Back to Ceph Foundation
GSoC 2026

Kafka Security Project

Addressing a major security gap in Ceph RGW Kafka bucket notifications. Current support is incomplete for modern secure Kafka deployments, especially for GSSAPI (Kerberos), OAUTHBEARER (JWT), mTLS client authentication, and fileless CA/certificate handling. The plan is to extend RGW’s Kafka connection path to resolve security inputs with clear precedence, correctly map them to librdkafka, and ensure safe producer identity reuse, while adding deterministic local tests and automating them in teuthology.

Project details

Contributor

Sujay Dongre

Mentors

Not available

Technologies

Not listed in the archive