Skip to content

CMAK vs Conduktor

Comparisons
Karel Sague·August 30, 2026·6 min read·Updated

At a glance

CMAK and Conduktor are scored here on the same five criteria, 50 points in all: CMAK 20 out of 50, Conduktor 36 out of 50. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year, modelled: $0 licence plus about $11,520 operator time (8 hours a month at $120). Conduktor takes its best score on Access control and audit (10 out of 10) and its lowest on Deployment footprint (3 out of 10). Cost a year, modelled: $12,000 for 10 Team seats plus about $2,880 operator time (2 hours a month at $120). Conduktor holds the highest total on this page at 36 out of 50.

CMAK vs Conduktor, compared

F1 Kpow, CMAK and Conduktor, side by side
Kpow CMAK Conduktor
Adding an engineerDoes the bill stay flat when somebody joins?Yes. No change up to the 100 users included with each cluster, because the licence counts clusters and not seats. Yes. No change to the bill. No. Another seat, once the team is past Community or needs a policy feature.
Newest published releaseIs the tool still being released?Yes. Version 96.4 in August 2026, after 96.3 and 96.2 in July, on a dated public changelog. No. 3.0.0.6, tagged 29 April 2022. Last commit December 2022. Yes. Shipping continuously. SOC2 Type II certified since 2023.
Kafka 4.0Does it work against a KRaft cluster?Yes. A KRaft view for cluster information and for unregistering brokers, with KRaft metrics on the Prometheus endpoint. No. Cannot connect. It requires a direct ZooKeeper connection, and Kafka 4.0 runs KRaft only. Yes. Connects over the Kafka protocol, so a KRaft cutover changes nothing for it.
What it needs to runDoes it run without an external datastore?Yes. None. A single stateless container configured through environment variables, with no external database, no proxy layer and no persistent volume. No. A reachable ZooKeeper ensemble, and a Scala build produced in-house. No. PostgreSQL 13 or later for Console, and it is not optional. Gateway, where deployed, is a second service in the data path.
GovernanceIs the audit trail readable in the product?Yes. Role based access control and masking policies are set in the product, and the audit log is readable in the UI as well as piped to a webhook or a Kafka topic. Enterprise. No. LDAP basic auth and global feature flags. No per-topic permissions and no audit log. Yes. Group-level RBAC, topic policies, and an audit log covering more than 70 event types, from Team Edition.
SupportIs there a support channel under contract?Yes. Email support and an Enterprise support SLA, with priority support on Enterprise, and a community Slack channel and GitHub issues on both editions. No. None. 522 issues are open with nobody triaging them. Yes. A vendor under contract, with support by edition.
Pricing unitA unit of sale, not a pass or a fail.Not a yes or no. Per cluster. Enterprise starts at 4,500 US dollars per cluster per year with 100 users included, and Community Edition is free. Not a yes or no. Free under Apache 2.0. No paid tier, no hosted offering and nothing to buy. Not a yes or no. Per seat. Team Edition is 1,200 US dollars per seat per year, or 125 US dollars per seat per month billed monthly.
Free tierDoes the free tier reach a fifty-person team?No. Community Edition, free with no time limit, covers 3 clusters and 10 users. RBAC, data masking, SSO and the audit log start on Enterprise. Yes. Everything it does, because there is no edition above it. Yes. Console Community, up to 50 users and 3 clusters, with SSO by OIDC or LDAP included.

Kpow meets 6 of 7 requirements on this page. One row is not a yes or no question.

Both ladders as published in August 2026. Kpow is Factor House's product and is listed first. Its marks answer the same requirement as the other two columns.

Key takeaway

CMAK requires a direct ZooKeeper connection, and Kafka 4.0 runs KRaft only, so a KRaft cutover ends it the day it lands. Its last release is 3.0.0.6 from April 2022, with 522 open issues nobody is working through. Conduktor Console Community is free for up to 50 users and 3 clusters, Team Edition is 1,200 US dollars per seat per year, and Console requires PostgreSQL 13 or later. Kpow by Factor House is licensed per cluster at a published price.

Kpow live demo

Test the trade-offs in a live Kafka UI

You have compared CMAK vs Conduktor. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.

Built for platform and data teams managing shared Kafka clusters.

Try the Kpow demo

What is CMAK?

CMAK is Cluster Manager for Apache Kafka, originally Kafka Manager, built at Yahoo and released under Apache 2.0. It is written in Scala on the Play framework, and its scope is administrative rather than data-plane. There is no commercial distribution, no hosted offering and no paid support tier. The repository is public and not archived, and it carries 11,925 stars and 2,476 forks.

  • registering and monitoring clusters from a single multi-cluster view
  • partition reassignment and preferred-replica election
  • dynamic topic configuration, partition creation and replica change
  • optional JMX polling at broker and topic level

It requires a direct connection to a ZooKeeper ensemble to function at all. The last stable release, 3.0.0.6, was tagged 29 April 2022, and the last commit on master is December 2022.

