Why this matters
- VaultCommerce SOC2 audit requires mTLS between services and brokers.
- SCRAM credentials rotated via HashiCorp Vault; no passwords in git.
- ACL deny-by-default with quarterly access reviews.
- Encryption at rest on broker disks via cloud KMS.
mTLS and SASL
Brokers present server cert; clients present client cert (mTLS) plus SCRAM username. ssl.endpoint.identification.algorithm=https prevents MITM. VaultCommerce internal CA signs all Kafka certs; 90-day rotation automated.
Key points
- mTLS — mutual TLS authenticates client and server
- SCRAM rotation — periodic credential refresh without downtime
- ACL audit — log denied and allowed operations
- Encryption at rest — EBS/disk KMS for broker volumes
- Network policy — Kubernetes deny-all except broker port from app namespaces
Hardening checklist
Disable PLAINTEXT listeners. allow.everyone.if.no.acl.found=false. Enable audit logs to SIEM. Separate admin principals. No JMX unauthenticated. VaultCommerce blocks inter-broker PLAINTEXT in prod — SASL_SSL only.
VaultCommerce rollout checklist
Before promoting changes that touch the VaultCommerce order and payment event backbone, run the staging KRaft cluster (Kafka 3.7+, Schema Registry 7.x) through a 10k events/min soak test. Compare producer request latency p99 and consumer lag per group against the pre-deploy baseline. SASL_SSL + mTLS + ACLs in production. Document the change in the internal topic registry, attach Grafana screenshots to the change ticket, and keep an engineer on lag dashboards for 30 minutes after production rollout — roll back the service release before altering broker-level settings if lag or under-replicated partitions spike.
# VaultCommerce production broker — listener security
listeners: SASL_SSL://0.0.0.0:9092,CONTROLLER://0.0.0.0:9093
advertised.listeners: SASL_SSL://kafka-1.vaultcommerce.internal:9092
security.inter.broker.protocol: SASL_SSL
sasl.mechanism.inter.broker.protocol: SCRAM-SHA-512
ssl.keystore.location: /etc/kafka/kafka.keystore.jks
ssl.truststore.location: /etc/kafka/kafka.truststore.jks
ssl.client.auth: required
authorizer.class.name: org.apache.kafka.metadata.authorizer.StandardAuthorizer
allow.everyone.if.no.acl.found: false
Quick recall
Everything you need if you only revisit this box.
- SASL_SSL + mTLS + ACLs in production.
- Deny-by-default ACL policy.
- Secrets from Vault, never source control.
Test yourself
Answer these before moving on — recall is what makes it stick.