# Accessing kafka broker deployed on Kubernetes on GCP - does it require SASL?

**URL:** <https://forum.confluent.io/t/accessing-kafka-broker-deployed-on-kubernetes-on-gcp-does-it-require-sasl/3331>\
**Category:** Containers\
**Created:** [10 November 2021 06:14 UTC](https://forum.confluent.io/t/accessing-kafka-broker-deployed-on-kubernetes-on-gcp-does-it-require-sasl/3331 "2021-11-10T06:14:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![karan.alang](https://avatars.discourse-cdn.com/v4/letter/k/ee59a6/32.png) [@karan.alang](https://forum.confluent.io/u/karan.alang)\
**Post date:** [10 November 2021 06:14 UTC](https://forum.confluent.io/t/accessing-kafka-broker-deployed-on-kubernetes-on-gcp-does-it-require-sasl/3331/1 "2021-11-10T06:14:17Z")

</div>

I’ve deployed Kafka on Kubernetes on GCP, referring the below link :

[https://www.qwiklabs.com/focuses/11777?locale=zh\_TW&parent=catalog](https://www.qwiklabs.com/focuses/11777?locale=zh_TW&parent=catalog)

I’ve created Ingress port, and am able to access the Control Center on the kafka-ingress port.

However, when i try to access the kafka broker using external endpoint(kafka-bootstrap-lb) it gives the following error :

```auto
104.198.74.49:9092/bootstrap: Disconnected: verify that security.protocol is correctly configured, broker might require SASL authentication (after 380ms in state UP)

```

Do I need to access the broker using SASL ? Any input on this would be appreciated!

 ![Screen Shot 2021-11-09 at 9.57.45 PM](https://us1.discourse-cdn.com/flex019/uploads/confluentcommunity/original/2X/7/7f41d27896afb1c277a00c88dbec0dc8ec452248.png)

tia!

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [10 November 2021 08:51 UTC](https://forum.confluent.io/t/accessing-kafka-broker-deployed-on-kubernetes-on-gcp-does-it-require-sasl/3331/2 "2021-11-10T08:51:33Z")

</div>

hi,

quickly checked the blog post and github repo.  
if my understanding is correct there is a sasl config in place, see

> <https://github.com/jasonsmithio/confluent-kafka-on-gcp-legacy/blob/57828e3f9e08cadd9e7fab4990b9626538836952/kafka/gke/cfg/kafka-client-secrets.yaml>

hth,  
michael

---

<div class="post-metadata">

**Author:** ![karan.alang](https://avatars.discourse-cdn.com/v4/letter/k/ee59a6/32.png) [@karan.alang](https://forum.confluent.io/u/karan.alang)\
**Post date:** [10 November 2021 23:36 UTC](https://forum.confluent.io/t/accessing-kafka-broker-deployed-on-kubernetes-on-gcp-does-it-require-sasl/3331/3 "2021-11-10T23:36:07Z")

</div>

HI -  
Thanks for the response !  
I’m trying tp understand how to access the broker using the sasl config you mentioned to access the brokers in the K38 cluster.

In the local instance of my kafka cluster, i run the following command -

$CONFLUENT\_HOME/bin/kafka-console-producer --broker-list Karans-MacBook-Pro.local:9093 --topic karantest --producer.config $CONFLUENT\_HOME/props/client-ssl.properties

What do i need to do when i want to access the kafka cluster in Kubernetes(in GCP) ?

any pointers on this will really help!

tia!

---

<div class="post-metadata">

**Author:** ![karan.alang](https://avatars.discourse-cdn.com/v4/letter/k/ee59a6/32.png) [@karan.alang](https://forum.confluent.io/u/karan.alang)\
**Post date:** [10 November 2021 23:49 UTC](https://forum.confluent.io/t/accessing-kafka-broker-deployed-on-kubernetes-on-gcp-does-it-require-sasl/3331/4 "2021-11-10T23:49:13Z")

</div>

Pls note - this is another pod (client-console) in the k38 cluster which is able to access the kafka broker and produce/consume data using the command →

kafka-console-consumer --bootstrap-server kafka:9071 --consumer.config /etc/kafka-client-properties/kafka-client.properties --topic clicks --from-beginning

However, i’m trying to figure out how to access from my local machine (or any other external client)

Pls let me know if you have any inputs on this.

thanks!

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [11 November 2021 09:24 UTC](https://forum.confluent.io/t/accessing-kafka-broker-deployed-on-kubernetes-on-gcp-does-it-require-sasl/3331/5 "2021-11-11T09:24:25Z")

</div>

thx  
basically it should work similar as connecting from within the k8s cluster

copy the client-properties to your local env and then

````nohighlight
104.198.74.49:9092 --consumer.config /etc/kafka-client-properties/kafka-client.properties --topic clicks --from-beginning```
````
