# Ops

**URL:** https://forum.confluent.io/c/ops/17.md

[Latest](https://forum.confluent.io/latest.md) · [Categories](https://forum.confluent.io/categories.md)

---

## [About the Ops category](https://forum.confluent.io/t/about-the-ops-category/26)

<div class="topic-metadata">

**Author:** [@rmoff](https://forum.confluent.io/u/rmoff)\
**Replies:** 0

</div>

If you’re not developing applications, you’re operating them! This category is for discussing broker problems, installations, upgrades, monitoring, containers, security configuration… that kind of thing :slight\_smile:

---

## [Cluster - pre-upgrade - which version to use?](https://forum.confluent.io/t/cluster-pre-upgrade-which-version-to-use/38214)

<div class="topic-metadata">

**Author:** [@ebjy](https://forum.confluent.io/u/ebjy)\
**Replies:** 1\
**Last updated:** [8 January 2026 09:34 UTC](https://forum.confluent.io/t/cluster-pre-upgrade-which-version-to-use/38214 "2026-01-08T09:34:26Z")

</div>

It appears that Im using ‘confluent-kafka-2.11-2.0.1cp8-1.noarch’. Before I move to whatever is next should I switch to using the ‘confluent-community’ package(s)? This package seems to appear when the repo file is upda…

---

## [Migrating v old installation (v5.x) to latest](https://forum.confluent.io/t/migrating-v-old-installation-v5-x-to-latest/38199)

<div class="topic-metadata">

**Author:** [@ebjy](https://forum.confluent.io/u/ebjy)\
**Replies:** 9\
**Last updated:** [5 January 2026 17:38 UTC](https://forum.confluent.io/t/migrating-v-old-installation-v5-x-to-latest/38199 "2026-01-05T17:38:27Z")

</div>

I have 5 brokers running rocky 9 and ‘confluent-kafka-2.11-2.0.1cp8-1’. The yum repo is ‘https://packages.confluent.io/rpm/5.0’ - which Im guessing is 3 major versions behind. The goal is to land on the latest (v8.x) wi…

---

## [CVE‑2025‑12183 this vulnerability compression.type for topic and producer](https://forum.confluent.io/t/cve-2025-12183-this-vulnerability-compression-type-for-topic-and-producer/38200)

<div class="topic-metadata">

**Author:** [@asif123](https://forum.confluent.io/u/asif123)\
**Replies:** 1\
**Last updated:** [5 January 2026 15:49 UTC](https://forum.confluent.io/t/cve-2025-12183-this-vulnerability-compression-type-for-topic-and-producer/38200 "2026-01-05T15:49:08Z")

</div>

Please assist to check the compression.type configuration for Kafka Broker and also at topic level to assess if CVE‐2025‐12183 is affecting applications. This is with regards to the latest vulnerability found related to…

---

## [Question on kafka ssl certificate refresh](https://forum.confluent.io/t/question-on-kafka-ssl-certificate-refresh/38197)

<div class="topic-metadata">

**Author:** [@theo123490](https://forum.confluent.io/u/theo123490)\
**Replies:** 0\
**Last updated:** [9 December 2025 10:47 UTC](https://forum.confluent.io/t/question-on-kafka-ssl-certificate-refresh/38197 "2025-12-09T10:47:58Z")

</div>

We have a kafka version 3 cluster using KRaft with SSL as the listener and contoller. We want to do a cert rotate on this certificate without doing a kafka restart. We have been able to update the certificate on the list…

---

## [Kafka Metadata Quorum Check Fails During Controller Setup – Connection Refused to Broker](https://forum.confluent.io/t/kafka-metadata-quorum-check-fails-during-controller-setup-connection-refused-to-broker/38195)

<div class="topic-metadata">

**Author:** [@Shaheerahmad](https://forum.confluent.io/u/Shaheerahmad)\
**Replies:** 0\
**Last updated:** [4 December 2025 08:46 UTC](https://forum.confluent.io/t/kafka-metadata-quorum-check-fails-during-controller-setup-connection-refused-to-broker/38195 "2025-12-04T08:46:18Z")

</div>

Hi Confluent Community, I’m running into an issue while setting up a new KRaft-based Kafka cluster using Ansible and the confluent.platform.kafka\_controller role. The deployment is failing at the \*\*“Check Kafka Metadata…

