KubeMQ
ConnectorsKafkaReference

Configuration reference

Kafka connector settings at a glance — the on-by-default enable flag, the 9092/9093 ports, TOML/environment/Docker examples, and the full settings reference.

Overview

The canonical field-by-field reference is connector settings — every Connectors.Kafka.* field, its default, its valid range, and its CONNECTORS_KAFKA_* / spec.kafka.* names. This page is an orientation pass: the handful of settings that decide whether the connector is on, which ports it opens, and how it's secured, plus copy-paste TOML/environment/Docker examples. For the narrative behind these settings — why the connector is on by default and what its security posture looks like — see Configuration concepts.

At a glance

SettingDefaultWhat it controls
Enable — CONNECTORS_KAFKA_ENABLE / spec.kafka.enabledtrueOn by default. Set false to close the wire listeners. Left at the default, a configuration the connector cannot run under (legacy storage engine, port clash, undeterminable per-broker addresses) prints one stderr WARNING and the server boots without Kafka; an explicit true makes those same problems fatal startup errors.
Port — CONNECTORS_KAFKA_PORT / spec.kafka.port9092The plaintext TCP listener.
TlsPort — CONNECTORS_KAFKA_TLS_PORT / spec.kafka.tlsPort9093The TLS listener — the only listener OAUTHBEARER and mTLS are enforced on.
Credentials / SaslMechanismsnone / []Populating the SASL credential store turns on SASL/PLAIN + SCRAM auth; SaslMechanisms narrows which mechanisms SaslHandshake offers.
OAuthBearer.Issuer""Non-empty activates OAUTHBEARER — there's no separate enable flag.
AdvertisedHost / AdvertisedPort"" / 0The client-reachable address handed to Kafka clients in Metadata/FindCoordinator — set this in Kubernetes to avoid a connect-then-hang.

This table is an orientation pass, not the full settings list — the connector has roughly two dozen fields, including advanced tuning knobs (fetch wait, offsets retention, transaction timeouts, quotas) that have no CRD/Helm path yet. See connector settings → Kafka for every field, and Authentication for the full SASL/OAUTHBEARER/mTLS story.

Examples

The same settings can be supplied through a TOML config file, environment variables, or docker run flags. Every environment variable uses the CONNECTORS_KAFKA_ prefix.

config.toml
[Connectors.Kafka]
  Enable = false   # on by default; set false to turn the connector off
  Port = "9092"
  TlsPort = "9093"
  AdvertisedHost = ""
  AdvertisedPort = 0
  MaxConnections = 1000
  MaxMessageBytes = 1048576
kafka.env
CONNECTORS_KAFKA_ENABLE=false   # on by default; set false to turn the connector off
CONNECTORS_KAFKA_PORT=9092
CONNECTORS_KAFKA_TLS_PORT=9093
CONNECTORS_KAFKA_ADVERTISED_HOST=
CONNECTORS_KAFKA_ADVERTISED_PORT=0
CONNECTORS_KAFKA_MAX_CONNECTIONS=1000
CONNECTORS_KAFKA_MAX_MESSAGE_BYTES=1048576
docker run -d \  --pull always \  --platform linux/amd64 \  --name kubemq \  --hostname kubemq \  -p 127.0.0.1:9092:9092 \  -p 127.0.0.1:9093:9093 \  -p 127.0.0.1:50000:50000 \  -p 127.0.0.1:8080:8080 \  -e STORE_ENGINE=next \  -e STORE_NEXT_ACK_POLICY=strict \  -e STORE_STORE_PATH=/kubemq/store \  -e API_BIND_ADDRESS=0.0.0.0 \  -v kubemq-data:/kubemq/store \  europe-docker.pkg.dev/kubemq/images/kubemq-next:latest

The Docker example sets no enable variable — the connector is on by default, so 9092 is bound out of the box (and 9093 once TLS is configured); the image EXPOSEs both. Add -e CONNECTORS_KAFKA_ENABLE=false to turn it off. Port 50000 is the native KubeMQ gRPC listener, included so the same container also accepts KubeMQ SDK clients.

Was this page helpful?

On this page