Account Setup and Service Creation:
Sign Up: Create an account on the Aiven platform.
Service Creation: Use the Aiven console to create a new Kafka service. This involves selecting the cloud provider, region, and plan that fits your needs.
Configuration:
Cluster Configuration: Configure the Kafka cluster settings, including the number of nodes, storage size, and other parameters.
Networking: Set up networking options such as VPC peering or public access, depending on your security requirements.
Deployment:
Automated Deployment: Aiven automates the deployment process, provisioning the necessary infrastructure and setting up the Kafka cluster.
Monitoring and Logging: Aiven provides integrated monitoring and logging tools to keep track of the cluster's health and performance.
Integration:
Client Configuration: Configure your Kafka clients to connect to the Aiven Kafka service using the provided connection details.
Data Ingestion: Start ingesting data into Kafka topics and set up producers and consumers as needed.
Management and Scaling:
Scaling: Easily scale the Kafka cluster up or down based on your workload requirements.
Maintenance: Aiven handles routine maintenance tasks such as software updates and backups.
Implementation Timeline
The implementation timeline for Aiven for Apache Kafka can vary depending on the complexity of the setup and the specific requirements of the business. However, the platform is designed to enable rapid deployment:
Initial Setup: The initial setup, including account creation and service deployment, can typically be completed within minutes to a few hours.
Configuration and Integration: Configuring the cluster and integrating it with your existing systems may take a few days, depending on the complexity of your environment and the level of customization required.
Custom Plans:
Aiven provides the option to create custom plans tailored to specific requirements. These plans can adjust variables such as the amount of storage, frequency of backups, number of nodes, and CPU/RAM configuration per node. Custom plans start at $5000 per month.
Advanced Configuration Parameters:
Users can customize various Kafka parameters, including partition count, replication factor, retention time, and more. These configurations can be managed through the Aiven web console or the Aiven CLI.
Terraform Integration:
Aiven supports custom configurations using Terraform scripts. This allows for automated and repeatable deployments with specific settings, such as enabling Kafka REST, configuring schema registries, and setting up Kafka topics and ACLs.
Horizontal and Vertical Scaling:
Aiven allows both horizontal and vertical scaling of Kafka clusters without downtime. This flexibility ensures that the cluster can grow with the business needs, either by adding more brokers or by upgrading the capacity of existing brokers.
Service Integrations:
Aiven for Apache Kafka integrates with various other services like PostgreSQL, Elasticsearch, and Redis, providing a comprehensive data infrastructure. This integration capability is crucial for businesses with complex data architectures.
Custom Domain and IP Filtering:
Hourly Billing:
Aiven services are billed hourly, with the minimum charge unit being one hour. This includes costs for virtual machines, network, backups, and setup.
Support Tiers:
While basic support is included, Aiven offers three additional support tiers for faster response times and phone support, which come at an extra cost.
Dynamic Disk Sizing:
Adding or removing additional storage incurs extra costs, depending on the amount of storage required.
Custom Plans:
Encryption:
TLS Encryption: All data in transit is encrypted using Transport Layer Security (TLS). This ensures that data transmitted between Kafka clients and brokers is secure.
At-Rest Encryption: Data stored on disk is encrypted using LUKS with a 512-bit key. Backups are also encrypted with AES-256 in CTR mode with HMAC-SHA256 for integrity protection.
Authentication:
SASL Authentication: Aiven supports SASL/PLAIN and SASL/SCRAM for secure authentication. SASL/PLAIN uses a combination of username and password over a TLS connection, while SASL/SCRAM uses a salted challenge-response mechanism to avoid sending plain-text passwords.
OAUTH2/OIDC Authentication: OpenID Connect (OIDC) is supported for authentication, providing an additional layer of security.
Access Control:
Access Control Lists (ACLs): ACLs are used to grant specific rights for producing or consuming topics, ensuring that only authorized users can access certain data.
