Follow-up to #3549, which carried this as its last acceptance criterion.
Summary
No test runs a real Kafka client that authenticates with SASL and then produces and consumes through the bridge. The SASL tests in gateways/kafka/tests/kafka_client_e2e_tests.rs stop after authenticating and listing metadata, and the Fetch tests in #4336 run with SASL off.
Depends on
Scope
Out of scope
Requests still run as the bridge's service account, not as the authenticated principal, so this proves the paths work together, not that permissions are enforced per user. See "Planned: authorization errors" in gateways/kafka/docs/AUTHENTICATION.md.
Follow-up to #3549, which carried this as its last acceptance criterion.
Summary
No test runs a real Kafka client that authenticates with SASL and then produces and consumes through the bridge. The SASL tests in
gateways/kafka/tests/kafka_client_e2e_tests.rsstop after authenticating and listing metadata, and the Fetch tests in #4336 run with SASL off.Depends on
NOT_LEADER_OR_FOLLOWER(6), so nothing can be consumed.Scope
IGGY_KAFKA_SASL_ENABLED=trueand the bridge enabled, against a realiggy-serverSASL_PLAINTEXTand reads the records back in orderOut of scope
Requests still run as the bridge's service account, not as the authenticated principal, so this proves the paths work together, not that permissions are enforced per user. See "Planned: authorization errors" in
gateways/kafka/docs/AUTHENTICATION.md.