Kafka Connect Chart Values Reference

This reference lists only the kafka-connect-helm chart (version 0.7.0) facts that the Kafka Connect Helm Readme doesn’t cover: the inputs to collect before deploying, values it omits or gives a wrong default for, validation behaviour, and how chart values map to Self-Service and Platform Manager.

Type

Reference

Goal

Look up a chart value fact, default correction, or Self-Service mapping that the generated Helm Readme lacks.

Audience

Platform Operator who writes or reviews the values file for a Kafka Connect cluster.

When to use

While preparing or reviewing Kafka Connect chart values, next to the Helm Readme values table.

The full values table, with every key and its description, is the Values reference in the Helm Readme. Where a default below differs from the Helm Readme, this reference matches the chart’s values.yaml. For the procedure, see How to deploy a Kafka Connect cluster; for the design, see Kafka Connect: Concepts and Architecture.

All keys are top-level keys in values.yaml for a direct chart install. When the chart runs as a Helm subchart (for example inside an Axual Cloud GitOps wrapper chart), all keys sit under the subchart name kafka-connect:.

Version compatibility

The Helm Readme gives the Kubernetes and Strimzi minimums for imageVolumes plugin delivery; this table adds the validated production minimum.

Requirement Version

Strimzi cluster operator (validated production minimum)

>= 0.51.0

Pre-deployment value reference

The following values come from your infrastructure before the chart is deployed, each with an illustrative example.

Value Example

Tenant short name

axual

Instance short name

dev

Kafka Connect (KC) cluster name (unique per instance, lowercase)

my-cluster

Kafka bootstrap address for the TLS/mutual TLS (mTLS) listener

my-kafka-bootstrap:9093

Kafka bootstrap address for the SASL_SSL listener

my-kafka-bootstrap:9094

Broker CA certificate: Kubernetes Secret name and key

my-cluster-ca-cert / ca.crt

Worker mTLS client-cert: Kubernetes Secret name

connect-worker-cert

Worker Simple Authentication and Security Layer (SASL) username and password Secret name

connect-worker / connect-worker

Connector Vault URL

https://vault.example:8200

Identity and naming values

These values set the resource name and the identity labels; the Helm Readme table omits the two override keys.

Key Type Default Description

nameOverride

string

""

Replaces the chart name (kafka-connect) when building the resource name. Not in values.yaml, accepted by the schema.

fullnameOverride

string

""

Pins the KafkaConnect Custom Resource (CR) name, and so the REST API Service <fullnameOverride>-connect-api:8083. When empty, the name is the Helm release name if it already contains the chart name, otherwise <release>-kafka-connect. Not in values.yaml, accepted by the schema.

tenant / instance / clusterName

string

""

Required. The tenant and instance short names, and the Kafka Connect cluster name as registered in Self-Service. Rendered as the axual.io/tenant, axual.io/instance and axual.io/connect-cluster pod labels. The schema rejects a value that isn’t a Kubernetes label value: 1 to 63 characters matching ^[a-z0-9]([-a-z0-9._]{0,61}[a-z0-9])?$.

Broker trust and worker authentication values

The Helm Readme table shows example Secret names as defaults for these keys; the chart defaults are empty.

Key Type Default Description

tls.trustedCertificates

list

[]

CA certificates that verify the broker TLS certificate, for both tls and scram-sha-512. Each entry has secretName (Kubernetes Secret) and certificate (key within the Secret), one entry per certificate in the chain.

authentication.certificateAndKey.secretName / certificate / key

string

""

Required when authentication.type: tls. Secret name, and the keys within it for the certificate (for example tls.crt) and private key (for example tls.key).

Plugin delivery values

These rows correct the plugins default and add the prebuilt image precedence the Helm Readme table lacks.

Key Type Default Description

plugins

list

[]

Plugins to mount in imageVolumes mode, in one of three entry forms (see Plugin entry forms). A string or name-only entry without a catalogue spec fails the render with no spec file at plugins/<name>.yaml.

prebuiltConnectImage

string

registry.axual.io/internal/axual/kafka-connect-with-smt:0.0.8-strimzi-0.51.0-kafka-4.1.1

Full Connect image for pluginDelivery: prebuiltImage, used only when prebuiltImageProfile is empty.

prebuiltImageProfile

string

default

When set, the image is <prebuiltImageRegistry>/<profile>:<chart-version>-strimzi-<strimziVersion>-kafka-<kafkaVersion> and takes precedence over prebuiltConnectImage. Profiles: default (kafka-topic-name-transforms), with-cdc (adds debezium-postgres).

Plugin entry forms

Each entry in the plugins list takes one of three forms.

Form Image source Use when

String name: - kafka-topic-name-transforms

Catalogue entry at plugins/<name>.yaml and CI-built image at <pluginRegistry>/<name>:<version>

Plugin has a catalogue spec file and its OCI image has been built by CI.

Name and explicit image: - name: aiven-jdbc / ` image: registry…​/aiven-jdbc:6.12.0`

The image URL given in the entry, with no spec lookup

Plugin isn’t in the catalogue, or its image is in a different registry.

Name and version override: - name: debezium-postgres / ` version: "3.5.1.Final"`

Catalogue spec, with version or digest overridden

A specific version of a catalogued plugin is required.

