Kafka in a DMZ: Protecting AWS MSK with Kong Event Gateway
Blog post from Kong
Running Apache Kafka on Amazon Managed Streaming for Apache Kafka (MSK) offers a managed service with benefits like automated patching and multi-AZ replication, but lacks a secure way to extend Kafka access beyond VPC boundaries. The article explores the DMZ pattern for MSK using Kong Event Gateway, highlighting its suitability for organizations needing to share Kafka access across VPCs or organizational perimeters. The DMZ pattern isolates Kafka access through a controlled gateway that authenticates clients and applies policies, keeping MSK brokers private and secure. This architecture offers advantages over MSK's public access options by hiding broker topology, reducing operational costs, and enabling centralized control and audit capabilities. Kong Event Gateway, deployed on AWS ECS Fargate, is stateless and integrates with Kong's Konnect for configuration management, enhancing scalability and operational simplicity. The setup ensures that external access doesn't impact internal MSK stability, and compliance is centralized at the gateway. The article further provides resources for implementing this architecture using Terraform, promoting a GitOps-compatible approach to manage the infrastructure.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Platform Engineering | 3 | 544 | 153 | 49 | -67% |
| OpenTelemetry | 2 | 375 | 74 | 37 | -61% |
| Real-time | 2 | 2,883 | 708 | 173 | -49% |
| Observability | 1 | 1,844 | 344 | 128 | -56% |
| Secrets Management | 1 | 1,384 | 221 | 91 | -44% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.