SIGN IN SIGN UP

Merge pull request #31411 from bartoszpiekny-redpanda/CORE-15822-audit-skip-create-topic

[CORE-15822] security/audit: make audit initialization controller-leader independent

Audit-log initialization no longer requires an elected controller leader on either sink, closing the CORE-15822 incident class (init wedged → per-shard queues fill → with audit_failure_policy=reject a cluster-wide authn outage).

RPC sink: skip CreateTopics when the audit topic already exists in the local topic table. Kafka-client sink: propagate the __auditing credential to all brokers up front via inform-all (propagation no longer rides on the create's SASL failure, which also fixes a wedge where a credential minted while peers were unreachable could never propagate), skip the controller-dependent ACL write when both bindings exist locally, skip CreateTopics likewise, and fail initialization loudly on in-band create_acls errors instead of discarding them. A missing-ACL state now surfaces as misconfigured-authorization (topic_authorization_failed) instead of silently dropping records.

Verified by ducktape on both transports: a broker restarting into a leaderless controller window initializes through the skips and an event audited during the window is consumed back from the audit topic while the controller is still leaderless; a genuinely deleted topic is recreated (the skip does not misfire); re-enable with the topic present skips creation and still delivers.
B
Bartosz Piekny committed
7166887f650b57fb9ce97a6bc4af883f5bed2f32
Committed by GitHub <noreply@github.com> on 8/14/2026, 1:16:27 PM