- Newest
- Most votes
- Most comments
Thanks a lot Mahesh!
If it's possible to share approx. ETA of resource based policy availability for MSK Serverless that would be super helpful. I see there is a cluster Policy in AWS console for MSK Serverless cluster that allow some sharing with other accounts but I can't add "kafka-cluster:*" actions to it.
Hello there,
As MSK Serverless only supports IAM Authentication, and it doesn’t have any resource based policy yet, unfortunately, it is not possible to access MSK Serverless cluster from cross account MSK Connect at the moment.
Hello there,
I just checked it again and observed that we have new change in MSK Serverless which allows you to add Cluster Policy.
You can customise that cluster policy by clicking on Advanced option and give the required actions and resources.
Please refer to the below screenshot:
Thanks Mahesh,
That's looks like exactly what I need. However when I try to add "kafka-cluster:*" actions to this policy I got the following errors:
The cluster policy is not valid. Action field includes AWS services that inconsistent with specified vendor.
Is there anything I'm doing wrong?
The consumer application requires "kafka-cluster:Connect" permissions to connect to Kafka cluster - https://docs.aws.amazon.com/msk/latest/developerguide/iam-access-control.html#actions:~:text=to%20serverless%20clusters-,kafka%2Dcluster%3AConnect,-Grants%20permission%20to.
When I try connecting with permissions on your screenshot I get Access Denied error.
Thanks, Pavel
Relevant content
- asked 9 months ago
- asked 3 years ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 3 months ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 5 months ago