Kafka Connect Chart Values Reference
This reference lists only the kafka-connect-helm chart (version 0.7.0) facts that the Kafka Connect Helm Readme doesn’t cover: the inputs to collect before deploying, values it omits or gives a wrong default for, validation behaviour, and how chart values map to Self-Service and Platform Manager.
Type |
Reference |
Goal |
Look up a chart value fact, default correction, or Self-Service mapping that the generated Helm Readme lacks. |
Audience |
Platform Operator who writes or reviews the values file for a Kafka Connect cluster. |
When to use |
While preparing or reviewing Kafka Connect chart values, next to the Helm Readme values table. |
The full values table, with every key and its description, is the Values reference in the Helm Readme. Where a default below differs from the Helm Readme, this reference matches the chart’s values.yaml. For the procedure, see How to deploy a Kafka Connect cluster; for the design, see Kafka Connect: Concepts and Architecture.
All keys are top-level keys in values.yaml for a direct chart install. When the chart runs as a Helm subchart (for example inside an Axual Cloud GitOps wrapper chart), all keys sit under the subchart name kafka-connect:.
|
Version compatibility
The Helm Readme gives the Kubernetes and Strimzi minimums for imageVolumes plugin delivery; this table adds the validated production minimum.
| Requirement | Version |
|---|---|
Strimzi cluster operator (validated production minimum) |
>= 0.51.0 |
Pre-deployment value reference
The following values come from your infrastructure before the chart is deployed, each with an illustrative example.
| Value | Example |
|---|---|
Tenant short name |
|
Instance short name |
|
Kafka Connect (KC) cluster name (unique per instance, lowercase) |
|
Kafka bootstrap address for the TLS/mutual TLS (mTLS) listener |
|
Kafka bootstrap address for the SASL_SSL listener |
|
Broker CA certificate: Kubernetes Secret name and key |
|
Worker mTLS client-cert: Kubernetes Secret name |
|
Worker Simple Authentication and Security Layer (SASL) username and password Secret name |
|
Connector Vault URL |
Identity and naming values
These values set the resource name and the identity labels; the Helm Readme table omits the two override keys.
| Key | Type | Default | Description |
|---|---|---|---|
|
string |
|
Replaces the chart name ( |
|
string |
|
Pins the |
|
string |
|
Required. The tenant and instance short names, and the Kafka Connect cluster name as registered in Self-Service. Rendered as the |
Broker trust and worker authentication values
The Helm Readme table shows example Secret names as defaults for these keys; the chart defaults are empty.
| Key | Type | Default | Description |
|---|---|---|---|
|
list |
|
CA certificates that verify the broker TLS certificate, for both |
|
string |
|
Required when |
Plugin delivery values
These rows correct the plugins default and add the prebuilt image precedence the Helm Readme table lacks.
| Key | Type | Default | Description |
|---|---|---|---|
|
list |
|
Plugins to mount in |
|
string |
|
Full Connect image for |
|
string |
|
When set, the image is |
Plugin entry forms
Each entry in the plugins list takes one of three forms.
| Form | Image source | Use when |
|---|---|---|
String name: |
Catalogue entry at |
Plugin has a catalogue spec file and its OCI image has been built by CI. |
Name and explicit image: |
The image URL given in the entry, with no spec lookup |
Plugin isn’t in the catalogue, or its image is in a different registry. |
Name and version override: |
Catalogue spec, with version or digest overridden |
A specific version of a catalogued plugin is required. |
String entries resolve against these catalogue specs in chart version 0.7.0: apicurio-converter, axual-http-sink, axual-kafka-sync, camel-sftp-sink, camel-sftp-source, connect-file, debezium-mongodb, debezium-mysql, debezium-oracle, debezium-postgres, debezium-sqlserver, kafka-topic-name-transforms and stream-reactor-ftp.
kafka-topic-name-transforms must be present in the plugins list. Platform Manager validates its presence at cluster registration.
|
Worker-level Connect config values
The config object passes through to the Connect worker configuration and isn’t in the Helm Readme table. Strimzi manages plugin.path, so it isn’t a config key. A config value containing ${vault: fails the render while vault.enabled is false.
| Key | Type | Default | Description |
|---|---|---|---|
|
integer |
|
Replication factor for the offset, config, and status storage topics. Equals the broker count in a production setup. |
|
string |
|
Default key and value converters for connectors that don’t set their own. |
|
boolean |
|
Whether the JSON key or value payload includes the schema. |
|
string |
(unset) |
Apicurio Registry URL read by an Apicurio Kafka Connect converter, for example |
|
string |
|
Allows connectors to override their own producer, consumer, and admin configuration. Required for per-connector Vault identities. |
Deployment, logging and ACL bootstrap values
These rows correct Helm Readme defaults or add constraints it doesn’t state, including one for the Access Control List (ACL) bootstrap Job.
| Key | Type | Default | Description |
|---|---|---|---|
|
object |
|
Worker pod requests and limits. The chart sets none by default (the Helm Readme’s 250m/1Gi and 2Gi aren’t in |
|
list |
|
Required for development images from the private |
|
string |
|
One of |
|
object |
|
Per-logger levels, as |
|
integer |
|
Minimum 1. Must be less than or equal to |
vault - Connector Vault integration
These facts about the vault keys aren’t in the Helm Readme:
-
vault.truststoreSecretis mounted at/mnt/vault-truststore/and itstruststore.passwordkey is injected as theVAULT_TRUSTSTORE_PASSWORDenvironment variable, only whilevault.enabledistrue. -
Setting
vault.address,vault.credentialsSecret,vault.approleRoleId,vault.approleSecretId,vault.testPathorvault.truststoreSecretwhilevault.enabledisfalsefails the render, naming the fields that are set.
Vault output destination mapping
This table maps each output from How to set up the Connector Vault for Kafka Connect to where it’s used.
| Output | Destination |
|---|---|
Platform Manager writer |
Produced only when the Connector Vault is a separate server from the Governance Vault. Handed to the Tenant Admin for the Self-Service registration form, then stored in the Governance Vault at |
Worker |
The Kubernetes Secret named by |
Probe secret Vault path |
|
REST API access values
The restApi keys, the two-half design, and a working block per ingress implementation are in REST API access in the Helm Readme. See Secure the REST API for the procedure. The rows below add behaviour the Helm Readme doesn’t state.
| Key | Type | Default | Description |
|---|---|---|---|
|
object |
|
Merged with |
|
list |
|
|
|
string |
|
Empty allows the operator only from the Connect cluster’s own namespace. With a cluster-wide operator in another namespace, an empty value blocks every reconcile and the |
Self-Service registration field mapping
This table maps each registration form field to where Platform Manager stores it.
| Item | Destination in Platform Manager |
|---|---|
KC REST URL |
|
Connect API authentication ( |
|
Worker auth method ( |
|
Connector Vault URL, KV path, AppRole mount path, Vault namespace |
|
Platform Manager writer |
Governance Vault at |
Connect log viewer URL (the Log Provisioner address) |
|