Skip to content
m manifester.io
All Kafka APIs

DescribeAcls

This page encodes the smallest legal instance of the request and the response: numeric fields are zero, strings and byte arrays are empty, every array carries exactly one sample element, and any records field holds one empty 61-byte RecordBatch v2. Version 3 is a flexible version, so every struct is terminated by a uvarint tagged-field count and strings and arrays carry compact length-plus-one prefixes. Sizes below include the leading int32 size prefix.

API key
29
Encoded at
v3
Flexible versions
2+
Headers
req v2, resp v1
Request versions
1-3
Response versions
1-3
Request size
23 bytes
Response size
28 bytes
framerpc headerrequest bodyRecordBatchRecordresponse bodytagged_fields

Request

DescribeAclsRequest v3, request header v2, 23 bytes on the wire

byte layout (23 bytes, 16 bytes per row)

0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010

object tree

DescribeAclsRequest          message v3                                [0x0000, 23B]
+-- Frame                                                              [0x0000, 4B]   length-delimited framing
|   +-- size                 int32            = 19                     [0x0000, 4B]   number of bytes that follow, patched after encoding
+-- RequestHeader            v2                                        [0x0004, 11B]  common request header
|   +-- request_api_key      int16            = 29 (DescribeAcls)      [0x0004, 2B]   numeric id of the API being invoked
|   +-- request_api_version  int16            = 3                      [0x0006, 2B]   version of the API being invoked
|   +-- correlation_id       int32            = 0                      [0x0008, 4B]   echoed back by the broker in the response
|   +-- client_id            nullable_string  = "" (int16 len=0)       [0x000c, 2B]   always a non-flexible int16-prefixed string
|   +-- tagged_fields        uvarint          = 0                      [0x000e, 1B]   number of tagged fields in the header
+-- DescribeAclsRequest      struct                                    [0x000f, 8B]   message body, version 3
    +-- ResourceTypeFilter   int8             = 0                      [0x000f, 1B]   The resource type.
    +-- ResourceNameFilter   string           = "" (compact, len+1=1)  [0x0010, 1B]   The resource name, or null to match any resource name.
    +-- PatternTypeFilter    int8             = 0                      [0x0011, 1B]   The resource pattern to match.
    +-- PrincipalFilter      string           = "" (compact, len+1=1)  [0x0012, 1B]   The principal to match, or null to match any principal.
    +-- HostFilter           string           = "" (compact, len+1=1)  [0x0013, 1B]   The host to match, or null to match any host.
    +-- Operation            int8             = 0                      [0x0014, 1B]   The operation to match.
    +-- PermissionType       int8             = 0                      [0x0015, 1B]   The permission type to match.
    +-- tagged_fields        uvarint          = 0                      [0x0016, 1B]   number of tagged fields in this struct

kafka message schema (.json)

{
  "apiKey": 29,
  "type": "request",
  "listeners": ["broker", "controller"],
  "name": "DescribeAclsRequest",
  // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline.
  // Version 1 adds resource pattern type.
  // Version 2 enables flexible versions.
  // Version 3 adds user resource type.
  "validVersions": "1-3",
  "flexibleVersions": "2+",
  "fields": [
    { "name": "ResourceTypeFilter", "type": "int8", "versions": "0+",
      "about": "The resource type." },
    { "name": "ResourceNameFilter", "type": "string", "versions": "0+", "nullableVersions": "0+",
      "about": "The resource name, or null to match any resource name." },
    { "name": "PatternTypeFilter", "type": "int8", "versions": "1+", "default": "3", "ignorable": false,
      "about": "The resource pattern to match." },
    { "name": "PrincipalFilter", "type": "string", "versions": "0+", "nullableVersions": "0+",
      "about": "The principal to match, or null to match any principal." },
    { "name": "HostFilter", "type": "string", "versions": "0+", "nullableVersions": "0+",
      "about": "The host to match, or null to match any host." },
    { "name": "Operation", "type": "int8", "versions": "0+",
      "about": "The operation to match." },
    { "name": "PermissionType", "type": "int8", "versions": "0+",
      "about": "The permission type to match." }
  ]
}

Response

DescribeAclsResponse v3, response header v1, 28 bytes on the wire

byte layout (28 bytes, 16 bytes per row)

