
client.quota.callback.static.storage.check-interval = 30
client.quota.callback.static.storage.hard = 30601641984
client.quota.callback.static.storage.soft = 28991029248
log.dirs = /var/lib/kafka/data-0/kafka-log1
2021-08-25T17:52:44Z INFO [main] [StaticQuotaCallback:123] Configured quota callback with {PRODUCE=upper=699050.0, FETCH=upper=699050.0, REQUEST=upper=1.7976931348623157E308}. Storage quota (soft, hard): (28991029248, 30601641984). Storage check interval: 30. Disable quota for anonymous: true
2021-08-25T17:52:44Z INFO [ThrottledChannelReaper-Fetch] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Fetch]: Starting
2021-08-25T17:52:44Z INFO [ThrottledChannelReaper-Produce] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Produce]: Starting
2021-08-25T17:52:44Z INFO [ThrottledChannelReaper-Request] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Request]: Starting
2021-08-25T17:52:44Z INFO [ThrottledChannelReaper-ControllerMutation] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-ControllerMutation]: Starting
2021-08-25T17:52:44Z INFO [main] [LogManager:66] Loading logs from log dirs ArrayBuffer(/var/lib/kafka/data-0/kafka-log1)
2021-08-25T17:52:44Z INFO [main] [LogManager:66] Skipping recovery for all logs in /var/lib/kafka/data-0/kafka-log1 since clean shutdown file was found
2021-08-25T17:52:44Z INFO [main] [LogManager:66] Loaded 0 logs in 12ms.
2021-08-25T17:52:44Z INFO [main] [LogManager:66] Starting log cleanup with a period of 300000 ms.
2021-08-25T17:52:44Z INFO [main] [LogManager:66] Starting log flusher with a default period of 9223372036854775807 ms.
2021-08-25T17:52:44Z INFO [main] [LogCleaner:66] Starting the log cleaner
2021-08-25T17:52:44Z INFO [kafka-log-cleaner-thread-0] [LogCleaner:66] [kafka-log-cleaner-thread-0]: Starting
2021-08-25T17:52:44Z INFO [main] [ConnectionQuotas:66] Created ConnectionAcceptRate sensor, quotaLimit=2147483647
2021-08-25T17:52:44Z INFO [main] [ConnectionQuotas:66] Created ConnectionAcceptRate-CONTROLPLANE-9090 sensor, quotaLimit=2147483647
2021-08-25T17:52:44Z INFO [main] [ConnectionQuotas:66] Updated CONTROLPLANE-9090 max connection creation rate to 2147483647
2021-08-25T17:52:44Z INFO [main] [Acceptor:66] Awaiting socket connections on 0.0.0.0:9090.
2021-08-25T17:52:44Z INFO [main] [SocketServer:66] [SocketServer brokerId=1] Created data-plane acceptor and processors for endpoint : ListenerName(CONTROLPLANE-9090)
2021-08-25T17:52:44Z INFO [main] [ConnectionQuotas:66] Created ConnectionAcceptRate-REPLICATION-9091 sensor, quotaLimit=2147483647
2021-08-25T17:52:44Z INFO [main] [ConnectionQuotas:66] Updated REPLICATION-9091 max connection creation rate to 2147483647
2021-08-25T17:52:44Z INFO [main] [Acceptor:66] Awaiting socket connections on 0.0.0.0:9091.
2021-08-25T17:52:45Z INFO [main] [SocketServer:66] [SocketServer brokerId=1] Created data-plane acceptor and processors for endpoint : ListenerName(REPLICATION-9091)
2021-08-25T17:52:45Z INFO [main] [ConnectionQuotas:66] Created ConnectionAcceptRate-TLS-9093 sensor, quotaLimit=2147483647
2021-08-25T17:52:45Z INFO [main] [ConnectionQuotas:66] Updated TLS-9093 max connection creation rate to 2147483647
2021-08-25T17:52:45Z INFO [main] [Acceptor:66] Awaiting socket connections on 0.0.0.0:9093.
