Complete these steps to configure VAST Event Broker:
Verifying a Virtual IP Pool for VAST Event Broker
With you cluster admin, verify that there is a virtual IP pool that can be used to access the event topics using the Kafka protocol. The pool must have the PROTOCOLS roles assigned.
The pool must have enough virtual IPs so that there is at least one virtual IP per CNode.
If the VAST Event Broker view will be associated with a view policy that includes virtual IP pools, the pool specified as the Kafka pool must be one of the view policy pools.
Configuring a User for VAST Event Broker
Configure a user on the authentication provider attached to the tenant where VAST Event Broker will run so that the user has S3 bucket creation permissions and S3 access keys.
This user will be assigned as the bucket owner when creating a view for VAST Event Broker.
Creating a VAST Event Broker View
VAST Event Broker runs on a view that has Kafka protocol enabled.
Note
View nesting is not supported.
Follow the steps in Creating Views to create a VAST Event Broker view as follows:
Enter a Path to the location where event topics will be stored.
Enable the setting to Create directory for the view.
Specify a view Policy that enforces S3 Native security flavor.
Specify Kafka as the view's Protocol.
Enabling the Kafka protocol automatically enables the S3 Bucket and Database protocols for the view.
Adding the Kafka protocol to an existing view is not allowed.
Enter an S3 bucket name for the view.
Specify the user configured for VAST Event Broker as the Bucket owner (in the S3 tab in VAST Web UI).
Set the view to use the Virtual IP pool you created for VAST Event Broker (in the Kafka tab in VAST Web UI).
Only one virtual IP pool can be associated with a VAST Event Broker view.
Once the view has been created, the virtual IP pool cannot be replaced by another one (but it can be modified if needed).
Configuring User Authentication for the VAST Event Broker View
(Optional) Configure authentication of users accessing the Kafka-enabled view.
Users accessing a Kafka-enabled view can be authenticated against the tenant's VAST provider using the PLAIN Simple Authentication and Security Layer (SASL) mechanism. SASL/PLAIN authentication is available on both encrypted (TLS) and non-encrypted connections.
To configure user authentication:
In VAST Web UI, specify the required authentication method in the Authentication Methods pane of the Kafka tab in view settings (Element Store -> Views -> choose to create or edit a view).
If you are going to use SASL/PLAIN authentication with TLS, ensure that the VAST cluster has been configured with a TLS certificate intended for use with Kafka-enabled views. To check or upload a Kafka TLS certificate and a key:
In VAST Web UI, choose Settings -> Certificates and in the Certificates for field, select Kafka.
The following limitations apply:
Active Directory/LDAP is not supported. The user must be defined as a VAST local user.
Only one Kafka TLS certificate can be uploaded per VAST cluster.
TLS Certificate Requirements and Considerations
Specify virtual IPs in the SAN field.
Since the VAST cluster advertises IP addresses (but not DNS-resolvable names), SAN entries in the TLS certificate must specify IP addresses, for example:
X509v3 Subject Alternative Name: IP Address:xxx.xxx.xxx.xxxThe certificate must include one SAN entry per virtual IP across all virtual IP pools associated with VAST Event Broker views on the cluster.
CA-imposed restrictions on the maximum allowed number of SAN entries may apply.
The certificate should be issued by an internal CA.
Since VAST cluster's virtual IPs are in the private IP range (per RFC 1918), publicly trusted CAs cannot issue certificates with SAN entries containing such IPs.Ensure that the certificate can be reissued as needed.
After you set up TLS for an VAST Event Broker view, creating subsequent VAST Event Broker views on the same VAST cluster requires that you reissue the cluster's TLS certificate (having updated it with the virtual IPs for the newly added view) and upload the updated certificate to the VMS.
An unattributable or lost CA results in inability to add more VAST Event Broker views.
Tip: To view the contents of the cluster's TLS certificate in human-readable format, run from the client:
openssl s_client -connect <Kafka virtual IP>:<port> -showcerts
Configuring User Authorization for the VAST Event Broker View
(Optional) Configure authorization of users accessing the Kafka-enabled view.
Only explicitly allowed operations can be performed.
Enable authorization for the Kafka view:
In VAST Web UI, toggle the Enable authorization option on in view settings (Element Store -> Views -> choose to create or edit a view -> Kafka tab -> Authentication Methods pane).
Add Kafka-related actions to user identity policies.