0
1
2
3
4
5
6
7
8
9
A
B
C
D
E
F
0000
0010

object tree

DescribeAclsResponse                    message v3                                       [0x0000, 28B]
+-- Frame                                                                                [0x0000, 4B]   length-delimited framing
|   +-- size                            int32                   = 24                     [0x0000, 4B]   number of bytes that follow, patched after encoding
+-- ResponseHeader                      v1                                               [0x0004, 5B]   common response header
|   +-- correlation_id                  int32                   = 0                      [0x0004, 4B]   matches the correlation_id of the request
|   +-- tagged_fields                   uvarint                 = 0                      [0x0008, 1B]   number of tagged fields in the header
+-- DescribeAclsResponse                struct                                           [0x0009, 19B]  message body, version 3
    +-- ThrottleTimeMs                  int32                   = 0                      [0x0009, 4B]   The duration in milliseconds for which the request was throttled due to a q...
    +-- ErrorCode                       int16                   = 0                      [0x000d, 2B]   The error code, or 0 if there was no error.
    +-- ErrorMessage                    string                  = "" (compact, len+1=1)  [0x000f, 1B]   The error message, or null if there was no error.
    +-- Resources                       []DescribeAclsResource  = 1 element              [0x0010, 11B]  Each Resource that is referenced in an ACL.
    |   +-- length                      uvarint                 = 2 (compact, n+1)       [0x0010, 1B]   one sample element follows
    |   +-- DescribeAclsResource[0]     DescribeAclsResource    = struct                 [0x0011, 10B]
    |       +-- ResourceType            int8                    = 0                      [0x0011, 1B]   The resource type.
    |       +-- ResourceName            string                  = "" (compact, len+1=1)  [0x0012, 1B]   The resource name.
    |       +-- PatternType             int8                    = 0                      [0x0013, 1B]   The resource pattern type.
    |       +-- Acls                    []AclDescription        = 1 element              [0x0014, 6B]   The ACLs.
    |       |   +-- length              uvarint                 = 2 (compact, n+1)       [0x0014, 1B]   one sample element follows
    |       |   +-- AclDescription[0]   AclDescription          = struct                 [0x0015, 5B]
    |       |       +-- Principal       string                  = "" (compact, len+1=1)  [0x0015, 1B]   The ACL principal.
    |       |       +-- Host            string                  = "" (compact, len+1=1)  [0x0016, 1B]   The ACL host.
    |       |       +-- Operation       int8                    = 0                      [0x0017, 1B]   The ACL operation.
    |       |       +-- PermissionType  int8                    = 0                      [0x0018, 1B]   The ACL permission type.
    |       |       +-- tagged_fields   uvarint                 = 0                      [0x0019, 1B]   number of tagged fields in this struct
    |       +-- tagged_fields           uvarint                 = 0                      [0x001a, 1B]   number of tagged fields in this struct
    +-- tagged_fields                   uvarint                 = 0                      [0x001b, 1B]   number of tagged fields in this struct

kafka message schema (.json)

{
  "apiKey": 29,
  "type": "response",
  "name": "DescribeAclsResponse",
  // Version 0 was removed in Apache Kafka 4.0, Version 1 is the new baseline.
  // Version 1 adds PatternType.
  // Starting in version 1, on quota violation, brokers send out responses before throttling.
  // Version 2 enables flexible versions.
  // Version 3 adds user resource type.
  "validVersions": "1-3",
  "flexibleVersions": "2+",
  "fields": [
    { "name": "ThrottleTimeMs", "type": "int32", "versions": "0+",
      "about": "The duration in milliseconds for which the request was throttled due to a quota violation, or zero if the request did not violate any quota." },
    { "name": "ErrorCode", "type": "int16", "versions": "0+",
      "about": "The error code, or 0 if there was no error." },
    { "name": "ErrorMessage", "type": "string", "versions": "0+", "nullableVersions": "0+",
      "about": "The error message, or null if there was no error." },
    { "name": "Resources", "type": "[]DescribeAclsResource", "versions": "0+",
      "about": "Each Resource that is referenced in an ACL.", "fields": [
      { "name": "ResourceType", "type": "int8", "versions": "0+",
        "about": "The resource type." },
      { "name": "ResourceName", "type": "string", "versions": "0+",
        "about": "The resource name." },
      { "name": "PatternType", "type": "int8", "versions": "1+", "default": "3", "ignorable": false,
        "about": "The resource pattern type." },
      { "name": "Acls", "type": "[]AclDescription", "versions": "0+",
        "about": "The ACLs.", "fields": [
        { "name": "Principal", "type": "string", "versions": "0+",
          "about": "The ACL principal." },
        { "name": "Host", "type": "string", "versions": "0+",
          "about": "The ACL host." },
        { "name": "Operation", "type": "int8", "versions": "0+",
          "about": "The ACL operation." },
        { "name": "PermissionType", "type": "int8", "versions": "0+",
          "about": "The ACL permission type." }
      ]}
    ]}
  ]
}