#version: kafka-ui, 1.5.1 image: registry: docker.io repository: wbsong111/kafka-ui tag: "v1.3.0" pullPolicy: IfNotPresent yamlApplicationConfig: kafka: clusters: - name: kafka-cluster bootstrapServers: SASL_PLAINTEXT://kafka-cluster-kafka-tls-bootstrap.$kafka_cluster_namespace.svc.cluster.local:9093 properties: security.protocol: SASL_PLAINTEXT sasl.mechanism: OAUTHBEARER sasl.jaas.config: | org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required oauth.token.endpoint.uri="https://keycloak.gke.paasup.io/realms/paasup/protocol/openid-connect/token" oauth.client.id="service-demo01-kafka-common" oauth.client.secret="27537019-2070-4de3-b380-89a239cf1511"; sasl.login.callback.handler.class: "io.strimzi.kafka.oauth.client.JaasClientOauthLoginCallbackHandler" auth: type: disabled management: health: ldap: enabled: false volumes: - name: truststore secret: secretName: truststore volumeMounts: - name: truststore mountPath: /etc/kafka/secrets readOnly: true ingress: enabled: true annotations: cert-manager.io/cluster-issuer: "root-ca-issuer" cert-manager.io/duration: 8760h cert-manager.io/renew-before: 720h kubernetes.io/ingress.class: kong konghq.com/protocols: https host: "demo01-kafka-ui6.gke.paasup.io" tls: enabled: true secretName: "demo01-kafka-ui6-tls-secret"