Provision, configure, and manage Kafka clusters (Apache Kafka KRaft or ZooKeeper-backed if legacy), Confluent Platform components (Schema Registry, Kafka Connect, ksqlDB, REST Proxy, Control Center), and Confluent Cloud resources.
Ensure high availability (HA) and resilience across multi‑AZ/region deployments; manage partition replication, min.insync.replicas (ISR), and rack awareness.
Implement and maintain client quotas, broker quotas, throttling, and back‑pressure strategies.
Plan and execute upgrades/patching with zero/minimal downtime; maintain version currency against EOL and security advisories.
Own backup/restore workflows for metadata (e.g., cluster configs), Schema Registry, and Connect configs
Implement authentication (mTLS/SASL: SCRAM, OAUTHBEARER with IdP, or Kerberos if legacy) and authorization (Kafka ACLs, Confluent RBAC).
Enforce encryption in transit and at rest, secret management (Vault/AKV/SSM), secure endpoint exposure, and private connectivity (VPC peering/PrivateLink).
Govern topic naming conventions, retention policies,
schema evolution rules (backward/fully compatible), and PII handling.
Maintain audit trails (broker, Schema Registry, Control Center, Confluent Cloud audit logs) and compliance artifacts (SOX, GDPR, HIPAA/PCI as applicable).
Coordinate vulnerability management (CVE watch, hardening baselines, CIS/STIG alignment).
Deploy and maintain metrics pipelines (JMX → Prometheus/Grafana), logs (ELK/OPensearch), and tracing (OpenTelemetry where applicable).
Define and monitor SLOs/SLIs (produce/consume latency, end‑to‑end lag, broker CPU/heap/file handles, network throughput, GC pauses).
Analyze broker hotspots, partition skew, large message handling, compaction and retention settings, and tune GC/JVM for sustained throughput.
Implement consumer lag monitoring and alerting with actionable runbooks to prevent data loss or SLA breaches.
Model workload growth, topic/partition scaling, storage/IOPS, network egress/ingress, and broker sizin
📌 KafKa Admin (India)
🏢 Infosys
📍 India