How to Deploy Axual Kafka

This guide shows you how to deploy an Axual Kafka cluster: writing its values file, choosing node pool topology and replication settings, installing the chart, verifying the brokers came up, and uninstalling it again.

Type

How-to guide

Goal

Deploy a Strimzi-based Kafka cluster that the Streaming and Governance layers can use.

Audience

Platform Operator with Helm access to the target namespace and Strimzi already installed.

When to use

Stage 3 of The installation order, before Install Axual Streaming.

Where this guide fits

Axual Kafka is a standalone Helm chart: it does not depend on the Streaming or Governance charts, and they depend on it. Two companion pages carry the material this guide does not repeat.

For every value the chart accepts, see Kafka Chart Values Reference. For why a multi-tenant installation needs the custom Axual Kafka image, see Principal Chain Builder.

Prerequisites

Confirm the following before you begin.

Access and permissions required

You need the following access and permissions:

  • Read access to the axual-kafka chart in the Axual Harbor Registry (registry.axual.io).

  • Permission to install Helm releases and create workloads in the target namespace.

Tools and versions required

You need the following tools and versions:

  • helm >= 3.12, with OCI registry support.

  • kubectl >= 1.22, configured for the target cluster.

  • The Strimzi operator, installed and watching the target namespace. For a multi-tenant installation it needs the custom Axual Kafka image; see Preparations.

Prerequisite how-tos to complete first

Complete this guide before Step 1:

  1. Preparations creates the namespace, the image pull Secret, and installs the Strimzi operator.

Resources that must exist before starting

The following resources must already exist before you start:

  • The target namespace and the image pull Secret (axualdockercred) it needs, both created in Preparations.

  • The Strimzi operator, watching the target namespace.

Step 1: Create your Kafka values file

Create an axual-kafka.values.yaml file. Build it section by section from the blocks below.

Name the release

Set the release name first, since it decides the resource names Strimzi creates.

fullnameOverride: "<cluster-name>"   (1)
1 Pins the resource names Strimzi creates. Match the cluster name you register in Self-Service.

Choose the node pool topology

Split the controller and broker roles into two KafkaNodePool resources for a production cluster; a combined pool is only for a trial.

kafkaNodePools:
  controller:
    replicas: 3               (1)
    roles:
      - "controller"
    resources: {}
    storage:
      type: jbod
      volumes:
        - id: 0
          type: persistent-claim
          size: <SIZE>
          deleteClaim: false
  broker:
    replicas: 3               (1)
    roles:
      - "broker"
    resources: {}
    storage:
      type: jbod
      volumes:
        - id: 0
          type: persistent-claim
          size: <SIZE>
          deleteClaim: false
1 Scale in groups of three, one per Availability Zone. See Infrastructure Requirements for node sizing.

Set replication for a production cluster

The chart’s defaults (1) suit a single-broker trial only.

kafka:
  config:
    offsets.topic.replication.factor: 3
    transaction.state.log.replication.factor: 3
    transaction.state.log.min.isr: 2
    default.replication.factor: 3
    min.insync.replicas: 2

Configure listeners

Add an internal TLS listener for in-cluster clients and an external one for clients outside the cluster.

kafka:
  listeners:
    internal:
      type: internal
      authentication:
        type: tls
      tls: true
      port: 9093
    external:
      type: ingress
      authentication:
        type: tls
      tls: true
      port: 9094
      configuration:
        bootstrap:
          host: "bootstrap-kafka.<domain>"
        brokers:
          - broker: 0
            host: "kafka-0.<domain>"

Set the Cluster and Clients CAs

Do not reuse the demonstration Certificate Authority (CA) shown in the Quick Setup example values file; its private key is published with this documentation and is not secret.

kafka:
  clientsCa:
    generateCertificateAuthority: true   (1)
  clusterCa:
    generateCertificateAuthority: true   (1)
1 Strimzi generates and manages its own CAs. To supply your own instead, see the clientsCa/clusterCa cert/key options in the Kafka Chart Values Reference.

Enable the Principal Chain Builder for a multi-tenant installation

Skip this block on a single-tenant installation.

axual:
  sslPrincipalBuilder:
    enabled: true

Set Kafka super users

List the principals that bypass authorization checks, starting with Platform Manager.

kafka:
  authorization:
    superUsers:
      - "CN=Platform Manager,OU=Axual,O=Axual,C=NL"

Step 2: Install the chart

Log in to the registry, then install the chart with your values.

Replace every <VALUE> placeholder with your own value before running a command.
  1. Log in to the Axual Harbor Registry.

    helm registry login -u <YOUR_USERNAME> registry.axual.io/axual-charts
  2. Install Axual Kafka with your axual-kafka.values.yaml. Find <CHART_VERSION> in Axual Kafka README, generated from the chart, so it is the version to trust when sources disagree.

    helm install axual-kafka oci://registry.axual.io/axual-charts/axual-kafka \
      --version <CHART_VERSION> -f ./axual-kafka.values.yaml -n <NAMESPACE>

helm upgrade --install is idempotent and safe to re-run for later changes.

Step 3: Verify the brokers are Ready

Confirm the cluster reached the Ready state.

kubectl wait kafka/<cluster-name> \
  --for=condition=Ready \
  --namespace <NAMESPACE> \
  --timeout=300s

Check that every broker and controller pod is running:

kubectl get pods -l strimzi.io/cluster=<cluster-name> --namespace <NAMESPACE>

Expected: one pod per replica in Running state with 1/1 ready. The brokers come up one at a time, so this can take longer than a typical Deployment rollout.

A Ready cluster with every broker running completes this guide. It does not yet carry Apicurio Registry or the Rest Proxy; Install Axual Streaming covers those next.

Uninstall Axual Kafka

Uninstalling removes the release, not the data.

helm uninstall axual-kafka -n <NAMESPACE>
The PersistentVolumeClaims holding the Kafka data survive the uninstall by design. Deleting them destroys every topic and message in the cluster, so remove them only when that is what you intend.