---

## [Kafka KRaft Cluster SASL Inter-Broker Authentication Failure: Unexpected Request During Handshake](https://forum.confluent.io/t/kafka-kraft-cluster-sasl-inter-broker-authentication-failure-unexpected-request-during-handshake/38180)

<div class="topic-metadata">

**Author:** [@risky-bit](https://forum.confluent.io/u/risky-bit)\
**Replies:** 0\
**Last updated:** [13 November 2025 10:28 UTC](https://forum.confluent.io/t/kafka-kraft-cluster-sasl-inter-broker-authentication-failure-unexpected-request-during-handshake/38180 "2025-11-13T10:28:20Z")

</div>

I am setting up a 3-node Apache Kafka cluster using KRaft mode (3.9.0) with SCRAM-SHA-256 for inter-broker communication on the SASL\_PLAINTEXT listener. The cluster is unable to form a quorum due to persistent SASL authe…

---

## [Confluent 8.0 – KRaft Combined Mode Production Availability](https://forum.confluent.io/t/confluent-8-0-kraft-combined-mode-production-availability/38171)

<div class="topic-metadata">

**Author:** [@manjunathkmph](https://forum.confluent.io/u/manjunathkmph)\
**Replies:** 2\
**Last updated:** [5 November 2025 14:50 UTC](https://forum.confluent.io/t/confluent-8-0-kraft-combined-mode-production-availability/38171 "2025-11-05T14:50:21Z")

</div>

I am upgrading Confluent from version 7.9.X to 8.0 by deprecating the ZooKeeper cluster and enabling KRaft mode in production. To reduce costs, we have decided not to add any additional nodes to the Kafka cluster to act …

---

## [JMX exporter configuration for Kraft combined mode](https://forum.confluent.io/t/jmx-exporter-configuration-for-kraft-combined-mode/38164)

<div class="topic-metadata">

**Author:** [@miles](https://forum.confluent.io/u/miles)\
**Replies:** 1\
**Last updated:** [31 October 2025 19:12 UTC](https://forum.confluent.io/t/jmx-exporter-configuration-for-kraft-combined-mode/38164 "2025-10-31T19:12:39Z")

</div>

Hello, I am running cp-kafka on a node in the kraft combined mode(broker+controller), and I would like to monitor this kafka instance with JMX exporter+prometheus. I am aware of the jmx exporter configuration file in t…

---

## [Control center service is running but it is not listening on port 9021](https://forum.confluent.io/t/control-center-service-is-running-but-it-is-not-listening-on-port-9021/38129)

<div class="topic-metadata">

**Author:** [@shambhuraj9984](https://forum.confluent.io/u/shambhuraj9984)\
**Replies:** 4\
**Last updated:** [9 October 2025 15:55 UTC](https://forum.confluent.io/t/control-center-service-is-running-but-it-is-not-listening-on-port-9021/38129 "2025-10-09T15:55:25Z")

</div>

getting error \[2025-10-09 07:39:33,619\] ERROR \[main\] failed to start topology (io.confluent.controlcenter.application.AllControlCenter) java.util.concurrent.TimeoutException at io.confluent.command.kafka.CommandSt…

---

## [Null pointer exception on any command in broker](https://forum.confluent.io/t/null-pointer-exception-on-any-command-in-broker/37263)

<div class="topic-metadata">

**Author:** [@Rand](https://forum.confluent.io/u/Rand)\
**Replies:** 6\
**Last updated:** [11 September 2025 15:01 UTC](https://forum.confluent.io/t/null-pointer-exception-on-any-command-in-broker/37263 "2025-09-11T15:01:03Z")

</div>

Hi, had a(nother) weird issue in our test cluster just now - I was trying to look at broker/topic default values to find reasons for our performance issue. Wehn connecting to the broker and running any command (kafka\_…

---

## [Best practices for deploying Kafka (KRaft mode) in production for a small enterprise](https://forum.confluent.io/t/best-practices-for-deploying-kafka-kraft-mode-in-production-for-a-small-enterprise/38098)

<div class="topic-metadata">

**Author:** [@ZakariaYakoub](https://forum.confluent.io/u/ZakariaYakoub)\
**Replies:** 11\
**Last updated:** [4 September 2025 12:36 UTC](https://forum.confluent.io/t/best-practices-for-deploying-kafka-kraft-mode-in-production-for-a-small-enterprise/38098 "2025-09-04T12:36:47Z")

