A Pulsar cluster is not intended to be exposed on the public internet. The security considerations in the current design expect network perimeter security. This requirement can be met by deploying Pulsar in private networks and restricting access to trusted clients and services.
This section guides you through every step of installing and running Apache Pulsar with Helm on Kubernetes quickly.
This quickstart guide uses default configurations suitable for development and testing only. The default Helm chart configuration does not meet production security requirements. For production deployments, you must review and customize security settings including authentication, authorization, TLS encryption, and network policies.
Run the script prepare_helm_release.sh to create the secrets required for installing the Apache Pulsar Helm chart. The username pulsar and password pulsar are used for logging into the Grafana dashboard.
note
When running the script, you can use -n to specify the Kubernetes namespace where the Pulsar Helm chart is installed, -k to define the Pulsar Helm release name, and -c to create the Kubernetes namespace. For more information about the script, run ./scripts/pulsar/prepare_helm_release.sh --help.
./scripts/pulsar/prepare_helm_release.sh \
-n pulsar \
-k pulsar-mini \
-c
Use the Pulsar Helm chart to install a Pulsar cluster to Kubernetes.
The --set overrides below pin every Pulsar component to the apachepulsar/pulsar:5.0.0-M2 image (matching this documentation version), use Oxia as the metadata store instead of ZooKeeper — the recommended option for new Pulsar clusters — and scale Oxia down to a single replica to fit the minikube footprint. You can also set these values in a values file instead of on the command line.
Step 2: Use pulsar-admin to create Pulsar tenants/namespaces/topics
pulsar-admin is the CLI (Command-Line Interface) tool for Pulsar. In this step, you can use pulsar-admin to create resources, including tenants, namespaces, and topics.
Then you can see all the partitioned topics in the namespace apache/pulsar.
"persistent://apache/pulsar/test-topic"
Step 3: Use Pulsar client to produce and consume messages
You can use the Pulsar client to create producers and consumers to produce and consume messages.
By default, the Pulsar Helm chart exposes the Pulsar cluster through a Kubernetes LoadBalancer. In Minikube, you can use the following command to check the proxy service.
kubectl get services -n pulsar |grep pulsar-mini-proxy
This output tells what are the node ports that Pulsar cluster's binary port and HTTP port are mapped to. The port after 80: is the HTTP port while the port after 6650: is the binary port.
Then you can find the IP address and exposed ports of your Minikube server by running the following command.