For a long time, one thing has been common to every Strimzi-based Apache Kafka cluster. It uses TLS encryption and mTLS authentication for all internal cluster communication. Data replication between brokers, KRaft controller communication, Strimzi operators talking with Kafka … all of this always uses TLS encryption and mTLS authentication.