</div>

Hello everyone, We are a small enterprise and recently deployed a microservice-based application that uses Apache Kafka. We are now preparing to move it into production, and I have a few questions about how we should pr…

---

## [After maintenance kafka broker not recovered after long period](https://forum.confluent.io/t/after-maintenance-kafka-broker-not-recovered-after-long-period/38090)

<div class="topic-metadata">

**Author:** [@vinod](https://forum.confluent.io/u/vinod)\
**Replies:** 1\
**Last updated:** [25 August 2025 14:48 UTC](https://forum.confluent.io/t/after-maintenance-kafka-broker-not-recovered-after-long-period/38090 "2025-08-25T14:48:26Z")

</div>

Hey Everyone, We recently faced an issue with one of our Apache Kafka brokers due to a disk failure. After performing maintenance, we added the broker back to the cluster using the same node ID. Once re-added, the brok…

---

## [Broker restart loop after hard shutdown](https://forum.confluent.io/t/broker-restart-loop-after-hard-shutdown/37905)

<div class="topic-metadata">

**Author:** [@Rand](https://forum.confluent.io/u/Rand)\
**Replies:** 24\
**Last updated:** [3 July 2025 09:56 UTC](https://forum.confluent.io/t/broker-restart-loop-after-hard-shutdown/37905 "2025-07-03T09:56:33Z")

</div>

Hi, (Edit: added some more info below the log) we had an unfortunate issue on the last weekend causing a hard power off of our Kafka cluster. Since then the (thankfully test) cluster is not working properly. The setu…

---

## [Encryption of data at rest](https://forum.confluent.io/t/encryption-of-data-at-rest/37850)

<div class="topic-metadata">

**Author:** [@jcurrent](https://forum.confluent.io/u/jcurrent)\
**Replies:** 1\
**Last updated:** [2 June 2025 18:20 UTC](https://forum.confluent.io/t/encryption-of-data-at-rest/37850 "2025-06-02T18:20:08Z")

</div>

Hi! I am reading a lot of encryption of data in motion with mTLS, but I am trying to figure out if Confluent server provides support for encryption of data at rest. Some resources indicate that this has to be done at O…

---

## [Multiple brokers in docker compose deployment](https://forum.confluent.io/t/multiple-brokers-in-docker-compose-deployment/37819)

<div class="topic-metadata">

**Author:** [@georgelza](https://forum.confluent.io/u/georgelza)\
**Replies:** 14\
**Last updated:** [26 May 2025 16:16 UTC](https://forum.confluent.io/t/multiple-brokers-in-docker-compose-deployment/37819 "2025-05-26T16:16:49Z")

</div>

guys, for a local confluent via docker-compose deployment (development), have anyone done it using multiple brokers ? would love a copy of the docker compose file if I may. Also curious howI would then “expose” my mul…

---

## [MirrorMaker2 not replicating certain topics](https://forum.confluent.io/t/mirrormaker2-not-replicating-certain-topics/37672)

<div class="topic-metadata">

**Author:** [@alexei.ivanov](https://forum.confluent.io/u/alexei.ivanov)\
**Replies:** 8\
**Last updated:** [2 May 2025 12:24 UTC](https://forum.confluent.io/t/mirrormaker2-not-replicating-certain-topics/37672 "2025-05-02T12:24:43Z")

</div>

Hello everyone! I have installed a MirrorMaker2 cluster with 2 nodes that is replicating a 3 broker + zookeeper Kafka cluster with just under 1100 topics. The replication works as expected for all but the following topi…

---

## [MirrorMaker 2: topic gets created on target but records stay (or loop) on source](https://forum.confluent.io/t/mirrormaker-2-topic-gets-created-on-target-but-records-stay-or-loop-on-source/37699)

<div class="topic-metadata">

**Author:** [@beaufort12](https://forum.confluent.io/u/beaufort12)\
**Replies:** 0\
**Last updated:** [24 April 2025 15:22 UTC](https://forum.confluent.io/t/mirrormaker-2-topic-gets-created-on-target-but-records-stay-or-loop-on-source/37699 "2025-04-24T15:22:02Z")

</div>

MirrorMaker 2: topic gets created on target but records stay (or loop) on source Behaviour Topology Source cluster (Docker Compose, Confluent 7.9.0, PLAINTEXT) → firewall / DNAT → Target cluster (Strimzi, TLS + SCRAM, …

