SlideShare a Scribd company logo
Thanks for joining!
We’ll get started soon!
Technical Enablement Session
Partners Q&A
Partners Q&A
@yourtwitterhandle | developer.confluent.io
Our Partner Technical Enablement offering
Scheduled sessions On-demand
Join us for these live sessions
where our experts will guide you
through sessions of different level
and will be available to answer
your questions. Some examples of
sessions are below:
• Confluent 101: for new starters
• Hybrid Cloud Workshop:
learn by doing
• Path to Production series ,
Confluent Cloud workshops
series
• Product Updates
Learn the basics with a guided
experience, at your own pace with
our learning paths on-demand. You
will also find an always growing
repository of more advanced
presentations to dig-deeper. Some
examples are below:
• Aware/Novice/Competent
Learning paths
• Confluent Use Cases
• Positioning Confluent Value
• Confluent Cloud Networking
• … and many more
AskTheExpert
we’ll offer a channel dedicated to
streaming questions
• Build CoE inside partners by
getting people with similar
interest together
• Connect with opportunities
and discover trends at focus
partners
• Build a Technical Community
• Q&A
• Tech Talk
@yourtwitterhandle | developer.confluent.io
What are the best practices to debug client applications
(producers/consumers in general but also Kafka Streams
applications)?
@yourtwitterhandle | developer.confluent.io
March 19-20, 2024
ExCeL London
#kafkasummit
cnfl.io/KSL2024
March 19-20, 2024
ExCeL London
REGISTER NOW
Partners Q&A
@yourtwitterhandle | developer.confluent.io
On the board for today
Confluent Cloud
Networking Overview
Best Practises for Private
Networking
Networking for Kafka
Connect
Ask me anything
networking!
@yourtwitterhandle | developer.confluent.io
Confluent Cloud Networking - Options
Public Endpoints
What we lead with, the classic SaaS model.
Pros:
• Easy, Short Time to Code,
Flexible Connectivity
• Confluent + CSP runs all infra
• Consistent across CSPs
Cons:
• Might not meet all
regulatory environments, we
ask why, always and
compare to other services.
• Might not meet all
regulatory environments, we
@yourtwitterhandle | developer.confluent.io
Confluent Cloud Networking - Options
Private Link
Primary Private Networking Option
Pros:
• Very agreeable to regulatory
security posture
• Strategic private networking
option for both Confluent
and CSPs
Cons:
• Its Private, requires
additional networking;
connectivity, routing,
security, DNS…. all managed
by the customer, drives
OPEX/CAPEX
• External access challenges
• CSP specific caveats/limits
are inherited
@yourtwitterhandle | developer.confluent.io
Confluent Cloud Networking - Options
Peering
Legacy Private Networking
Pros:
• Easy starting point for Private
Networking
Cons:
• Its Private, non-Transitive &
requires additional
networking
• Confluent is part of customer
network, security concerns
• External access challenges
• CSP specific caveats/limits are
inherited
@yourtwitterhandle | developer.confluent.io
Confluent Cloud Networking - Options
Transit Gateway (AWS Only)
Large Scale Private Networking
Pros:
• Scales for regional, global and
cross CSP environments.
Cons:
• Its Private, requires additional
networking; connectivity,
routing, security…. all
managed by the customer,
drives OPEX/CAPEX
• Confluent is part of customer
network, security concerns
• External access challenges
• AWS specific
Best Practises for Private Networking
Go-to Architecture when Public Endpoints are not accepted
FW FW
Peering
Hub VNet DMZ & Landing Zone VNet
Private Link
Endpoint(s) Private Link
Services
Private Zone(s) for PL Endpoints
Confluent Azure Tenant
Customer Azure Tenant
FW FW
Peering Peerings
Hub VNet DMZ VNet
Private Link
Endpoint(s)
Private Link
Service
Private Zone(s) for PL Endpoints
Confluent Azure Tenant
Customer Azure
Tenant
Kafka
Connect
LandingZone VNet
Connect VNet
Kafka
Connect
Outbound
Private Link
For Connect
DB
Outbound
Private Link
For Connect
DB
Private Networking Best Practices - Private Link Architecture
Azure Use Case: Hub-n-Spoke
Reference Architecture
Private Networking Best Practices - Azure Hub and Spoke -Peering
Private Networking Best Practices - Azure Hub and Spoke - Private Link
FW FW
Peering Peering
Hub VNet
DMZ VNet
Confluent Azure Tenant /16
Customer Azure Tenant
Customer Azure
Tenant
UDR UDR
Public DNS (Confluent Managed)
Private Networking for Managed
Connectors
Copyright 2020, Confluent, Inc. All rights reserved. This document may not be reproduced in any manner without the express written permission of Confluent, Inc.
The plumbing, the foundational requirement.
● Internet
● Peering
● Transit Gateway
● Private Link
● OnPremise, Remote Networks, Multi-Cloud
Friction - Connectivity
Network Connectivity
DNS
Connector Configuration
Copyright 2020, Confluent, Inc. All rights reserved. This document may not be reproduced in any manner without the express written permission of Confluent, Inc.
If FQDNs are required and we can’t resolve, we are dead in the water.
● Public DNS
○ Public record can have a private or a public IP.
● Private DNS - Hosted Zone Requirement
● Confluent Cloud resolves DNS in Confluent VPC/VNet, private DNS zones not exposed as configurable
to customers.
Friction - DNS
23
Network Connectivity
DNS
Connector Configuration
Copyright 2020, Confluent, Inc. All rights reserved. This document may not be reproduced in any manner without the express written permission of Confluent, Inc.
● Connector Config Options are Limited
○ Limits the use of custom endpoints
■ For example, you supply only the bucket name and the standard public endpoint is used
● storage.googleapis.com not a custom endpoint SERVICE-ENDPOINT.p.googleapis.com
Friction - Connector Configuration
24
Network Connectivity
DNS
Connector Configuration
Enhancements in Flight - DNS Peering for TGW/Peered Clusters
Q1 - AWS/Azure Q2 - GCP
25
2
1
4
5
3
Enhancements in Flight - DNS Peering for TGW/Peered Clusters
FW FW
Peering
Hub VNet DMZ & Landing Zone VNet
Private Link
Endpoint(s) Private Link
Services
Private Zone(s) for PL Endpoints
Confluent Azure Tenant
Customer Azure Tenant
Kafka
Connect
Outbound
Private Link
For Connect
DB
Enhancements in Flight - Outbound PL for Managed Connectors
BYOC support beyond 2024.
1. Customer creates PrivateLink Service for their source/sink (like a DB).
2. Customer creates an endpoint in Confluent Cloud VPC/VNet.
3. Customer creates a DNS record in Confluent Cloud to proper resolve.
Creates a clean secure solution for Managed Connectors in PL Environments (Peeering/TGW late 2024)
Enables Private & Public outbound access for Managed Connectors

