AWS Lambda supports OAuth authentication for self-managed Apache Kafka event sources
AWS Lambda now supports OAuth authentication for self-managed Apache Kafka event source mappings (ESM), including Kafka clusters that customers run themselves and managed offerings such as Confluent Cloud, Aiven, and Redpanda. With this launch, customers can authenticate their Lambda Kafka consumers through their enterprise identity provider, helping them meet the security and compliance requirements for their Kafka applications.
Customers building event-driven Kafka workloads for use cases such as payment processing, fraud detection, and real-time data pipelines use Kafka ESM to build serverless Kafka consumers. Kafka ESM provides automatic scaling, error handling, batching, and event filtering. Previously, Kafka ESM supported only SASL/PLAIN, SASL/SCRAM, and mutual TLS (mTLS) as authentication methods, so customers in regulated industries that require OAuth could not use Kafka ESM with their clusters. With OAuth support, customers can use their enterprise identity provider, such as Amazon Cognito or Okta, to authenticate their Kafka ESM and apply the same identity governance and access policies across their Kafka clusters and Lambda consumers.
This capability is available in all AWS commercial Regions where self-managed Kafka ESM is available. To use OAuth authentication, create a new Kafka ESM with your authentication configuration through the AWS Management Console, Lambda API, AWS CLI, AWS CloudFormation, or AWS SAM. To learn more, see the AWS Lambda developer guide and AWS Lambda pricing.