kafka-ui-jmx-secured.yml 3.2 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273
  1. ---
  2. version: '2'
  3. services:
  4. kafka-ui:
  5. container_name: kafka-ui
  6. image: provectuslabs/kafka-ui:latest
  7. ports:
  8. - 8080:8080
  9. depends_on:
  10. - kafka0
  11. environment:
  12. KAFKA_CLUSTERS_0_NAME: local
  13. KAFKA_CLUSTERS_0_BOOTSTRAPSERVERS: kafka0:29092
  14. KAFKA_CLUSTERS_0_SCHEMAREGISTRY: http://schemaregistry0:8085
  15. KAFKA_CLUSTERS_0_KAFKACONNECT_0_NAME: first
  16. KAFKA_CLUSTERS_0_KAFKACONNECT_0_ADDRESS: http://kafka-connect0:8083
  17. KAFKA_CLUSTERS_0_METRICS_PORT: 9997
  18. KAFKA_CLUSTERS_0_METRICS_USERNAME: root
  19. KAFKA_CLUSTERS_0_METRICS_PASSWORD: password
  20. KAFKA_CLUSTERS_0_METRICS_KEYSTORE_LOCATION: /jmx/clientkeystore
  21. KAFKA_CLUSTERS_0_METRICS_KEYSTORE_PASSWORD: '12345678'
  22. KAFKA_CLUSTERS_0_SSL_TRUSTSTORE_LOCATION: /jmx/clienttruststore
  23. KAFKA_CLUSTERS_0_SSL_TRUSTSTORE_PASSWORD: '12345678'
  24. volumes:
  25. - ./jmx/clienttruststore:/jmx/clienttruststore
  26. - ./jmx/clientkeystore:/jmx/clientkeystore
  27. kafka0:
  28. image: confluentinc/cp-kafka:7.2.1
  29. hostname: kafka0
  30. container_name: kafka0
  31. ports:
  32. - 9092:9092
  33. - 9997:9997
  34. environment:
  35. KAFKA_BROKER_ID: 1
  36. KAFKA_LISTENER_SECURITY_PROTOCOL_MAP: 'CONTROLLER:PLAINTEXT,PLAINTEXT:PLAINTEXT,PLAINTEXT_HOST:PLAINTEXT'
  37. KAFKA_ADVERTISED_LISTENERS: 'PLAINTEXT://kafka0:29092,PLAINTEXT_HOST://localhost:9092'
  38. KAFKA_OFFSETS_TOPIC_REPLICATION_FACTOR: 1
  39. KAFKA_GROUP_INITIAL_REBALANCE_DELAY_MS: 0
  40. KAFKA_TRANSACTION_STATE_LOG_MIN_ISR: 1
  41. KAFKA_TRANSACTION_STATE_LOG_REPLICATION_FACTOR: 1
  42. KAFKA_JMX_PORT: 9997
  43. KAFKA_PROCESS_ROLES: 'broker,controller'
  44. KAFKA_NODE_ID: 1
  45. KAFKA_CONTROLLER_QUORUM_VOTERS: '1@kafka0:29093'
  46. KAFKA_LISTENERS: 'PLAINTEXT://kafka0:29092,CONTROLLER://kafka0:29093,PLAINTEXT_HOST://0.0.0.0:9092'
  47. KAFKA_INTER_BROKER_LISTENER_NAME: 'PLAINTEXT'
  48. KAFKA_CONTROLLER_LISTENER_NAMES: 'CONTROLLER'
  49. KAFKA_LOG_DIRS: '/tmp/kraft-combined-logs'
  50. # CHMOD 700 FOR JMXREMOTE.* FILES
  51. KAFKA_JMX_OPTS: >-
  52. -Dcom.sun.management.jmxremote
  53. -Dcom.sun.management.jmxremote.authenticate=true
  54. -Dcom.sun.management.jmxremote.ssl=true
  55. -Dcom.sun.management.jmxremote.registry.ssl=true
  56. -Dcom.sun.management.jmxremote.ssl.need.client.auth=true
  57. -Djavax.net.ssl.keyStore=/jmx/serverkeystore
  58. -Djavax.net.ssl.keyStorePassword=12345678
  59. -Djavax.net.ssl.trustStore=/jmx/servertruststore
  60. -Djavax.net.ssl.trustStorePassword=12345678
  61. -Dcom.sun.management.jmxremote.password.file=/jmx/jmxremote.password
  62. -Dcom.sun.management.jmxremote.access.file=/jmx/jmxremote.access
  63. -Dcom.sun.management.jmxremote.rmi.port=9997
  64. -Djava.rmi.server.hostname=kafka0
  65. volumes:
  66. - ./jmx/serverkeystore:/jmx/serverkeystore
  67. - ./jmx/servertruststore:/jmx/servertruststore
  68. - ./jmx/jmxremote.password:/jmx/jmxremote.password
  69. - ./jmx/jmxremote.access:/jmx/jmxremote.access
  70. - ./scripts/update_run.sh:/tmp/update_run.sh
  71. command: "bash -c 'if [ ! -f /tmp/update_run.sh ]; then echo \"ERROR: Did you forget the update_run.sh file that came with this docker-compose.yml file?\" && exit 1 ; else /tmp/update_run.sh && /etc/confluent/docker/run ; fi'"