Hi team I am using Kafka emitter, and we have setu...
# all-things-deployment
c
Hi team I am using Kafka emitter, and we have setup authentication for our Kafka client environment and schema registry (local) is pointing to https And we write our action pipeline from which we passing our configuration. This my emitter: For Kafka it’s able to authenticate and connect to client Kafka but for schema registry it is showing Ssl certificate error. Please refer the action config that we have as well
Any update on this ?
@brainy-tent-14503
b
I am afraid I don’t fully understand the context here. Let me see if I can try to focus in on the problem, there are some configuration snippets. First I am guessing you mean the python emitter, not a java one, based on the first screenshot. So this doc on the python emitter. That seems to be created using that other data in the second screenshot. What is the error specifically? Is it an invalid cert or a protocol mismatch? In the schema registry url, did you remove the protocol? Why is there a url path? When you say schema registry
local
what do you mean by that? Do you mean using GMS as the schema registry with an
INTERNAL
configuration? If using the INTERNAL configuration, how did you implement the SSL encryption? What is doing the decoding and what is managing the certs there?
c
Yes we are using python emitter and in kafka configuration we are have setup basic authentication for kafka ( for external communication) and in producer config we are providing required configuration for this in order to connect to Kafka deployed in other cluster. For schema registry we haven’t setup any authentication it’s only on https ( using internal schema registry gms) and in schema registry config we are passing ssl.ca.location but it’s unable to verify certs and it’s working when the schema registry url is on http. Error : Http local issueers unable to verify certs And all these configuration coming from my action Pipeline config section.
Is it a correct way to passing ca chain as for Kafka it’s working but for schema it is throwing error
@dazzling-judge-80093
a
Is this a custom action? What do you do with that config in your action?
c
We have custom action that will convert MCL into MCP and we are using Kafka emitter to push those MCP into client environment which is being replicated there via mirror maker. In the action config we are passing the required keys like bootstrap url, ca location , username and password for basic auth. And we are able to connect to Kafka of client environment but with schema registry( internal gms) it’s not working on https( ssl certificate verification failed: local issuers) but working on http And we have the provided configuration as shown in above picture
a
Based on the code we pass in everything to the Confluent’s Schema Registry client whatever you set in
schema_registry_config
-> https://github.com/datahub-project/datahub/blob/ddcd5109dcbe01aac28347cf34221d65cb5faa30/metadata-ingestion/src/datahub/emitter/kafka_emitter.py#L65
Here in the example you can see how the add schema_registry config -> https://datahubproject.io/docs/metadata-ingestion/as-a-library/#example-usage-1
c
I tried to understand and provide the values like this now. Is it a correct way of passing ? @dazzling-judge-80093
a
This looks fine to me
c
While running I am getting x509 certificate signed by unknown authority error
a
Can you check if the generated config looks ok? It is hard to see from this code snippet.
c
Does Kafka and schema requires different certificates ?
a
It depends on your setup
c
The values are coming from action config file and I have checked the values I am getting this error : X509: certificate signed by unknown authority
d
But here the gms’ healthcheck threw the certificate issue and not the action, am I right?
or more precisely when the action tries to connect to the healthcheck
c
Right
Then how can I resolve this ?
I think you can do the following:: 1. Set an environment variable for your Docker container and specify the SSL cert file with the
SSL_CERT_FILE
environment variable. Based on Golang’s doc (which is the language dockerize was built):
Copy code
On Unix systems other than macOS the environment variables SSL_CERT_FILE and SSL_CERT_DIR can be used to override the system default locations for the SSL certificate file and SSL certificate files directory, respectively. The latter can be a colon-separated list.
c
Hi tamas The above issue is fix but after adding the config into schema registry client like this My python code is giving this error : str object is not a mapping Can you please have a look on this picture ? And check it’s a correct way of providing ?
@brainy-tent-14503 and @dazzling-judge-80093
@mammoth-bear-12532
This error is coming at schema_registry_conf = { ‘Url’ : self.action_config. Schema_registry_url , **self.action_config.ssl_ca_istio_location
a
@creamy-van-28626, this issue happens if your variable is not a dict but a string you pass. Please, can you check/print
self.action_config.ssl_ca_istio_location
?
c
I am Using only Kafka emitter and in that I am providing all the configuration But only for schema registry certificate verification I am getting error :
It’s not working for ssl.ca.location and producer config is working fine
Is it correct way right?
d
is it intentional you are passing a different ca for producer than for schema_registry?
c
If we pass the same also same error
Unable to get local issuer certificate
But when I am crul the url to that particular location I am getting reposne
d
Do you pass the ca file to the curl command?
c
Yes
How can I fix this and I am stuck from 1 week on this
a
The config seems to be ok. Do you pass the same ca file location which you used in your curl command?
c
Curl —cacert etc/ssl/certs/ca.cry (url) I am using this command and getting response
Yeah same one
How can we disable verification in Kafka emitter then in order to resolve this issue ?
I can see no option in Kafka emitter code
For schema_registry if we want to disable verification
a
I checked the code, and I’m confident the set properties are passed to the Schema Registry client. Here is my test recipe:
Copy code
source:
  type: "kafka"
  config:
    connection:
      bootstrap: "localhost:9092"
      #consumer_config:
      #  security.protocol: "SASL_SSL"
      #  sasl.mechanism: "PLAIN"
      #  sasl.username: "kafka_key"
      #  sasl.password: "kafka_secret"
      schema_registry_url: "<http://localhost:8081>"
      schema_registry_config:
        # See <https://docs.confluent.io/platform/current/clients/confluent-kafka-python/html/index.html#confluent_kafka.schema_registry.SchemaRegistryClient>
        # Most of these config keys are optional.
        ssl.ca.location: "certificate_ca.pem"
        ssl.certificate.location: "certificate.pem"
        ssl.key.location: "private_key.pem"
        ssl.key.password: "XXXXXXX"
based on the Confluent Schema Registry Python code there is a way to disable SSL cert verification, even though it is a bit hacky, if you set the
ssl.ca.location
to
false
c
I am using Kafka emitter only and I am setting all these configuration like this
Does we need to pass these to schema registry client as it’s already a Kafka emitter
a
For the emitter the config looks like this:
Copy code
sink:
  type: "datahub-kafka"
  config:
    connection:
      bootstrap: localhost:9092
      schema_registry_url: <http://localhost:8081>
      schema_registry_config:
        # See <https://docs.confluent.io/platform/current/clients/confluent-kafka-python/html/index.html#confluent_kafka.schema_registry.SchemaRegistryClient>
        # Most of these config keys are optional.
        #ssl.ca.location: "certificate_ca.pem"
        ssl.certificate.location: "certificate.pem"
        ssl.key.location: "private_key.pem"
and here I verified as well the config properties are passed to the Conflunet Schema Registry client
c
I have this python code for Kafka emitter and all the configuration are passed from action pipeline
Like this
Is it correct ?
a
As this is a custom code, I would debug your code if it passes properly the parameters you set. Unfortunately, I can only test/check what is in our codebase and there the Kafka Emitter should pass the property if it is passed properly
As I said another thing your can try to set the
ssl.ca.location
to
False
if you are sure you set that property and you want to disable verifying the server’s certificate
c
Let me share you
a
Can’t you debug your code in standalone mode without the action framework?
just to see if the Kafka Emitter gets the proper parameters
c
Yeah debug that it’s working fine
In action framework I am passing correctly ?
a
or log from your code the config you pass to the Kafka Emitter and check from the Action Framework logs
c
Setting ssl.ca.location to false also not working