rpk security acl list
List ACLs.
See the rpk security acl help text for a full write up on ACLs. List flags
work in a similar multiplying effect as creating ACLs, but list is more
advanced: listing works on a filter basis. Any unspecified flag defaults to
matching everything (all operations, or all allowed principals, etc).
As mentioned, not specifying flags matches everything. If no resources are
specified, all resources are matched. If no operations are specified, all
operations are matched. You can also opt in to matching everything with any:
--operation any matches any operation.
The --resource-pattern-type, defaulting to any, configures how to filter.
resource names:
* any returns exact name matches of either prefixed or literal pattern type
* match returns wildcard matches, prefix patterns that match your input, and literal matches
* prefix returns prefix patterns that match your input (prefix fo matches foo)
* literal returns exact name matches
The list command lists ACLs for both Kafka and Schema Registry. To limit the
results to a specific subsystem, use the --subsystem flag with either kafka or
registry.
Examples
This section provides examples of how to use rpk security acl list.
List all ACLs.
rpk security acl list
List all Schema Registry ACLs.
rpk security acl list --subsystem registry
List all ACLs for topic "foo".
rpk security acl list --topic foo
List all ACLs for user "bar" on topic "foo".
rpk security acl list --allow-principal bar --topic foo
List all ACLs for role "admin" on schema registry subject "foo-value".
rpk security acl list --allow-role admin --registry-subject foo-value
Flags
| Value | Type | Description |
|---|---|---|
|
stringSlice |
Allowed host ACLs to match ( |
|
stringSlice |
Allowed principal ACLs to match ( |
|
stringSlice |
Allowed role ACLs to match ( |
|
bool |
Whether to match ACLs to the cluster. |
|
stringSlice |
Denied host ACLs to match ( |
|
stringSlice |
Denied principal ACLs to match ( |
|
stringSlice |
Denied role ACLs to match ( |
|
string |
Output format ( |
|
stringSlice |
Group to match ACLs for ( |
|
stringSlice |
Operation to match ( |
|
bool |
Print the filters that were requested (failed filters are always printed). |
|
bool |
Whether to match ACLs for the schema registry. |
|
stringSlice |
Schema registry subjects to match ACLs for ( |
|
string |
Pattern to use when matching resource names ( |
|
stringSlice |
The subsystem to match ACLs for ( |
|
stringSlice |
Topic to match ACLs for ( |
|
stringSlice |
Transactional IDs to match ACLs for ( |
Global flags
| Value | Type | Description |
|---|---|---|
|
string |
Redpanda or |
|
stringArray |
Override |
|
bool |
Ignore |
|
string |
|
|
bool |
Enable verbose logging. |