kafka-ui-jmx-secured.yml 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134
  1. ---
  2. version: '2'
  3. services:
  4. kafka-ui:
  5. container_name: kafka-ui
  6. image: provectuslabs/kafka-ui:latest
  7. ports:
  8. - 8080:8080
  9. - 5005:5005
  10. depends_on:
  11. - kafka0
  12. - schemaregistry0
  13. - kafka-connect0
  14. environment:
  15. KAFKA_CLUSTERS_0_NAME: local
  16. KAFKA_CLUSTERS_0_BOOTSTRAPSERVERS: kafka0:29092
  17. KAFKA_CLUSTERS_0_SCHEMAREGISTRY: http://schemaregistry0:8085
  18. KAFKA_CLUSTERS_0_KAFKACONNECT_0_NAME: first
  19. KAFKA_CLUSTERS_0_KAFKACONNECT_0_ADDRESS: http://kafka-connect0:8083
  20. KAFKA_CLUSTERS_0_METRICS_PORT: 9997
  21. KAFKA_CLUSTERS_0_METRICS_SSL: 'true'
  22. KAFKA_CLUSTERS_0_METRICS_USERNAME: root
  23. KAFKA_CLUSTERS_0_METRICS_PASSWORD: password
  24. JAVA_OPTS: >-
  25. -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=*:5005
  26. -Djavax.net.ssl.trustStore=/jmx/clienttruststore
  27. -Djavax.net.ssl.trustStorePassword=12345678
  28. -Djavax.net.ssl.keyStore=/jmx/clientkeystore
  29. -Djavax.net.ssl.keyStorePassword=12345678
  30. volumes:
  31. - ./jmx/clienttruststore:/jmx/clienttruststore
  32. - ./jmx/clientkeystore:/jmx/clientkeystore
  33. kafka0:
  34. image: confluentinc/cp-kafka:7.2.1
  35. hostname: kafka0
  36. container_name: kafka0
  37. ports:
  38. - 9092:9092
  39. - 9997:9997
  40. environment:
  41. KAFKA_BROKER_ID: 1
  42. KAFKA_LISTENER_SECURITY_PROTOCOL_MAP: 'CONTROLLER:PLAINTEXT,PLAINTEXT:PLAINTEXT,PLAINTEXT_HOST:PLAINTEXT'
  43. KAFKA_ADVERTISED_LISTENERS: 'PLAINTEXT://kafka0:29092,PLAINTEXT_HOST://localhost:9092'
  44. KAFKA_OFFSETS_TOPIC_REPLICATION_FACTOR: 1
  45. KAFKA_GROUP_INITIAL_REBALANCE_DELAY_MS: 0
  46. KAFKA_TRANSACTION_STATE_LOG_MIN_ISR: 1
  47. KAFKA_TRANSACTION_STATE_LOG_REPLICATION_FACTOR: 1
  48. KAFKA_JMX_PORT: 9997
  49. KAFKA_PROCESS_ROLES: 'broker,controller'
  50. KAFKA_NODE_ID: 1
  51. KAFKA_CONTROLLER_QUORUM_VOTERS: '1@kafka0:29093'
  52. KAFKA_LISTENERS: 'PLAINTEXT://kafka0:29092,CONTROLLER://kafka0:29093,PLAINTEXT_HOST://0.0.0.0:9092'
  53. KAFKA_INTER_BROKER_LISTENER_NAME: 'PLAINTEXT'
  54. KAFKA_CONTROLLER_LISTENER_NAMES: 'CONTROLLER'
  55. KAFKA_LOG_DIRS: '/tmp/kraft-combined-logs'
  56. # CHMOD 700 FOR JMXREMOTE.* FILES
  57. KAFKA_JMX_OPTS: >-
  58. -Dcom.sun.management.jmxremote
  59. -Dcom.sun.management.jmxremote.authenticate=true
  60. -Dcom.sun.management.jmxremote.ssl=true
  61. -Dcom.sun.management.jmxremote.registry.ssl=true
  62. -Dcom.sun.management.jmxremote.ssl.need.client.auth=true
  63. -Djavax.net.ssl.keyStore=/jmx/serverkeystore
  64. -Djavax.net.ssl.keyStorePassword=12345678
  65. -Djavax.net.ssl.trustStore=/jmx/servertruststore
  66. -Djavax.net.ssl.trustStorePassword=12345678
  67. -Dcom.sun.management.jmxremote.password.file=/jmx/jmxremote.password
  68. -Dcom.sun.management.jmxremote.access.file=/jmx/jmxremote.access
  69. -Dcom.sun.management.jmxremote.rmi.port=9997
  70. -Djava.rmi.server.hostname=kafka0
  71. -Djava.rmi.server.logCalls=true
