Skip to content

Connect Clusters

Connect clusters are required when using MirrorMaker 2 or Confluent Replicator as your replication tool. These clusters host the replication connectors that move data between Kafka clusters.

The summary page displays all registered Connect clusters with their validation status. Use the search bar to locate a specific cluster.

Click Add Connect Cluster to open the registration form.

FieldRequiredDescription
Cluster AliasYesA unique name for the Connect cluster.
DescriptionNoOptional description of the cluster.
TagsNoOptional tags for organization.
REST EndpointYesThe URL of the Kafka Connect REST API.

SSL Certificate Locations and Keytab Paths

Section titled “SSL Certificate Locations and Keytab Paths”

If SSL or Kerberos authentication is configured on the associated Kafka clusters, provide the file paths as they exist on the Connect cluster host. These paths tell the Connect workers where to find the certificates and keytab files at runtime.

FieldDescription
Keystore LocationPath to the keystore file on the source Connect worker. Example: /etc/kafka/ssl/source-keystore.jks
Truststore LocationPath to the truststore file on the source Connect worker. Example: /etc/kafka/ssl/source-truststore.jks
FieldDescription
Keystore LocationPath to the keystore file on the destination Connect worker. Example: /etc/kafka/ssl/dest-keystore.jks
Truststore LocationPath to the truststore file on the destination Connect worker. Example: /etc/kafka/ssl/dest-truststore.jks or a custom path such as /mnt/kafka/external-configuration/app-certs-cz

Ensure your Connect workers already have the keytab files deployed to their filesystem before filling in these paths. KMI does not transfer keytab files to Connect workers; it only passes the paths to the connector configuration.

When a source or destination Kafka cluster uses Kerberos, provide the filesystem paths where the Connect workers can find the keytab files at runtime. If the destination cluster also uses SSL, ensure the destination truststore path is set under Destination Kafka Cluster SSL Locations above.

Source Kerberos cluster

FieldDescription
Source Keytab PathPath to the keytab file on the source Connect worker. Example: /mnt/kafka/external-configuration/kerberos-client.keytab

Destination Kerberos cluster

FieldDescription
Destination Keytab PathPath to the keytab file on the destination Connect worker. Example: /etc/kafka/keytabs/dest.keytab
Destination Truststore LocationIf the destination Kerberos cluster also uses SASL_SSL, provide the path to the truststore on the destination Connect worker. Example: /mnt/kafka/external-configuration/app-certs-cz

The following examples show a fully configured Add Connect Cluster form with SSL locations and Kerberos keytab paths filled in, after a successful connection test.

Add Connect Cluster — mm2-source-kerberos with Kerberos keytab paths and SSL locations configured

Add Connect Cluster — mm2_source_cp_sasl_ssl_k with custom destination truststore path and Kerberos keytab paths configured

Select the authentication method that matches your Connect cluster’s REST API configuration.

No authentication is required for the Connect REST API.

No authentication

When your migration source uses Cloudera-native serialization and the replication tool is MirrorMaker 2 or Replicator, install the Cloudera re-frame Single Message Transform (SMT) on the Connect cluster. The SMT rewrites Cloudera-native wire-format bytes so Confluent consumers on the destination can deserialize them.

  1. Download the sample SMT Java source from the plan and build it into a jar (or use your own implementation that matches the configured class name).

  2. Copy the jar to a directory on the Connect worker’s plugin path. The plugin path is the directory (or set of directories) configured in the worker’s plugin.path property (for example, /opt/kafka/plugins/).

    Terminal window
    cp cloudera-reframe-smt.jar /opt/kafka/plugins/
  3. Restart the Connect worker so it picks up the new plugin.

  4. Verify that the plugin is available by checking the Connect REST API:

    Terminal window
    curl http://<connect-host>:8083/connector-plugins | grep -i reframe

    The class name from your SMT configuration block should appear in the list.

After configuring the Connect cluster, click Test Connection to verify that the suite can reach the Connect REST API with the provided credentials.

Connection test failure

Click the three-dot menu on any cluster row and select Edit to modify its configuration. You can also re-test the connection from the edit view.

Connect cluster action menu

Click the three-dot menu and select Delete. A confirmation dialog is displayed before the cluster is removed.

Delete confirmation dialog

Cluster deleted successfully