Skip to content

ACLs Tab

The ACLs tab lists the access control lists (ACLs) chosen for replication between the source and destination clusters and shows whether each one has reached the destination.

The tab appears only when ACL replication was enabled during job creation (the Sync ACLs option on the Tool Selection step) and only for Cluster Linking and MirrorMaker 2 jobs. Replicator and WarpStream Orbit jobs do not support ACL replication, so the tab is not shown for them.

The tab shows the ACLs selected for replication. ACLs included in the migration display a Selected badge.

ColumnDescription
PrincipalThe user or service account the rule applies to, for example User:alice
Resource TypeThe kind of resource the rule covers: Topic, Group, Cluster, or Transactional ID
Resource NameThe name of the topic, group, or other resource the rule applies to
Pattern TypeWhether the resource name is matched literally or as a prefix
OperationThe action the rule governs, such as Read, Write, or Describe
PermissionWhether the rule allows or denies the operation
HostThe host the rule applies to, or any host

Use the search box to filter by principal, resource, or operation. The table is paginated when there are many ACLs.

If no ACLs match the current view, the tab shows “No ACLs available”, or “No ACLs match your search” when a search filter is active.

While the job is running, the Monitor view shows the live sync status of each ACL:

StatusMeaning
SyncedThe ACL has been created on the destination cluster
PendingThe ACL is in the process of being created on the destination
UnknownThe status cannot be determined yet, usually a temporary monitoring gap

The Manage ACLs tab lets you add a new ACL to replication after the job has started, without recreating the job. It lists the ACLs on the source cluster, each with a status:

StatusMeaning
SelectedThe ACL is already being replicated
Available to AddThe ACL exists on the source and can be added to replication
ConflictingThe ACL already exists on the destination with different settings, so it cannot be added
ExcludedThe ACL is blocked by an exclusion pattern set during job creation

To add ACLs, select one or more entries marked Available to Add and confirm. A dialog asks you to confirm the addition, and the selected ACLs begin replicating to the destination. You can add several at once using the row checkboxes.

Adding an ACL requires the Manage ACLs permission and a running job. The Add action is unavailable for ACLs that are already replicated, conflicting, or excluded.