2021-08-25T17:52:45Z INFO [main] [SocketServer:66] [SocketServer brokerId=1] Created data-plane acceptor and processors for endpoint : ListenerName(TLS-9093)
2021-08-25T17:52:45Z INFO [main] [ConnectionQuotas:66] Created ConnectionAcceptRate-EXTERNAL-9094 sensor, quotaLimit=2147483647
2021-08-25T17:52:45Z INFO [main] [ConnectionQuotas:66] Updated EXTERNAL-9094 max connection creation rate to 33
2021-08-25T17:52:45Z INFO [main] [Acceptor:66] Awaiting socket connections on 0.0.0.0:9094.
2021-08-25T17:52:45Z ERROR [main] [KafkaServer:159] [KafkaServer id=1] Fatal error during KafkaServer startup. Prepare to shutdown
org.apache.kafka.common.KafkaException: java.lang.RuntimeException: Failed to fetch public keys needed to validate JWT signatures: https://keycloak-mas-sso.apps.gryan-3az.nvee.s1.devshift.org/auth/realms/rhoas/protocol/openid-connect/certs
at org.apache.kafka.common.network.SaslChannelBuilder.configure(SaslChannelBuilder.java:172)
at org.apache.kafka.common.network.ChannelBuilders.create(ChannelBuilders.java:157)
at org.apache.kafka.common.network.ChannelBuilders.serverChannelBuilder(ChannelBuilders.java:97)
at kafka.network.Processor.<init>(SocketServer.scala:790)
at kafka.network.SocketServer.newProcessor(SocketServer.scala:415)
at kafka.network.SocketServer.$anonfun$addDataPlaneProcessors$1(SocketServer.scala:288)
at kafka.network.SocketServer.addDataPlaneProcessors(SocketServer.scala:287)
at kafka.network.SocketServer.$anonfun$createDataPlaneAcceptorsAndProcessors$1(SocketServer.scala:254)
at kafka.network.SocketServer.$anonfun$createDataPlaneAcceptorsAndProcessors$1$adapted(SocketServer.scala:251)
at scala.collection.mutable.ResizableArray.foreach(ResizableArray.scala:62)
at scala.collection.mutable.ResizableArray.foreach$(ResizableArray.scala:55)
at scala.collection.mutable.ArrayBuffer.foreach(ArrayBuffer.scala:49)
at kafka.network.SocketServer.createDataPlaneAcceptorsAndProcessors(SocketServer.scala:251)
at kafka.network.SocketServer.startup(SocketServer.scala:125)
at kafka.server.KafkaServer.startup(KafkaServer.scala:303)
at kafka.server.KafkaServerStartable.startup(KafkaServerStartable.scala:44)
at kafka.Kafka$.main(Kafka.scala:82)
at kafka.Kafka.main(Kafka.scala)
Caused by: java.lang.RuntimeException: Failed to fetch public keys needed to validate JWT signatures: https://keycloak-mas-sso.apps.gryan-3az.nvee.s1.devshift.org/auth/realms/rhoas/protocol/openid-connect/certs
at io.strimzi.kafka.oauth.validator.JWTSignatureValidator.fetchKeys(JWTSignatureValidator.java:259)
at io.strimzi.kafka.oauth.validator.JWTSignatureValidator.<init>(JWTSignatureValidator.java:145)
at io.strimzi.kafka.oauth.server.JaasServerOauthValidatorCallbackHandler.lambda$configure$0(JaasServerOauthValidatorCallbackHandler.java:282)
at io.strimzi.kafka.oauth.services.Validators.lambda$get$0(Validators.java:17)
at java.base/java.util.concurrent.ConcurrentHashMap.computeIfAbsent(ConcurrentHashMap.java:1705)
at io.strimzi.kafka.oauth.services.Validators.get(Validators.java:17)
at io.strimzi.kafka.oauth.server.JaasServerOauthValidatorCallbackHandler.configure(JaasServerOauthValidatorCallbackHandler.java:333)
at io.strimzi.kafka.oauth.server.plain.JaasServerOauthOverPlainValidatorCallbackHandler.configure(JaasServerOauthOverPlainValidatorCallbackHandler.java:141)
at org.apache.kafka.common.network.SaslChannelBuilder.configure(SaslChannelBuilder.java:139)
... 17 more
Caused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:131)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:349)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:292)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:287)