---

## [While creating the cluster, we are encountering issues with the 3 controllers](https://forum.confluent.io/t/while-creating-the-cluster-we-are-encountering-issues-with-the-3-controllers/37642)

<div class="topic-metadata">

**Author:** [@naveen](https://forum.confluent.io/u/naveen)\
**Replies:** 9\
**Last updated:** [14 April 2025 12:34 UTC](https://forum.confluent.io/t/while-creating-the-cluster-we-are-encountering-issues-with-the-3-controllers/37642 "2025-04-14T12:34:53Z")

</div>

Dear Team, While creating the KRaft cluster with 3 controllers and 3 brokers using the Confluent Operator, we created the controller resource definition file as shown below. However, upon startup, we are continuously en…

---

## [java.io.IOException: Packet len 9592748 is out of range! (zk- broker not communicating)](https://forum.confluent.io/t/java-io-ioexception-packet-len-9592748-is-out-of-range-zk-broker-not-communicating/37627)

<div class="topic-metadata">

**Author:** [@SaiKrishnaNeeli](https://forum.confluent.io/u/SaiKrishnaNeeli)\
**Replies:** 6\
**Last updated:** [4 April 2025 12:20 UTC](https://forum.confluent.io/t/java-io-ioexception-packet-len-9592748-is-out-of-range-zk-broker-not-communicating/37627 "2025-04-04T12:20:29Z")

</div>

Hi Team, We recently encountered an issue where there was a communication gap between the Kafka brokers and Zookeeper, leading to aborted internal operations. Broker Log Observed: Image: Image: confluentinc/cp-kafka:7…

---

## [Kafka broker failure not happening when network is partitioned](https://forum.confluent.io/t/kafka-broker-failure-not-happening-when-network-is-partitioned/37620)

<div class="topic-metadata">

**Author:** [@sobhansaf](https://forum.confluent.io/u/sobhansaf)\
**Replies:** 8\
**Last updated:** [4 April 2025 10:34 UTC](https://forum.confluent.io/t/kafka-broker-failure-not-happening-when-network-is-partitioned/37620 "2025-04-04T10:34:21Z")

</div>

hi everybody. I did an experiment in regard to kafka replication using docker-compose. I created a 3-node kafka cluster. I created 3 networks for connectivity between each two nodes. i.e. one network which node 1 and nod…

---

## [Apache Kafka MirrorMaker 2 (MM2) bidirectional replication A \<-\> B](https://forum.confluent.io/t/apache-kafka-mirrormaker-2-mm2-bidirectional-replication-a-b/37028)

<div class="topic-metadata">

**Author:** [@Mahesh](https://forum.confluent.io/u/Mahesh)\
**Replies:** 9\
**Last updated:** [31 March 2025 07:50 UTC](https://forum.confluent.io/t/apache-kafka-mirrormaker-2-mm2-bidirectional-replication-a-b/37028 "2025-03-31T07:50:50Z")

</div>

We have 2 clusters one in On\_prem (10 brokers) and another on GCP (6 brokers). We have setup mm2 on GCP kafka cluster to replicate data to & from On\_prem. Replication from GCP to On\_prem: We see replication is running o…

---

## [Observability tool for Confluent community](https://forum.confluent.io/t/observability-tool-for-confluent-community/37546)

<div class="topic-metadata">

**Author:** [@Lisha](https://forum.confluent.io/u/Lisha)\
**Replies:** 0\
**Last updated:** [21 March 2025 05:31 UTC](https://forum.confluent.io/t/observability-tool-for-confluent-community/37546 "2025-03-21T05:31:48Z")

</div>

Hi Please suggest an observability tool that is best for Distributed tracing, understanding kafka latency and management

---

## [Mirror Maker 2 offsets synchronization problem](https://forum.confluent.io/t/mirror-maker-2-offsets-synchronization-problem/37517)

<div class="topic-metadata">

**Author:** [@arthura](https://forum.confluent.io/u/arthura)\
**Replies:** 1\
**Last updated:** [19 March 2025 07:35 UTC](https://forum.confluent.io/t/mirror-maker-2-offsets-synchronization-problem/37517 "2025-03-19T07:35:57Z")

</div>

We are trying to replicate a topic called “RTNS” on site A to a topic called “10\_20\_for\_backup\_RTNS” on site B. Site B also has RTNS topic which is replciated to site A. A consumer group called “realtime-notifications-…