CMAK

What is Conduktor?

Conduktor is a commercial Kafka management and governance platform, sold as separately licensed products. Console is a React web interface over topics, schemas, connectors, consumer groups and access control across clusters. Gateway is a proxy between clients and brokers that enforces encryption, data masking, quota policy and multi-tenancy at the wire level, so producers and consumers need no change to their code. A Schema Registry Proxy is licensed separately again. The company retired its JavaFX desktop product at the end of 2025.

Gateway is what makes this a different category of product rather than a newer CMAK, and it is also what changes the risk. CMAK touches cluster metadata and never sits in the data path. Gateway does sit in it, which is what allows field-level encryption without touching a client, server-side virtual topic filtering, and a backend cluster failover applications never notice. Conduktor has been SOC2 Type II certified since 2023.

Conduktor

What is the official 2026 pricing of CMAK and Conduktor?

CMAK costs nothing to license and there is no tier above it. The whole cost is operator time: somebody builds it from Scala source, keeps a ZooKeeper ensemble reachable for it, and answers for it when it stops. There is no SLA to escalate to, because 522 issues stand open with no maintainer triaging them.

Conduktor sells six tiers across three products and publishes a price for exactly one of the paid ones. Console Community is the free entry point, capped by user and cluster count, carrying SSO by OIDC or LDAP, full Kafka operations, the advanced data explorer, and API and CLI access. Gateway Community is free as well, restricted to network connectivity. Console Team Edition is the published price, and it is where group-level RBAC, topic policies, unlimited audit logs, unlimited clusters and data masking begin. Console Enterprise, Gateway Enterprise and the Schema Registry Proxy are contact-only, and Gateway Enterprise is licensed per cluster with a three-cluster minimum.

Read the unit rather than the amount. Five engineers sharing a Kafka management console sit inside Community and pay nothing. Opening the same tool to fifty crosses into a per-seat line that grows every time somebody new needs a topic browser, and Gateway is a second purchase priced on a different axis again.

Where does each one run out?

Both tools are marked out of 10 on the same five criteria, for a total out of 50, and every criterion counts once. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on support and maintenance, where CMAK marks 1 and Conduktor marks 9. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.

The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Running it yourself is common to both. What differs is whether somebody is contracted to produce the fix.

CMAK cannot connect to a Kafka 4.0 cluster at all. It needs a direct ZooKeeper connection and Kafka 4.0 runs KRaft only. The maintainer acknowledged this in 2022, said ZooKeeper would be phased out but that the replacement metadata store was still to be designed, and nothing has shipped since. MSK, Confluent Cloud, Aiven and Redpanda Cloud either lock down or no longer expose ZooKeeper endpoints, so most managed Kafka is out on the same rule.

Enabling ZooKeeper ACLs breaks the connection entirely, and the one Kubernetes path, a third-party Helm chart, is archived and read-only. Both are limits on any Kafka security architecture that has to be evidenced.

Conduktor’s costs are architectural rather than functional. Console requires PostgreSQL 13 or later and it is not optional, so a monitoring stack acquires a database with its own backups and upgrade path.

Console also falls back to querying the cluster directly when its index is stale, which shows up as slow page loads, and there is no native distributed tracing, so it sits alongside the best Kafka monitoring tools rather than replacing them. Governance is priced rather than absent: group-level RBAC for Kafka, topic policies, masking and unlimited audit logs all begin at Team Edition.

Rank 1

CMAK

github.com/yahoo/CMAK

20 out of 50 Total

Cost a year, modelled
$0 licence plus about $11,520 operator time (8 hours a month at $120)
Newest published release
3.0.0.6, tagged 29 April 2022
Kafka 4.0
Cannot connect, it needs ZooKeeper
Cost as teams grow
10 out of 10
Deployment footprint
3 out of 10
Support and maintenance
1 out of 10
Access control and audit
2 out of 10
Multi-cluster reach
4 out of 10
Why these scores for CMAK
Cost as teams grow 10 out of 10
This page’s table gives the pricing unit as “Free under Apache 2.0. No paid tier, no hosted offering and nothing to buy”. This page’s estimate of the annual total: $0 licence plus about $11,520 of operator time, at 8 engineer-hours a month at $120 an engineer hour, for a Scala build produced in-house against a ZooKeeper ensemble kept alive for it. The 10 scores the slope, not the level.
Deployment footprint 3 out of 10
This page’s table gives What it needs to run as “A reachable ZooKeeper ensemble, and a Scala build produced in-house”, and the page records that the one Kubernetes path, a third-party Helm chart, is archived and read-only.
Support and maintenance 1 out of 10
This page’s table gives the newest published release as “3.0.0.6, tagged 29 April 2022. Last commit December 2022”, and support as “None. 522 issues are open with nobody triaging them”.
Access control and audit 2 out of 10
This page’s table gives Governance as “LDAP basic auth and global feature flags. No per-topic permissions and no audit log”, and the page adds that credentials pass in plaintext unless SSL is configured by hand.
Multi-cluster reach 4 out of 10
This page gives registering and monitoring clusters from a single multi-cluster view, but it needs a direct ZooKeeper connection, which MSK, Confluent Cloud, Aiven and Redpanda Cloud no longer expose.

