Confluent CSFLE metadata backup
OSO Kafka Backup Enterprise backs up metadata from Confluent's Client-Side Field-Level Encryption (CSFLE) system. It captures Key Encryption Keys (KEKs), Data Encryption Keys (DEKs), encrypted subjects, and the Schema Registry rules that describe which fields are encrypted.
This feature preserves existing Confluent CSFLE metadata. It does not encrypt Kafka backup segment files, and it does not add encryption to plaintext Kafka records. Confluent CSFLE encrypts fields in the producer or serializer before the records reach Kafka; Kafka Backup Enterprise preserves the metadata needed to understand and recover that setup.
The open source CLI does not provide backup encryption. The Strimzi Backup
Operator does not support spec.backup.encryption.
What gets backed up
| Item | Captured data |
|---|---|
| KEK Registry | KEK names, KMS type, KMS key identifier, properties, and status |
| DEK Registry | Subject, version, algorithm, and encrypted key material for each DEK |
| Encrypted subjects | Subjects with Confluent ENCRYPT rules, their KEK, algorithm, and encrypted-field count |
| Schema encryption rules | Raw Schema Registry versions containing encryption rules and metadata tags |
| Encryption manifest | Counts, KMS types, backup timestamp, and per-subject summaries |
The feature copies encrypted DEK material and KMS references. It does not export KMS master keys or other plaintext key material.