---

## [SASL PLAIN\_TEXT using env variables not working](https://forum.confluent.io/t/sasl-plain-text-using-env-variables-not-working/37436)

<div class="topic-metadata">

**Author:** [@Amo](https://forum.confluent.io/u/Amo)\
**Replies:** 0\
**Last updated:** [8 March 2025 00:19 UTC](https://forum.confluent.io/t/sasl-plain-text-using-env-variables-not-working/37436 "2025-03-08T00:19:00Z")

</div>

Hello, Been fighting with this for a while, I cant’ get a the following docker-compose.yml file to work. I have the constraints I can’t mount volumes to my docker, so everything has to be passed as an env variable. ver…

---

## [Allow \_\_consumer\_offsets creation when auto.create.topics.enable=false](https://forum.confluent.io/t/allow-consumer-offsets-creation-when-auto-create-topics-enable-false/37405)

<div class="topic-metadata">

**Author:** [@FrVaBe](https://forum.confluent.io/u/FrVaBe)\
**Replies:** 2\
**Last updated:** [6 March 2025 09:33 UTC](https://forum.confluent.io/t/allow-consumer-offsets-creation-when-auto-create-topics-enable-false/37405 "2025-03-06T09:33:38Z")

</div>

We would like to have strict control over the topics in our system and therefore prohibit the automatic creation of topics via the broker property auto.create.topics.enable=false. Unfortunately, this means that the auto…

---

## [What happens to a one-voter setup failure after KIP-853?](https://forum.confluent.io/t/what-happens-to-a-one-voter-setup-failure-after-kip-853/37337)

<div class="topic-metadata">

**Author:** [@afjoseph](https://forum.confluent.io/u/afjoseph)\
**Replies:** 0\
**Last updated:** [26 February 2025 09:28 UTC](https://forum.confluent.io/t/what-happens-to-a-one-voter-setup-failure-after-kip-853/37337 "2025-02-26T09:28:10Z")

</div>

Hey. From what I read, v3.9.0 supports KIP-853 (dynamic controller quorum) What would happen in the following scenario: 3 brokers (broker1,broker2,broker3), one of them is designated as the voter (broker1) i.e., foll…

---

## [CFK Cluster link](https://forum.confluent.io/t/cfk-cluster-link/37258)

<div class="topic-metadata">

**Author:** [@agvsap1](https://forum.confluent.io/u/agvsap1)\
**Replies:** 2\
**Last updated:** [24 February 2025 13:34 UTC](https://forum.confluent.io/t/cfk-cluster-link/37258 "2025-02-24T13:34:43Z")

</div>

Hi I have created this ClusterLink, but kafka pods reports this errors en destination cluster: \[ERROR\] 2025-02-16 16:54:05,790 \[kafka-admin-client-thread | cluster-link-client-admin-clusterlink-tfn-global-destination-2…

---

## [Confluent operator cve-2024-45337 vulnerability](https://forum.confluent.io/t/confluent-operator-cve-2024-45337-vulnerability/37299)

<div class="topic-metadata">

**Author:** [@Beniyeal1](https://forum.confluent.io/u/Beniyeal1)\
**Replies:** 1\
**Last updated:** [21 February 2025 16:33 UTC](https://forum.confluent.io/t/confluent-operator-cve-2024-45337-vulnerability/37299 "2025-02-21T16:33:27Z")

</div>

Hi Team, Confluent operator images has cve-2024-45337 vulnerability and could not find a latest version that resolved this. Kindly confirm when this can be resolved. |CFK Helm Version|CFK Image Tag| |2.10.0|0.1145.6|

---

## [Scale MirrorMaker2 to Run Multiple Instances](https://forum.confluent.io/t/scale-mirrormaker2-to-run-multiple-instances/4448)

<div class="topic-metadata">

**Author:** [@jk4102](https://forum.confluent.io/u/jk4102)\
**Replies:** 6\
**Last updated:** [21 February 2025 08:28 UTC](https://forum.confluent.io/t/scale-mirrormaker2-to-run-multiple-instances/4448 "2025-02-21T08:28:33Z")

</div>

Hello! I’m wondering if it’s possible to run multiple instances of MM2 per data center? I am trying to run 2 instances of connect-mirror-maker.sh per data center for scalability purposes. However, I cannot get 2 instanc…

[Next page](https://forum.confluent.io/c/ops/17.md?page=1)
