Nov 2026
9 Mon
10 Tue
11 Wed
12 Thu
13 Fri 09:00 AM – 06:00 PM IST
14 Sat 09:00 AM – 06:00 PM IST
15 Sun
Guda Sai Vikhyath Reddy
@vikhyath
Submitted Oct 7, 2026
Session title
Kafka: The Infrastructure Around the Infrastructure
One-line summary
Evaluating Kafka ACLs, network boundary controls, and protocol-aware gateways (Kroxylicious) to tackle multi-team operational complexity at scale.
What problem are you addressing?
Kafka scales core messaging reliably, but as deployments expand across dozens of application teams and network boundaries, platform operations become complex. Requirements like IP whitelisting per broker, missing centralized audit visibility, and raw Kafka ACLs create operational friction and security risks when evolving infrastructure or onboarding new clients.
This session breaks down how to address these operational bottlenecks in production environments. We analyze where native Kafka capabilities (ACLs, broker networking) are sufficient, where introducing an intermediary layer like Kroxylicious simplifies governance, and the architectural trade-offs between native control versus proxy-based abstraction.
The focus is not on presenting a single solution, but on the engineering reasoning involved in deciding where a problem should be solved and what complexity each approach introduces.
Who is the intended audience?
Platform Engineering / SRE / DevOps / Infrastructure / Software Developers/Engineers
Level:
Intermediate/Advanced
List one or two practical takeaways.
What will you share?
What is your experience with this problem?
What approaches failed, disappointed, or created unexpected problems?
Relying solely on broker IP whitelisting and direct broker connectivity created operational bottlenecks whenever clusters were expanded or brokers were replaced. Additionally, enabling Kafka ACLs retroactively without detailed knowledge of topic ownership and active consumers posed a significant risk of breaking existing applications.
We examined the practical limitations of relying exclusively on broker-level networking and standard ACLs as client counts scale, challenges around auditing, client-side reconfiguration, and policy enforcement across heterogeneous teams.
Rather than treating these approaches as failures, we examined where they stop being sufficient for a particular operational requirement and what additional complexity alternative approaches introduce.
What will you do differently today?
What trade-offs did you consider?
How can this help other practitioners?
Current state
Prototype
Tags
#kafka #platformengineering #infrastructure #devops #sre #security #distributed-systems #kubernetes #networking #observability #architecture #failurestory #demo #casestudy #workinprogress #kroxylicious
(This will be a talk with 2 speakers)
{{ gettext('Login to leave a comment') }}
{{ gettext('Post a comment…') }}{{ errorMsg }}
{{ gettext('No comments posted yet') }}