  72. # -Djavax.net.debug=ssl:handshake
  73. volumes:
  74. - ./jmx/serverkeystore:/jmx/serverkeystore
  75. - ./jmx/servertruststore:/jmx/servertruststore
  76. - ./jmx/jmxremote.password:/jmx/jmxremote.password
  77. - ./jmx/jmxremote.access:/jmx/jmxremote.access
  78. - ./scripts/update_run.sh:/tmp/update_run.sh
  79. command: "bash -c 'if [ ! -f /tmp/update_run.sh ]; then echo \"ERROR: Did you forget the update_run.sh file that came with this docker-compose.yml file?\" && exit 1 ; else /tmp/update_run.sh && /etc/confluent/docker/run ; fi'"
  80. schemaregistry0:
  81. image: confluentinc/cp-schema-registry:7.2.1
  82. ports:
  83. - 8085:8085
  84. depends_on:
  85. - kafka0
  86. environment:
  87. SCHEMA_REGISTRY_KAFKASTORE_BOOTSTRAP_SERVERS: PLAINTEXT://kafka0:29092
  88. SCHEMA_REGISTRY_KAFKASTORE_SECURITY_PROTOCOL: PLAINTEXT
  89. SCHEMA_REGISTRY_HOST_NAME: schemaregistry0
  90. SCHEMA_REGISTRY_LISTENERS: http://schemaregistry0:8085
  91. SCHEMA_REGISTRY_SCHEMA_REGISTRY_INTER_INSTANCE_PROTOCOL: "http"
  92. SCHEMA_REGISTRY_LOG4J_ROOT_LOGLEVEL: INFO
  93. SCHEMA_REGISTRY_KAFKASTORE_TOPIC: _schemas
  94. kafka-connect0:
  95. image: confluentinc/cp-kafka-connect:7.2.1
  96. ports:
  97. - 8083:8083
  98. depends_on:
  99. - kafka0
  100. - schemaregistry0
  101. environment:
  102. CONNECT_BOOTSTRAP_SERVERS: kafka0:29092
  103. CONNECT_GROUP_ID: compose-connect-group
  104. CONNECT_CONFIG_STORAGE_TOPIC: _connect_configs
  105. CONNECT_CONFIG_STORAGE_REPLICATION_FACTOR: 1
  106. CONNECT_OFFSET_STORAGE_TOPIC: _connect_offset
  107. CONNECT_OFFSET_STORAGE_REPLICATION_FACTOR: 1
  108. CONNECT_STATUS_STORAGE_TOPIC: _connect_status
  109. CONNECT_STATUS_STORAGE_REPLICATION_FACTOR: 1
  110. CONNECT_KEY_CONVERTER: org.apache.kafka.connect.storage.StringConverter
  111. CONNECT_KEY_CONVERTER_SCHEMA_REGISTRY_URL: http://schemaregistry0:8085
  112. CONNECT_VALUE_CONVERTER: org.apache.kafka.connect.storage.StringConverter
  113. CONNECT_VALUE_CONVERTER_SCHEMA_REGISTRY_URL: http://schemaregistry0:8085
  114. CONNECT_INTERNAL_KEY_CONVERTER: org.apache.kafka.connect.json.JsonConverter
  115. CONNECT_INTERNAL_VALUE_CONVERTER: org.apache.kafka.connect.json.JsonConverter
  116. CONNECT_REST_ADVERTISED_HOST_NAME: kafka-connect0
  117. CONNECT_PLUGIN_PATH: "/usr/share/java,/usr/share/confluent-hub-components"
  118. kafka-init-topics:
  119. image: confluentinc/cp-kafka:7.2.1
  120. volumes:
  121. - ./message.json:/data/message.json
  122. depends_on:
  123. - kafka0
  124. command: "bash -c 'echo Waiting for Kafka to be ready... && \
  125. cub kafka-ready -b kafka0:29092 1 30 && \
  126. kafka-topics --create --topic second.users --partitions 3 --replication-factor 1 --if-not-exists --bootstrap-server kafka0:29092 && \
  127. kafka-topics --create --topic first.messages --partitions 2 --replication-factor 1 --if-not-exists --bootstrap-server kafka0:29092 && \
  128. kafka-console-producer --bootstrap-server kafka0:29092 --topic second.users < /data/message.json'"