More Related Content

Similar to Q&A with Confluent Experts: Navigating Networking in Confluent Cloud (20)

PPTX
Cloud integration patterns for it pros - itprceed
Sam Vanhoutte
 
PDF
Confluent Partner Tech Talk with Reply
confluent
 
PDF
Why Cloud-Native Kafka Matters: 4 Reasons to Stop Managing it Yourself
DATAVERSITY
 
PDF
Interconnection 101
Equinix
 
PPTX
Scalable and Cost Effective interconnection of Data-Center Servers Using Dua...
Nimal Joseph
 
PPTX
Is Private Cloud Right for Your Organization?
ServiceMesh
 
PDF
3 Ways to Deliver an Elastic, Cost-Effective Cloud Architecture
confluent
 
PDF
Istio Service Mesh
Lew Tucker
 
PDF
Building Real-Time Gen AI Applications with SingleStore and Confluent
confluent
 
PPTX
Networking in the Cloud for Enterprises
Hostway|HOSTING
 
PDF
Misc: The Internet Story - How Data Travels, Transit Works, and the Role of C...
3G4G
 
PDF
Partner Connect APAC - 2022 - April
confluent
 
PDF
DIMT 2023 SG - Hands-on Workshop_ Getting started with Confluent Cloud.pdf
confluent
 
