Cloud

rpk security acl list

List ACLs.

See the rpk security acl help text for a full write up on ACLs. List flags work in a similar multiplying effect as creating ACLs, but list is more advanced: listing works on a filter basis. Any unspecified flag defaults to matching everything (all operations, or all allowed principals, etc).

As mentioned, not specifying flags matches everything. If no resources are specified, all resources are matched. If no operations are specified, all operations are matched. You can also opt in to matching everything with any: --operation any matches any operation.

The --resource-pattern-type, defaulting to any, configures how to filter. resource names: * any returns exact name matches of either prefixed or literal pattern type * match returns wildcard matches, prefix patterns that match your input, and literal matches * prefix returns prefix patterns that match your input (prefix fo matches foo) * literal returns exact name matches

The list command lists ACLs for both Kafka and Schema Registry. To limit the results to a specific subsystem, use the --subsystem flag with either kafka or registry.

Usage

rpk security acl list [flags]

Aliases

rpk security acl ls
rpk security acl describe

Examples

This section provides examples of how to use rpk security acl list.

List all ACLs.

rpk security acl list

List all Schema Registry ACLs.

rpk security acl list --subsystem registry

List all ACLs for topic "foo".

rpk security acl list --topic foo

List all ACLs for user "bar" on topic "foo".

rpk security acl list --allow-principal bar --topic foo

List all ACLs for role "admin" on schema registry subject "foo-value".

rpk security acl list --allow-role admin --registry-subject foo-value

Flags

Value Type Description

--allow-host

stringSlice

Allowed host ACLs to match (repeatable).

--allow-principal

stringSlice

Allowed principal ACLs to match (repeatable).

--allow-role

stringSlice

Allowed role ACLs to match (repeatable).

--cluster

bool

Whether to match ACLs to the cluster.

--deny-host

stringSlice

Denied host ACLs to match (repeatable).

--deny-principal

stringSlice

Denied principal ACLs to match (repeatable).

--deny-role

stringSlice

Denied role ACLs to match (repeatable).

--format

string

Output format (json,yaml,text,wide,help).

--group

stringSlice

Group to match ACLs for (repeatable).

--operation

stringSlice

Operation to match (repeatable).

-f, --print-filters

bool

Print the filters that were requested (failed filters are always printed).

--registry-global

bool

Whether to match ACLs for the schema registry.

--registry-subject

stringSlice

Schema registry subjects to match ACLs for (repeatable).

--resource-pattern-type

string

Pattern to use when matching resource names (any, match, literal, or prefixed).

--subsystem

stringSlice

The subsystem to match ACLs for (kafka, registry, or both).

--topic

stringSlice

Topic to match ACLs for (repeatable).

--transactional-id

stringSlice

Transactional IDs to match ACLs for (repeatable).

Global flags

Value Type Description

--config

string

Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml.

-X, --config-opt

stringArray

Override rpk configuration settings; -X help for detail or -X list for terser detail.

--ignore-profile

bool

Ignore rpk.yaml and redpanda.yaml; use default settings.

--profile

string

rpk profile to use.

-v, --verbose

bool

Enable verbose logging.