Getting Started with OAuth for Confluent Cloud Using Azure AD DS
Blog post from Confluent
Confluent Cloud’s OAuth support, released in December 2022, enables organizations to integrate third-party identity providers such as Azure Active Directory Domain Services to centrally authenticate and authorize applications accessing Kafka clusters. Applications use the OAuth client credentials grant to obtain a signed JWT from the identity provider, present it through the SASL OAUTHBEARER mechanism, and are authorized by Confluent Cloud through identity pools and RBAC role bindings based on token claims. Configuration requires registering an identity provider with its issuer and JWKS endpoints, defining identity pools with claim-based filters, and configuring supported Kafka clients with the token endpoint, client credentials, target cluster, and identity pool ID. The Azure AD example details registering a Confluent Cloud application, creating app roles, enabling version 2 access tokens, registering client applications and secrets, granting permissions, and mapping JWT roles to Confluent Cloud identity pools. Identity pools can reduce reliance on individual service accounts and API keys, support shared authorization for common resources, or enforce application-specific access, including distinct permissions across development and production environments.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Platform Engineering | 33 | 283 | 60 | 40 | -16% |
| Secrets Management | 2 | 865 | 106 | 64 | +106% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.