PDF
Going Cloud, Going Mobile: Will Your Network Drag You Down?
Wes Morgan
 
PDF
Bridge to Cloud: Using Apache Kafka to Migrate to AWS
confluent
 
PDF
There is NO CLOUD: Geeky Version
Open Spectrum Inc
 
PPTX
NaaS Cloud Connect - for Customer (2).pptx
MustofaDanangA
 
PDF
3 Ways to Deliver an Elastic, Cost-Effective Cloud Architecture (ANZ)
confluent
 
PPTX
Hp gavin pratt - open stack networking presentation
laurabeckcahoon
 
PDF
Industry 4.0: Building the Unified Namespace with Confluent, HiveMQ and Spark...
confluent
 
Cloud integration patterns for it pros - itprceed
Sam Vanhoutte
 
Confluent Partner Tech Talk with Reply
confluent
 
Why Cloud-Native Kafka Matters: 4 Reasons to Stop Managing it Yourself
DATAVERSITY
 
Interconnection 101
Equinix
 
Scalable and Cost Effective interconnection of Data-Center Servers Using Dua...
Nimal Joseph
 
Is Private Cloud Right for Your Organization?
ServiceMesh
 
3 Ways to Deliver an Elastic, Cost-Effective Cloud Architecture
confluent
 
Istio Service Mesh
Lew Tucker
 
Building Real-Time Gen AI Applications with SingleStore and Confluent
confluent
 
Networking in the Cloud for Enterprises
Hostway|HOSTING
 
Misc: The Internet Story - How Data Travels, Transit Works, and the Role of C...
3G4G
 
Partner Connect APAC - 2022 - April
confluent
 
DIMT 2023 SG - Hands-on Workshop_ Getting started with Confluent Cloud.pdf
confluent
 
Going Cloud, Going Mobile: Will Your Network Drag You Down?
Wes Morgan
 
Bridge to Cloud: Using Apache Kafka to Migrate to AWS
confluent
 
There is NO CLOUD: Geeky Version
Open Spectrum Inc
 
NaaS Cloud Connect - for Customer (2).pptx
MustofaDanangA
 
3 Ways to Deliver an Elastic, Cost-Effective Cloud Architecture (ANZ)
confluent
 
Hp gavin pratt - open stack networking presentation
laurabeckcahoon
 
Industry 4.0: Building the Unified Namespace with Confluent, HiveMQ and Spark...
confluent
 

More from confluent (20)

PDF
Stream Processing Handson Workshop - Flink SQL Hands-on Workshop (Korean)
confluent
 
PPTX
Webinar Think Right - Shift Left - 19-03-2025.pptx
confluent
 
PDF
Migration, backup and restore made easy using Kannika
confluent
 
PDF
Five Things You Need to Know About Data Streaming in 2025
confluent
 
PDF
Data in Motion Tour Seoul 2024 - Keynote
confluent
 
PDF
Data in Motion Tour Seoul 2024 - Roadmap Demo
confluent
 
PDF
From Stream to Screen: Real-Time Data Streaming to Web Frontends with Conflue...
confluent
 
PDF
Confluent per il settore FSI: Accelerare l'Innovazione con il Data Streaming...
confluent
 
PDF
Data in Motion Tour 2024 Riyadh, Saudi Arabia
confluent
 
PDF
Build a Real-Time Decision Support Application for Financial Market Traders w...
confluent
 
PDF
Strumenti e Strategie di Stream Governance con Confluent Platform
confluent
 
PDF
Compose Gen-AI Apps With Real-Time Data - In Minutes, Not Weeks
confluent
 
PDF
Unlocking value with event-driven architecture by Confluent
confluent
 
PDF
Il Data Streaming per un’AI real-time di nuova generazione
confluent
 
PDF
Unleashing the Future: Building a Scalable and Up-to-Date GenAI Chatbot with ...
confluent
 
PDF
Building API data products on top of your real-time data infrastructure
confluent
 
PDF
Speed Wins: From Kafka to APIs in Minutes
confluent
 
PDF
Evolving Data Governance for the Real-time Streaming and AI Era
confluent
 
PDF
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
confluent
 
PDF
Santander Stream Processing with Apache Flink
confluent
 
Stream Processing Handson Workshop - Flink SQL Hands-on Workshop (Korean)
confluent
 