String entries resolve against these catalogue specs in chart version 0.7.0: apicurio-converter, axual-http-sink, axual-kafka-sync, camel-sftp-sink, camel-sftp-source, connect-file, debezium-mongodb, debezium-mysql, debezium-oracle, debezium-postgres, debezium-sqlserver, kafka-topic-name-transforms and stream-reactor-ftp.

kafka-topic-name-transforms must be present in the plugins list. Platform Manager validates its presence at cluster registration.

Worker-level Connect config values

The config object passes through to the Connect worker configuration and isn’t in the Helm Readme table. Strimzi manages plugin.path, so it isn’t a config key. A config value containing ${vault: fails the render while vault.enabled is false.

Key Type Default Description

config.offset.storage.replication.factor / config.config.storage.replication.factor / config.status.storage.replication.factor

integer

1

Replication factor for the offset, config, and status storage topics. Equals the broker count in a production setup.

config.key.converter / config.value.converter

string

org.apache.kafka.connect.json.JsonConverter

Default key and value converters for connectors that don’t set their own.

config.key.converter.schemas.enable / config.value.converter.schemas.enable

boolean

false

Whether the JSON key or value payload includes the schema.

config.key.converter.apicurio.registry.url / config.value.converter.apicurio.registry.url

string

(unset)

Apicurio Registry URL read by an Apicurio Kafka Connect converter, for example io.apicurio.registry.utils.converter.AvroConverter. No effect while the converter stays at the default JsonConverter. A connector that overrides its converter to an Apicurio class supplies its own copy of this key. See the Apicurio Registry documentation for the converter classes.

config.connector.client.config.override.policy

string

All

Allows connectors to override their own producer, consumer, and admin configuration. Required for per-connector Vault identities.

Deployment, logging and ACL bootstrap values

These rows correct Helm Readme defaults or add constraints it doesn’t state, including one for the Access Control List (ACL) bootstrap Job.

Key Type Default Description

resources

object

{}

Worker pod requests and limits. The chart sets none by default (the Helm Readme’s 250m/1Gi and 2Gi aren’t in values.yaml).

imagePullSecrets

list

[]

Required for development images from the private internal Harbor project. Not required for production images from the public Harbor project.

logging.level

string

INFO

One of OFF, FATAL, ERROR, WARN, INFO, DEBUG, TRACE, ALL.

logging.loggers

object

{org.reflections: ERROR, org.apache.kafka.connect.runtime.rest.RestServer: WARN}

Per-logger levels, as name: level. The default has two entries.

aclBootstrap.minInsyncReplicas

integer

1

Minimum 1. Must be less than or equal to aclBootstrap.replicationFactor.

vault - Connector Vault integration

These facts about the vault keys aren’t in the Helm Readme:

  • vault.truststoreSecret is mounted at /mnt/vault-truststore/ and its truststore.password key is injected as the VAULT_TRUSTSTORE_PASSWORD environment variable, only while vault.enabled is true.

  • Setting vault.address, vault.credentialsSecret, vault.approleRoleId, vault.approleSecretId, vault.testPath or vault.truststoreSecret while vault.enabled is false fails the render, naming the fields that are set.

Vault output destination mapping

This table maps each output from How to set up the Connector Vault for Kafka Connect to where it’s used.

Output Destination

Platform Manager writer role-id and secret-id (strict on-premises only)

Produced only when the Connector Vault is a separate server from the Governance Vault. Handed to the Tenant Admin for the Self-Service registration form, then stored in the Governance Vault at <tenant>/<instance>/<kafka-cluster-name>/connects/<connect-cluster-name>, under the keys roleId and secretId. On Axual Cloud, Platform Manager uses its own AppRole and this output isn’t produced.

Worker role-id and secret-id

The Kubernetes Secret named by vault.credentialsSecret (Mode B), or vault.approleRoleId and vault.approleSecretId (Mode A).

Probe secret Vault path

vault.testPath in the chart values.

REST API access values

The restApi keys, the two-half design, and a working block per ingress implementation are in REST API access in the Helm Readme. See Secure the REST API for the procedure. The rows below add behaviour the Helm Readme doesn’t state.

Key Type Default Description

restApi.route.annotations

object

{}

Merged with restApi.basicAuth.annotations, which wins on a key collision.

restApi.route.parentRefs / filters

list

[]

kind: HTTPRoute only. Either one set on kind: Ingress fails the render.

restApi.networkPolicy.strimziOperator.namespace

string

""

Empty allows the operator only from the Connect cluster’s own namespace. With a cluster-wide operator in another namespace, an empty value blocks every reconcile and the KafkaConnect resource never reports Ready.

Self-Service registration field mapping

This table maps each registration form field to where Platform Manager stores it.

Item Destination in Platform Manager

KC REST URL

connect_cluster.connect_urls

Connect API authentication (basic or none)

connect_cluster.connect_api_auth_method

Worker auth method (tls or scram-sha-512)

connect_cluster.auth_method

Connector Vault URL, KV path, AppRole mount path, Vault namespace

connect_cluster.connector_vault_*

Platform Manager writer role-id and secret-id (strict on-premises only)

Governance Vault at <tenant>/<instance>/<kafka-cluster-name>/connects/<connect-cluster-name>, under the keys roleId and secretId. Not required on Axual Cloud, where Platform Manager uses its own AppRole.

Connect log viewer URL (the Log Provisioner address)

connect_cluster.log_viewer_url