
Redpanda is a modern, high-performance streaming platform that supports the Kafka API while using a simpler, more efficient architecture. It runs natively in C++ and eliminates JVM components like ZooKeeper, so you avoid common Kafka maintenance difficulties like memory tuning, GC delays, and coordination overhead. This simplified design reduces latency, operating burden, and increases throughput.
This article shows how to set up and configure Redpanda on Ubuntu 24.04, and make its console accessible over a web interface with HTTPS. It covers system preparation, secure configuration practices, and the use of Redpanda tooling such as bootstrap configuration and rpk profiles.
Before starting, ensure you:
redpanda.example.com, to point to your server’s public IP address.Redpanda provides a setup script that detects the operating system and configures the apt repositories automatically. Follow the steps below to update the APT package manager index and install Redpanda on your server.
Update the APT package index.
Download and execute the official Redpanda's APT setup script as root.
If the script or its hosting source is compromised, it can run arbitrary commands and fully take over the system. Only run it if you trust the source, and your network.
Install the Redpanda server binary, the Redpanda tuner, and the Redpanda Keeper (rpk) CLI tool.
Verify the installation by checking the rpk version.
By default, Redpanda services communicate on specific TCP ports. To allow external clients, administrators, and other nodes in the cluster to connect, you must explicitly let traffic through the Uncomplicated Firewall (UFW).
The table below outlines the specific ports used by Redpanda and their functions:
Follow the steps below to open the ports for each specific Redpanda component.
Open all required ports.
To generate and renew TLS certificates with Let's Encrypt, Certbot requires port 80 to be open to perform ACME HTTP-01 challenge validation. Allow port 80 through your firewall.
Allow port 443 through your firewall to access Redpanda web console over HTTPS.
Reload the firewall.
By default, Redpanda data is sent unencrypted. This poses a significant security risk in production environments, as sensitive data streams could be intercepted. To secure your cluster, you must enable TLS encryption.
Follow the steps below to install Certbot, get a certificate, and organize the files for Redpanda.
Install Certbot.
Set a shell variable for your domain name. Replace redpanda.example.com with your domain name.
Set a shell variable for your email address. Replace admin@example.com with your email address.
Request a TLS certificate for your domain using Certbot.
/etc/letsencrypt/live, which is readable only by the root user.redpanda user, you must copy the certificates to a dedicated directory with appropriate permissions.Create a directory to store Redpanda TLS certificates.
Copy the public certificate to the Redpanda certificate directory.
Copy the private key to the Redpanda certificate directory.
Copy the CA certificate to the Redpanda certificate directory.
Grant the redpanda user ownership of the certificate directory.
Set restrictive permissions on the private key so only the owner can read it.
Allow read-only access to the public certificate and CA certificate.
Let’s Encrypt certificates expire every 90 days. To avoid service outages, Certbot includes an automated renewal system using certbot.timer. You must add a deploy hook so that whenever certificates are renewed, your Redpanda TLS files are updated and the service reloads securely.
Create the renewal script.
Add the following contents to the file. Replace redpanda.example.com with your domain.
Make the renewal script executable.
Run a dry-run renewal to verify that automatic renewal and the deploy hook work correctly.
Redpanda runs in development mode by default, which disables hardware optimization and leaves the cluster open. To prepare for production, you will enable hardware tuning, then use the Bootstrap File method to initialize security settings and create the superuser before the cluster starts processing traffic.
Production mode enforces stricter resource checks. Ensure your server meets the memory and CPU requirements, otherwise, Redpanda may fail to start.
The autotuner identifies your hardware configuration and optimizes the Linux kernel (I/O schedulers, CPU settings) for performance.
Set Redpanda to production mode.
Tune the Linux kernel.
This takes about 30 seconds and dramatically increases performance. Changes to the kernel do not always persist across reboots. Enabling the redpanda-tuner service guarantees that optimizations are automatically reapplied when the node restarts.
Enable the Redpanda tuner service to persist optimizations across reboots.
Redpanda allows you to configure cluster settings before the first startup using a .bootstrap.yaml file. This is the cleanest way to set up authentication and security from the beginning.
Create the Redpanda bootstrap configuration file.
Add the following initial configuration to the file.
Save and close the file. This configuration ensures authentication and administrative access are enforced from the very first startup.
This file is only read on the first startup of Redpanda. Any later configuration changes must be done through the Admin API or rpk cluster config commands.
The bootstrap file defines who the superuser is, but it does not create the password. To create the user credentials on the first boot, define an environment variable in the Redpanda system configuration.
Add the RP_BOOTSTRAP_USER variable to the bottom of the file. Replace STRONG_PASSWORD with your actual password.
This creates a user named admin with your specified password using the SCRAM-SHA-256 authentication mechanism.
Redpanda uses a YAML configuration file located at /etc/redpanda/redpanda.yaml. By default, the service listens on the localhost interface. To allow external connections, configure the advertised addresses. Now configure the main Redpanda settings with your domain name and TLS certificates.
Back up the original configuration.
Open the configuration file.
Replace the entire configuration file with the following content. Replace redpanda.example.com with your actual domain name.
Save and close the file. This configuration defines the core Redpanda node settings:
redpanda
admin API
rpk tuning
Start the Redpanda service.
Redpanda initializes the node, applies the bootstrap configuration, creates the configured superuser, and brings the cluster online with authentication and TLS enforced.
Verify the service is active.
Run rpk as your regular sudo-capable user (not via sudo) so it can use your profile configuration.
Create a new rpk profile file to store your Redpanda credentials.
Add the following configuration to the file. Replace redpanda.example.com and STRONG_PASSWORD with your actual broker address and password.
Save and close the file.
Create and switch to the profile from the file.
Now check the cluster health. Thanks to the rpk profile, you don't need to specify credentials or TLS flags.
Output:
Now that the cluster is secured and running, perform a basic producer-consumer test to ensure it processes data accurately.
Create a test topic named test-topic.
Output should show:
Produce a message to the topic.
Output should show:
Consume the message from the topic.
The output should display the message payload and metadata in JSON format.
Redpanda Console is a modern web interface for managing and monitoring your cluster. It provides visibility into topics, messages, consumer groups, and the schema registry.
Having configured the Redpanda repository earlier, install the console package.
Configure the Redpanda Console configuration file.
Replace the existing content with the following configuration.
Save and close the file.
The redpanda-console-config.yaml file controls how the console connects to your Redpanda cluster.
Enable the Redpanda Console service to start automatically on boot.
Start the Redpanda Console service.
Since the open-source version of Redpanda Console does not include built-in login functionality, you must secure it using Nginx Basic Authentication. This setup forces users to enter a username and password before they can access the dashboard.
Install Nginx.
Install the Apache utilities package.
This package provides the htpasswd utility, which is required to generate the password file for Nginx.
Run the following command to create a user named admin. You will be prompted to enter and confirm a password.
The above command prompts you to enter and confirm the password for the admin user.
Create a new Nginx configuration file for the console.
Add the following configuration. Replace redpanda.example.com with your domain.
Save and close the file.
Enable the new site configuration.
Test the Nginx configuration for syntax errors.
Restart Nginx to apply the changes.
Open your web browser and navigate to your domain using HTTPS.
The browser prompts you to enter the username and the password you created earlier. After entering your credentials, you should see the Redpanda Console dashboard secured with a valid TLS certificate.
In this article, you installed a single-binary Redpanda cluster on Ubuntu 24.04, secured external access using TLS encryption with Let's Encrypt, configured automatic certificate renewal, and set up Redpanda Console for observability. For more information, refer to the Redpanda Documentation.
0 Comments
Be the first to comment and share your perspective with the community.