Webinar Think Right - Shift Left - 19-03-2025.pptx
confluent
 
Migration, backup and restore made easy using Kannika
confluent
 
Five Things You Need to Know About Data Streaming in 2025
confluent
 
Data in Motion Tour Seoul 2024 - Keynote
confluent
 
Data in Motion Tour Seoul 2024 - Roadmap Demo
confluent
 
From Stream to Screen: Real-Time Data Streaming to Web Frontends with Conflue...
confluent
 
Confluent per il settore FSI: Accelerare l'Innovazione con il Data Streaming...
confluent
 
Data in Motion Tour 2024 Riyadh, Saudi Arabia
confluent
 
Build a Real-Time Decision Support Application for Financial Market Traders w...
confluent
 
Strumenti e Strategie di Stream Governance con Confluent Platform
confluent
 
Compose Gen-AI Apps With Real-Time Data - In Minutes, Not Weeks
confluent
 
Unlocking value with event-driven architecture by Confluent
confluent
 
Il Data Streaming per un’AI real-time di nuova generazione
confluent
 
Unleashing the Future: Building a Scalable and Up-to-Date GenAI Chatbot with ...
confluent
 
Building API data products on top of your real-time data infrastructure
confluent
 
Speed Wins: From Kafka to APIs in Minutes
confluent
 
Evolving Data Governance for the Real-time Streaming and AI Era
confluent
 
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
confluent
 
Santander Stream Processing with Apache Flink
confluent
 
Ad

Recently uploaded (20)

PPTX
A Complete Guide to Salesforce SMS Integrations Build Scalable Messaging With...
360 SMS APP
 
PDF
Executive Business Intelligence Dashboards
vandeslie24
 
PPTX
MiniTool Power Data Recovery Full Crack Latest 2025
muhammadgurbazkhan
 
PDF
Capcut Pro Crack For PC Latest Version {Fully Unlocked} 2025
hashhshs786
 
PPTX
Tally software_Introduction_Presentation
AditiBansal54083
 
PPTX
Platform for Enterprise Solution - Java EE5
abhishekoza1981
 
PDF
iTop VPN With Crack Lifetime Activation Key-CODE
utfefguu
 
PPTX
MailsDaddy Outlook OST to PST converter.pptx
abhishekdutt366
 
PDF
Beyond Binaries: Understanding Diversity and Allyship in a Global Workplace -...
Imma Valls Bernaus
 
PDF
Continouous failure - Why do we make our lives hard?
Papp Krisztián
 
PDF
GetOnCRM Speeds Up Agentforce 3 Deployment for Enterprise AI Wins.pdf
GetOnCRM Solutions
 
PPTX
Fundamentals_of_Microservices_Architecture.pptx
MuhammadUzair504018
 
PDF
MiniTool Partition Wizard 12.8 Crack License Key LATEST
hashhshs786
 
PDF
Understanding the Need for Systemic Change in Open Source Through Intersectio...
Imma Valls Bernaus
 
PDF
Mobile CMMS Solutions Empowering the Frontline Workforce
CryotosCMMSSoftware
 
PPTX
Migrating Millions of Users with Debezium, Apache Kafka, and an Acyclic Synch...
MD Sayem Ahmed
 
PDF
Streamline Contractor Lifecycle- TECH EHS Solution
TECH EHS Solution
 
PPTX
An Introduction to ZAP by Checkmarx - Official Version
Simon Bennetts
 
PPTX
How Odoo Became a Game-Changer for an IT Company in Manufacturing ERP
SatishKumar2651
 
PDF
Unlock Efficiency with Insurance Policy Administration Systems
Insurance Tech Services
 
A Complete Guide to Salesforce SMS Integrations Build Scalable Messaging With...
360 SMS APP
 
