rgw: support kafka auth mechanism parameter

Ceph has support [1,2] for configuring which authentication
mechanism to use for bucket notifications using Kafka topics.

This commit adds the corresponding support to rook.

[1]: https://github.com/ceph/ceph/pull/48181/commits/d5dce601f65974a21c83c4b1add036030a75c3c4
[2]: https://tracker.ceph.com/issues/57608

Signed-off-by: Ragnar Dahlén <r.dahlen@gmail.com>
This commit is contained in:
Ragnar Dahlén
2025-03-24 21:53:49 +01:00
parent d05a4e88ca
commit 8bf7c679bb
9 changed files with 53 additions and 3 deletions
@@ -65,6 +65,7 @@ spec:
# disableVerifySSL: true [16]
# ackLevel: broker [17]
# useSSL: false [18]
# mechanism: SCRAM-SHA-512 [19]
```
1. `name` of the `CephBucketTopic`
@@ -100,6 +101,12 @@ spec:
+ “none”: message is considered “delivered” if sent to broker
+ “broker”: message is considered “delivered” if acked by broker (default)
18. `useSSL` (optional) indicates that secure connection will be used for connecting with the broker (“false” by default)
19. `mechanism` (optional) select which authentication mechanism to use, one of:
+ “PLAIN” (default)
+ “SCRAM-SHA-512”
+ “SCRAM-SHA-256”
+ “GSSAPI”
+ “OAUTHBEARER”
!!! note
In case of Kafka and AMQP, the consumer of the notifications is not required to ack the notifications, since the broker persists the messages before delivering them to their final destinations.