Data plane: no message browsing, no Schema Registry integration and no Kafka Connect management.

Access control: LDAP basic auth and coarse global feature flags, with no per-user or per-topic granularity and no audit log.

Transport: credentials pass in plaintext unless SSL is configured by hand, which the README states.

Freshness: reads come from an internal cache rather than live broker APIs, so a reassignment may not appear immediately.

Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.

Rank 2

Conduktor

conduktor.io

36 out of 50 Total

Cost a year, modelled
$12,000 for 10 Team seats plus about $2,880 operator time (2 hours a month at $120)
Free tier
Community: 50 users, 3 clusters
What it needs to run
PostgreSQL 13 or later, not optional
Cost as teams grow
5 out of 10
Deployment footprint
3 out of 10
Support and maintenance
9 out of 10
Access control and audit
10 out of 10
Multi-cluster reach
9 out of 10
Why these scores for Conduktor
Cost as teams grow 5 out of 10
This page’s table gives the pricing unit as “Team Edition is 1,200 US dollars per seat per year, or 125 US dollars per seat per month billed monthly”, with Community free to 50 users and 3 clusters. This page’s estimate of the annual total for ten Team seats: about $14,880, the $12,000 of seats plus 2 engineer-hours a month at $120 an engineer hour for Console and its PostgreSQL.
Deployment footprint 3 out of 10
This page’s table gives what it needs to run as “PostgreSQL 13 or later for Console, and it is not optional”, plus 2 CPU and 3 GB of RAM for Console and 2 CPU and 4 GB for Gateway.
Support and maintenance 9 out of 10
This page’s table gives the newest published release as “Shipping continuously. SOC2 Type II certified since 2023”, and support as “A vendor under contract, with support by edition”.
Access control and audit 10 out of 10
This page’s table gives Governance as “Group-level RBAC, topic policies, and an audit log covering more than 70 event types, from Team Edition”, and the page has masking and unlimited audit logs beginning at Team Edition.
Multi-cluster reach 9 out of 10
This page has Community already carrying 3 clusters, and unlimited clusters begin at Console Team Edition.

Resources: 2 CPU and 3 GB of RAM for Console, plus 2 CPU and 4 GB for Gateway.

Latency: Gateway is a proxy in the data path that can slightly increase end-to-end latency, and it is a single point of failure needing its own high-availability plan.

Azure: Event Hubs is reachable over Kafka protocol compatibility, but Azure’s native Schema Registry is not integrated.

Directory: Active Directory needs a specific LDAP search filter, or the default configuration returns an invalid user error.

Which should you pick?

Conduktor scores far higher here, 36 against 20, and is the pick for any cluster heading to KRaft, because CMAK needs a ZooKeeper connection Kafka 4.0 does not provide and has shipped nothing since April 2022. Conduktor bills 1,200 US dollars per seat a year and needs PostgreSQL 13 behind it. Where the bill should track clusters rather than headcount, shortlist Kpow by Factor House.

Keep CMAK if:

  • the cluster is still on ZooKeeper with no migration scheduled
  • the people using it already hold cluster credentials
  • the daily work is partition reassignment and preferred-replica election

Take Conduktor if:

  • a regulator or a customer contract makes the audit trail non-negotiable
  • encryption or masking has to be enforced below the application rather than in a UI
  • handing topic creation to product teams inside policy guardrails is the actual project

CMAK’s case closes on the day the cluster moves to KRaft, and a look at the best Kafka management tools is better done before that day than after. Conduktor’s seat price buys a vendor under contract and a certification an auditor will accept, and on those three requirements no free Kafka UI substitutes for one.

Kpow: on KRaft, and out of the data path

CMAK cannot connect to a Kafka 4.0 cluster at all, since it needs a direct ZooKeeper connection and KRaft is the only mode left, and Conduktor’s Gateway, where deployed, sits in the data path itself, which can slightly increase end-to-end latency, and becomes a single point of failure that needs its own high-availability plan. Neither gives a team governance that’s both current with KRaft and outside the data path it’s watching. Kpow by Factor House is licensed per cluster at a published price, runs against a KRaft cluster you already operate, needs no external database, and never sits in the data path. A new engineer is not a new invoice line.

The bill shouldn’t be attached to the seat count or the latency budget. Point Kpow at your own KRaft cluster and see what neither of these gives you.

Kpow

How these tools were scored

Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total. Conduktor is listed last whatever its total; on its total of 36 it would place first.

Sources

Related reading