Executive Business Intelligence Dashboards
vandeslie24
 
MiniTool Power Data Recovery Full Crack Latest 2025
muhammadgurbazkhan
 
Capcut Pro Crack For PC Latest Version {Fully Unlocked} 2025
hashhshs786
 
Tally software_Introduction_Presentation
AditiBansal54083
 
Platform for Enterprise Solution - Java EE5
abhishekoza1981
 
iTop VPN With Crack Lifetime Activation Key-CODE
utfefguu
 
MailsDaddy Outlook OST to PST converter.pptx
abhishekdutt366
 
Beyond Binaries: Understanding Diversity and Allyship in a Global Workplace -...
Imma Valls Bernaus
 
Continouous failure - Why do we make our lives hard?
Papp Krisztián
 
GetOnCRM Speeds Up Agentforce 3 Deployment for Enterprise AI Wins.pdf
GetOnCRM Solutions
 
Fundamentals_of_Microservices_Architecture.pptx
MuhammadUzair504018
 
MiniTool Partition Wizard 12.8 Crack License Key LATEST
hashhshs786
 
Understanding the Need for Systemic Change in Open Source Through Intersectio...
Imma Valls Bernaus
 
Mobile CMMS Solutions Empowering the Frontline Workforce
CryotosCMMSSoftware
 
Migrating Millions of Users with Debezium, Apache Kafka, and an Acyclic Synch...
MD Sayem Ahmed
 
Streamline Contractor Lifecycle- TECH EHS Solution
TECH EHS Solution
 
An Introduction to ZAP by Checkmarx - Official Version
Simon Bennetts
 
How Odoo Became a Game-Changer for an IT Company in Manufacturing ERP
SatishKumar2651
 
Unlock Efficiency with Insurance Policy Administration Systems
Insurance Tech Services
 
Ad

Q&A with Confluent Experts: Navigating Networking in Confluent Cloud

  • 1. Thanks for joining! We’ll get started soon! Technical Enablement Session
  • 4. @yourtwitterhandle | developer.confluent.io Our Partner Technical Enablement offering Scheduled sessions On-demand Join us for these live sessions where our experts will guide you through sessions of different level and will be available to answer your questions. Some examples of sessions are below: • Confluent 101: for new starters • Hybrid Cloud Workshop: learn by doing • Path to Production series , Confluent Cloud workshops series • Product Updates Learn the basics with a guided experience, at your own pace with our learning paths on-demand. You will also find an always growing repository of more advanced presentations to dig-deeper. Some examples are below: • Aware/Novice/Competent Learning paths • Confluent Use Cases • Positioning Confluent Value • Confluent Cloud Networking • … and many more AskTheExpert we’ll offer a channel dedicated to streaming questions • Build CoE inside partners by getting people with similar interest together • Connect with opportunities and discover trends at focus partners • Build a Technical Community • Q&A • Tech Talk
  • 5. @yourtwitterhandle | developer.confluent.io What are the best practices to debug client applications (producers/consumers in general but also Kafka Streams applications)?
  • 7. March 19-20, 2024 ExCeL London #kafkasummit cnfl.io/KSL2024
  • 8. March 19-20, 2024 ExCeL London REGISTER NOW
  • 10. @yourtwitterhandle | developer.confluent.io On the board for today Confluent Cloud Networking Overview Best Practises for Private Networking Networking for Kafka Connect Ask me anything networking!
  • 11. @yourtwitterhandle | developer.confluent.io Confluent Cloud Networking - Options Public Endpoints What we lead with, the classic SaaS model. Pros: • Easy, Short Time to Code, Flexible Connectivity • Confluent + CSP runs all infra • Consistent across CSPs Cons: • Might not meet all regulatory environments, we ask why, always and compare to other services. • Might not meet all regulatory environments, we
  • 12. @yourtwitterhandle | developer.confluent.io Confluent Cloud Networking - Options Private Link Primary Private Networking Option Pros: • Very agreeable to regulatory security posture • Strategic private networking option for both Confluent and CSPs Cons: • Its Private, requires additional networking; connectivity, routing, security, DNS…. all managed by the customer, drives OPEX/CAPEX • External access challenges • CSP specific caveats/limits are inherited
  • 13. @yourtwitterhandle | developer.confluent.io Confluent Cloud Networking - Options Peering Legacy Private Networking Pros: • Easy starting point for Private Networking Cons: • Its Private, non-Transitive & requires additional networking • Confluent is part of customer network, security concerns • External access challenges • CSP specific caveats/limits are inherited
  • 14. @yourtwitterhandle | developer.confluent.io Confluent Cloud Networking - Options Transit Gateway (AWS Only) Large Scale Private Networking Pros: • Scales for regional, global and cross CSP environments. Cons: • Its Private, requires additional networking; connectivity, routing, security…. all managed by the customer, drives OPEX/CAPEX • Confluent is part of customer network, security concerns • External access challenges • AWS specific
  • 15. Best Practises for Private Networking Go-to Architecture when Public Endpoints are not accepted
  • 16. FW FW Peering Hub VNet DMZ & Landing Zone VNet Private Link Endpoint(s) Private Link Services Private Zone(s) for PL Endpoints Confluent Azure Tenant Customer Azure Tenant FW FW Peering Peerings Hub VNet DMZ VNet Private Link Endpoint(s) Private Link Service Private Zone(s) for PL Endpoints Confluent Azure Tenant Customer Azure Tenant Kafka Connect LandingZone VNet Connect VNet Kafka Connect Outbound Private Link For Connect DB Outbound Private Link For Connect DB Private Networking Best Practices - Private Link Architecture
  • 17. Azure Use Case: Hub-n-Spoke Reference Architecture
  • 18. Private Networking Best Practices - Azure Hub and Spoke -Peering
  • 19. Private Networking Best Practices - Azure Hub and Spoke - Private Link
  • 20. FW FW Peering Peering Hub VNet DMZ VNet Confluent Azure Tenant /16 Customer Azure Tenant Customer Azure Tenant UDR UDR Public DNS (Confluent Managed)
  • 21. Private Networking for Managed Connectors
  • 22. Copyright 2020, Confluent, Inc. All rights reserved. This document may not be reproduced in any manner without the express written permission of Confluent, Inc. The plumbing, the foundational requirement. ● Internet ● Peering ● Transit Gateway ● Private Link ● OnPremise, Remote Networks, Multi-Cloud Friction - Connectivity Network Connectivity DNS Connector Configuration
  • 23. Copyright 2020, Confluent, Inc. All rights reserved. This document may not be reproduced in any manner without the express written permission of Confluent, Inc. If FQDNs are required and we can’t resolve, we are dead in the water. ● Public DNS ○ Public record can have a private or a public IP. ● Private DNS - Hosted Zone Requirement ● Confluent Cloud resolves DNS in Confluent VPC/VNet, private DNS zones not exposed as configurable to customers. Friction - DNS 23 Network Connectivity DNS Connector Configuration
  • 24. Copyright 2020, Confluent, Inc. All rights reserved. This document may not be reproduced in any manner without the express written permission of Confluent, Inc. ● Connector Config Options are Limited ○ Limits the use of custom endpoints ■ For example, you supply only the bucket name and the standard public endpoint is used ● storage.googleapis.com not a custom endpoint SERVICE-ENDPOINT.p.googleapis.com Friction - Connector Configuration 24 Network Connectivity DNS Connector Configuration
  • 25. Enhancements in Flight - DNS Peering for TGW/Peered Clusters Q1 - AWS/Azure Q2 - GCP 25
  • 26. 2 1 4 5 3 Enhancements in Flight - DNS Peering for TGW/Peered Clusters
  • 27. FW FW Peering Hub VNet DMZ & Landing Zone VNet Private Link Endpoint(s) Private Link Services Private Zone(s) for PL Endpoints Confluent Azure Tenant Customer Azure Tenant Kafka Connect Outbound Private Link For Connect DB Enhancements in Flight - Outbound PL for Managed Connectors BYOC support beyond 2024. 1. Customer creates PrivateLink Service for their source/sink (like a DB). 2. Customer creates an endpoint in Confluent Cloud VPC/VNet. 3. Customer creates a DNS record in Confluent Cloud to proper resolve. Creates a clean secure solution for Managed Connectors in PL Environments (Peeering/TGW late 2024) Enables Private & Public outbound access for Managed Connectors