CCAC Cheat Sheet: Confluent Cloud Operating Boundaries

Recall resource scope, access, connectivity, offsets, monitoring, governance and recovery distinctions for Confluent Cloud operator practice.

Use this reference after studying a topic. Confirm offering-specific behavior in the official documentation for the cloud provider, region and cluster type in your scenario.

Target, identity and access

CheckBoundary to remember
Exact resourceDisplay names can repeat. Trace organization, environment, cluster and topic identifiers before a change.
Human or workloadKeep interactive administrators individually accountable; give unattended workloads suitable service identities.
AuthenticationA credential must work for its intended resource and principal. Successful login does not prove authorization.
AuthorizationEvaluate the required operation and scope. A broad role can grant more than the requested task needs.
Environment separationSeparate resource groupings do not replace permissions, network controls or dependency isolation.

Network paths

Check DNS, routing, endpoint reachability, TLS, authentication and authorization as separate layers. A reachable bootstrap endpoint alone does not establish access to every broker endpoint a client discovers.

A client’s private connection to Kafka does not establish a managed connector’s outbound connection to an external sink. Verify the supported egress mechanism for that offering and region. A network diagram should identify direction, endpoints and customer-managed dependencies, not just draw one connection labelled private.

Kafka records and progress

EvidenceWhat it establishes
Partition offsetA position inside one partition, not a global topic order.
Shared consumer groupMembers divide partition work; separate groups can read independently.
Committed offset 420The group’s next-read position is 420, not its last completed record.
Retained recordsReplay is possible within the retained range; external effects still need replay protection.
Time and size retentionEither applicable limit can make old segments eligible for cleanup. Size retention applies per partition.

An offset reset does not undo a database update or a charge. Before replaying uncertain outcomes, establish how the destination prevents or reconciles repeated effects.

Measurements and change validation

Use the correct resource ID, time window, unit and aggregation. Bytes, records and requests are different measurements. Combined egress can exceed ingress when independent groups read the stream, but it does not prove that each group is caught up.

For credential rotation, distribute the replacement, verify real workload activity on every required instance, and then retire the old credential. A process being alive is weaker evidence than successful authentication and advancing work.

Managed pipelines and schemas

  • A source connector imports records into Kafka; a sink exports them. Check both task state and destination evidence.
  • Flink statements depend on their assigned compute pool and its capacity limit. A second pool does not automatically move existing statements.
  • Subject-level compatibility can override the Schema Registry default. Registration permission and configuration permission are separate.
  • Schema compatibility does not establish unchanged business meaning or prove every application can process a new version.
  • Lineage exposes observed or declared dependencies within its coverage. Ask owners for evidence about systems outside that coverage.

Availability and recovery

A multi-zone managed cluster does not make a customer’s DNS, network path, application or database multi-zone. Test fresh connections during a failure, not just existing sessions.

TransitionEvidence to establish
Planned promotionQuiesce the source as required and validate final replication and synchronization before moving clients.
Unplanned failoverUse the authorized recovery priority, record last-known lag and acknowledge unreplicated data exposure.
FailbackPreserve divergent data before a destructive restore; replicate from the current active lineage and validate the final cutover.

Record replication and consumer-offset synchronization are distinct. Validate both alongside credentials, routes, schemas and downstream effects.

Try the free preview · Build a study plan