Network Security:
VPC Peering: When using VPC peering, no public internet access is provided to the services. This ensures that data remains within a private network.
Firewall Protection: Virtual machine network interfaces are protected by dynamically configured iptables-based firewalls, allowing only user-controlled source IP addresses to establish connections.
Periodic Security Evaluations:
Aiven services are periodically assessed and penetration tested by independent professional cybersecurity vendors to identify and mitigate any security issues.
Operator Access:
Update Frequency:
Aiven follows the upstream project's release schedule and ensures that major versions reach End of Life (EOL) one year after they are made available on the Aiven platform.
Automated Upgrade Procedure:
The upgrade procedure involves starting new Kafka nodes alongside existing ones, transferring partition data and leadership to the new nodes, and retiring the old nodes. This process ensures zero downtime as there are always active nodes in the cluster.
EOL Notifications:
Customers receive email notifications and alerts in the Aiven Console when a service version is approaching EOL. Monthly reminders are sent, increasing to weekly reminders in the month of the EOL date.
Upgrade Impact and Risks:
Data Ownership:
Customers own the data they input into Aiven services. Aiven does not access or use customer data unless specifically requested in writing by the customer for support purposes.
Data Portability:
Aiven supports data portability by allowing customers to export their data and configurations. This is facilitated through various tools and APIs provided by Aiven.
Customers can also use the Bring Your Own Cloud (BYOC) model, where they retain control over the infrastructure and data, ensuring that services can run independently of Aiven's control plane if needed.
Data Deletion:
Vertical Scaling:
Definition: Verticalscaling involvesupgrading thecapacity of existingbrokers withoutchanging theirnumber. Thisis useful whenincreasing thepartition ortopic count isnot feasibledue to applicationconstraints.
Process: Forexample, upgradingfrom a "Business-4" planto a "Business-8" planinvolves launchingnew brokers withhigher capacity, transferringdata to thesenew nodes, andretiring theold brokers oncethe data is replicated.
Horizontal Scaling:
Definition: Horizontalscaling involvesadding more brokersto the existingKafka cluster, which helpsdistribute theload and enhancesfault tolerance.
Process: Forinstance, changingfrom a 3-node "Business-8" planto a 6-node "Premium-6x-8" planinvolves addingnew brokers tothe cluster, replicating data tothem, and thenretiring theold nodes.
Dynamic Disk Sizing:
Definition: Adjusting the disk spaceallocation withoutchanging theservice plan.
Process: Userscan increaseor decrease diskspace as neededthrough the Aiven Console, upto three timesthe amount definedin their plan.
Service PlanChanges:
Contract Renewal:
Automatic Renewal: Contracts typically renew automatically unless explicitly canceled by the customer.
Notification: Customers are usually notified in advance of the renewal date, allowing them to make any necessary changes or cancellations.
Cancellation:
Process: Customers can cancel their services at any time through the Aiven Console or by contacting Aiven support.
Data Retention: Upon termination, Aiven will delete and destroy personal data processed on behalf of the customer within 90 days, unless legally required to retain it. Customers can request the return of their data, subject to additional costs.
Service Credits: If Aiven fails to meet the Service Level Objective (SLO), customers are eligible for service credits, which can be applied to future use of the Cloud Services within 90 days.
Free Trial and Credits:
Free Trial: Aiven offers trial credits of $500 for a 30-day evaluation on any Aiven services. Additional credits or time can be requested if necessary.
SOC 2 Compliance:
Aiven is SOC 2 compliant, which requires strict information security policies and procedures, including the security, availability, processing integrity, and privacy of customer data.
ISO 27001 Certification:
Aiven holds ISO 27001:2013 certification for its information security management system, ensuring that it meets international standards for information security.
PCI-DSS Compliance:
Aiven services are PCI-DSS compliant, which is crucial for handling payment card information securely.
HIPAA Compliance:
Aiven supports HIPAA compliance, making it suitable for handling healthcare-related data.
Enhanced Compliance Environments (ECE):