at java.base/sun.security.ssl.CertificateMessage$T13CertificateConsumer.checkServerCerts(CertificateMessage.java:1357)
at java.base/sun.security.ssl.CertificateMessage$T13CertificateConsumer.onConsumeCertificate(CertificateMessage.java:1232)
at java.base/sun.security.ssl.CertificateMessage$T13CertificateConsumer.consume(CertificateMessage.java:1175)
at java.base/sun.security.ssl.SSLHandshake.consume(SSLHandshake.java:392)
at java.base/sun.security.ssl.HandshakeContext.dispatch(HandshakeContext.java:443)
at java.base/sun.security.ssl.HandshakeContext.dispatch(HandshakeContext.java:421)
at java.base/sun.security.ssl.TransportContext.dispatch(TransportContext.java:182)
at java.base/sun.security.ssl.SSLTransport.decode(SSLTransport.java:172)
at java.base/sun.security.ssl.SSLSocketImpl.decode(SSLSocketImpl.java:1426)
at java.base/sun.security.ssl.SSLSocketImpl.readHandshakeRecord(SSLSocketImpl.java:1336)
at java.base/sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:450)
at java.base/sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:421)
at java.base/sun.net.www.protocol.https.HttpsClient.afterConnect(HttpsClient.java:572)
at java.base/sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:197)
at java.base/sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(HttpsURLConnectionImpl.java:168)
at io.strimzi.kafka.oauth.common.HttpUtil.request(HttpUtil.java:132)
at io.strimzi.kafka.oauth.common.HttpUtil.request(HttpUtil.java:86)
at io.strimzi.kafka.oauth.common.HttpUtil.get(HttpUtil.java:50)
at io.strimzi.kafka.oauth.validator.JWTSignatureValidator.fetchKeys(JWTSignatureValidator.java:232)
... 25 more
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at java.base/sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:439)
at java.base/sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:306)
at java.base/sun.security.validator.Validator.validate(Validator.java:264)
at java.base/sun.security.ssl.X509TrustManagerImpl.validate(X509TrustManagerImpl.java:313)
at java.base/sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:222)
at java.base/sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:129)
at java.base/sun.security.ssl.CertificateMessage$T13CertificateConsumer.checkServerCerts(CertificateMessage.java:1341)
... 43 more
Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at java.base/sun.security.provider.certpath.SunCertPathBuilder.build(SunCertPathBuilder.java:141)
at java.base/sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:126)
at java.base/java.security.cert.CertPathBuilder.build(CertPathBuilder.java:297)
at java.base/sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:434)
... 49 more
2021-08-25T17:52:45Z INFO [main] [KafkaServer:66] [KafkaServer id=1] shutting down
2021-08-25T17:52:45Z INFO [main] [SocketServer:66] [SocketServer brokerId=1] Stopping socket server request processors
2021-08-25T17:52:45Z INFO [main] [SocketServer:66] [SocketServer brokerId=1] Stopped socket server request processors
2021-08-25T17:52:45Z INFO [main] [LogManager:66] Shutting down.
2021-08-25T17:52:45Z INFO [main] [LogCleaner:66] Shutting down the log cleaner.
2021-08-25T17:52:45Z INFO [main] [LogCleaner:66] [kafka-log-cleaner-thread-0]: Shutting down
2021-08-25T17:52:45Z INFO [kafka-log-cleaner-thread-0] [LogCleaner:66] [kafka-log-cleaner-thread-0]: Stopped
2021-08-25T17:52:45Z INFO [main] [LogCleaner:66] [kafka-log-cleaner-thread-0]: Shutdown completed
2021-08-25T17:52:45Z INFO [main] [LogManager:66] Shutdown complete.
