Home / Companies / Kong / Blog / Post Details
Content Deep Dive

Kafka in a DMZ: Protecting AWS MSK with Kong Event Gateway

Blog post from Kong

Post Details
Company
Date Published
Author
Hugo Guerrero
Word Count
2,589
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

Running Apache Kafka on Amazon Managed Streaming for Apache Kafka (MSK) offers a managed service with benefits like automated patching and multi-AZ replication, but lacks a secure way to extend Kafka access beyond VPC boundaries. The article explores the DMZ pattern for MSK using Kong Event Gateway, highlighting its suitability for organizations needing to share Kafka access across VPCs or organizational perimeters. The DMZ pattern isolates Kafka access through a controlled gateway that authenticates clients and applies policies, keeping MSK brokers private and secure. This architecture offers advantages over MSK's public access options by hiding broker topology, reducing operational costs, and enabling centralized control and audit capabilities. Kong Event Gateway, deployed on AWS ECS Fargate, is stateless and integrates with Kong's Konnect for configuration management, enhancing scalability and operational simplicity. The setup ensures that external access doesn't impact internal MSK stability, and compliance is centralized at the gateway. The article further provides resources for implementing this architecture using Terraform, promoting a GitOps-compatible approach to manage the infrastructure.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Platform Engineering 3 1,431 351 79 -11%
OpenTelemetry 2 1,075 169 52 +11%
Real-time 2 6,395 1,450 242 +6%
Observability 1 4,170 814 198 -2%
Secrets Management 1 2,588 483 133 +2%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.