principal mapping rules
Broker settings that turn a certificate's distinguished name or a Kerberos principal into a short Kafka user name.
Each rule is a regular expression with a replacement, tried in order, ending with DEFAULT, which keeps the full name. A name no rule matches makes authentication fail.