2021-08-25T17:52:45Z INFO [main] [FinalizedFeatureChangeListener$ChangeNotificationProcessorThread:66] [feature-zk-node-event-process-thread]: Shutting down
2021-08-25T17:52:45Z INFO [main] [FinalizedFeatureChangeListener$ChangeNotificationProcessorThread:66] [feature-zk-node-event-process-thread]: Shutdown completed
2021-08-25T17:52:45Z INFO [feature-zk-node-event-process-thread] [FinalizedFeatureChangeListener$ChangeNotificationProcessorThread:66] [feature-zk-node-event-process-thread]: Stopped
2021-08-25T17:52:45Z INFO [main] [ZooKeeperClient:66] [ZooKeeperClient Kafka server] Closing.
2021-08-25T17:52:45Z INFO [main] [ClientCnxnSocketNetty:273] channel is told closing
2021-08-25T17:52:45Z INFO [nioEventLoopGroup-2-1] [ClientCnxnSocketNetty:493] channel is disconnected: [id: 0xc6f9a6b7, L:/10.131.0.35:43348 ! R:gryan-zookeeper-client/172.30.171.47:2181]
2021-08-25T17:52:45Z INFO [nioEventLoopGroup-2-1] [ClientCnxnSocketNetty:273] channel is told closing
2021-08-25T17:52:45Z INFO [main] [ZooKeeper:1422] Session: 0x100006a0a7f0006 closed
2021-08-25T17:52:45Z INFO [main-EventThread] [ClientCnxn:524] EventThread shut down for session: 0x100006a0a7f0006
2021-08-25T17:52:45Z INFO [main] [ZooKeeperClient:66] [ZooKeeperClient Kafka server] Closed.
2021-08-25T17:52:45Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Fetch]: Shutting down
2021-08-25T17:52:46Z INFO [ThrottledChannelReaper-Fetch] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Fetch]: Stopped
2021-08-25T17:52:46Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Fetch]: Shutdown completed
2021-08-25T17:52:46Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Produce]: Shutting down
2021-08-25T17:52:47Z INFO [ThrottledChannelReaper-Produce] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Produce]: Stopped
2021-08-25T17:52:47Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Produce]: Shutdown completed
2021-08-25T17:52:47Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Request]: Shutting down
2021-08-25T17:52:47Z INFO [ThrottledChannelReaper-Request] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Request]: Stopped
2021-08-25T17:52:47Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-Request]: Shutdown completed
2021-08-25T17:52:47Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-ControllerMutation]: Shutting down
2021-08-25T17:52:47Z INFO [main] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-ControllerMutation]: Shutdown completed
2021-08-25T17:52:47Z INFO [ThrottledChannelReaper-ControllerMutation] [ClientQuotaManager$ThrottledChannelReaper:66] [ThrottledChannelReaper-ControllerMutation]: Stopped
2021-08-25T17:52:47Z INFO [main] [SocketServer:66] [SocketServer brokerId=1] Shutting down socket server
2021-08-25T17:52:47Z INFO [main] [SocketServer:66] [SocketServer brokerId=1] Shutdown completed
2021-08-25T17:52:47Z INFO [main] [Metrics:668] Metrics scheduler closed
2021-08-25T17:52:47Z INFO [main] [Metrics:672] Closing reporter org.apache.kafka.common.metrics.JmxReporter
2021-08-25T17:52:47Z INFO [main] [Metrics:678] Metrics reporters closed
2021-08-25T17:52:47Z INFO [main] [BrokerTopicStats:66] Broker and topic stats closed
2021-08-25T17:52:47Z INFO [main] [AppInfoParser:83] App info kafka.server for 1 unregistered
2021-08-25T17:52:47Z INFO [main] [KafkaServer:66] [KafkaServer id=1] shut down completed
2021-08-25T17:52:47Z ERROR [main] [KafkaServerStartable:143] Exiting Kafka.
2021-08-25T17:52:47Z INFO [kafka-shutdown-hook] [KafkaServer:66] [KafkaServer id=1] shutting down
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment