# Configure Kafka Queue Splitting with mirrord

Kafka splitting requires matching Kubernetes resources, client authentication, and developer message filters. This skill guides configuration generation, compatibility checks, and troubleshooting for mirrord.

## Install

```bash
npx skillstore add metalbear-co/mirrord-kafka
```

## Metadata

- Status: approved
- Slug: metalbear-co-mirrord-kafka
- Version: 2.5
- Author version: 2.5
- Skillstore revision: r1
- Version status: invalid
- Tree hash: 2310e96d2d6f454c2dd4ac3baccd964964a4a1e7b8661dedad5bf933b57a589d
- Author: metalbear-co
- GitHub username: metalbear-co
- License: MIT
- Repository: https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-kafka
- Ref: bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: confirmation\_required
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands, filesystem
- Quality score: 38
- Quality tier: warning
- Public page: https://skillstore.pages.dev/skills/metalbear-co-mirrord-kafka
- Manifest: https://skillstore.pages.dev/api/skills/metalbear-co-mirrord-kafka/manifest

## Capabilities

- Draft MirrordSplitConfig and MirrordPropertyList resources with matching workload, namespace, queue, and client references.
- Generate mirrord message filters for Kafka headers, JSON payloads, and supported raw protobuf records.
- Explain SASL, SSL, Java KeyStore, and AWS MSK IAM configuration using credential references.
- Provide Helm value guidance for Kafka splitting and the Kafka Streams sidecar.
- Check required fields, resource relationships, client compatibility, and documented version requirements.
- Guide legacy resource migration and troubleshoot group protocol errors, replication policies, and session timeouts.

## Use Cases

- Prepare a Team Kafka Connection: Generate namespace-specific connection and split resources with Secret references and the required Helm settings.
- Debug Selected Consumer Messages: Draft header or payload filters that route relevant Kafka messages to a local application.
- Diagnose Failed Splitting Sessions: Compare redacted errors and installed versions against documented protocol, replication, and rollout constraints.

## Prompt Templates

### Check Setup Requirements

```
Explain the prerequisites for mirrord Kafka splitting. Ask for versions and nonsecret workload details. Do not inspect my cluster or request credentials.
```

### Draft a Standard Consumer Setup

```
Draft Kafka splitting resources for [deployment] in [namespace], using [broker], [topic environment variable], and [group environment variable]. Reference [Secret name] without reading its values. Include Helm guidance and matching mirrord configuration; do not apply changes.
```

### Design Payload Filters

```
Design filters for [queue ID] using this redacted payload example: [sample]. Check [operator version], [CLI version], and [client backend]. Explain JSON or raw protobuf options, filter errors, and mirror versus steal behavior.
```

### Review Migration and Failure Recovery

```
Review these redacted legacy resources and logs: [inputs]. Plan migration to current resources for [versions]. Check namespace lookup, authentication references, replication policies, and rollout timeouts. Provide validation and recovery steps without reading secrets or changing the cluster.
```

## Limitations

- Kafka splitting requires a mirrord Team or Enterprise license and compatible operator and CLI versions.
- Kafka Streams requires the Java client and sidecar; jq\_filter and payload\_protobuf require librdkafka.
- Raw protobuf filtering does not support schema-registry framing, and its minimum version is not specified in these references.
- This is configuration guidance, not a runtime validator; users must review changes and correct the flagged credential-handling examples.

## Best Practices

- Confirm operator and CLI versions, namespace ownership, and Kafka client compatibility before generating resources.
- Use Secret references and owner-only credential files; avoid command-line credential values and unprotected private-key exports.
- Review generated changes and redact workload output before sharing it with an agent.

## Anti Patterns

- Pasting passwords, private keys, or unredacted workload YAML into prompts.
- Using jq\_filter with Kafka Streams or assuming protobuf schema-registry framing is supported.
- Setting group.id manually or defining both groupId and appId for one queue.

## Security Audit

- Audited at: 2026-09-29T21:41:01.952\+00:00
- Summary: Most alerts are false positives involving Markdown backticks, TLS property names, or read-only discovery. Four alerts identify credential exposure through command arguments or unencrypted key exports; unfiltered workload inspection adds a separate disclosure risk. No evidence found of malicious exfiltration or prompt injection.

## Stats

- Views: 0
- Downloads: 1
- Favorites: 0
- Popularity score: 0
