At a glance
CMAK and Confluent Control Center are scored here on the same five criteria, 50 points in all: CMAK 20 out of 50, Confluent Control Center 20 out of 50. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year: This page's estimate: $11,520 in operator time. Confluent Control Center takes its best score on Access control and audit (7 out of 10) and its lowest on Cost as teams grow (2 out of 10). Cost a year: This page's estimate: $4,680 before the licence.
CMAK vs Confluent Control Center, compared
Kpow meets 6 of 7 requirements on this page. One row is not a yes or no question.
Key takeaway
CMAK requires a ZooKeeper ensemble, which Kafka 4.0 has none of, so a KRaft cutover ends it the day it completes. Control Center requires the proprietary Confluent Metrics Reporter in the broker classpath, so it cannot watch Amazon MSK, Redpanda or Aiven. Neither has a price you can compare, and they are not the same kind of product: CMAK administers and has never browsed messages, and Control Center’s Streams and ksqlDB views have no open-source equivalent. Kpow by Factor House is licensed per cluster at a published price.
Kpow live demo
Test the trade-offs in a live Kafka UI
You have compared CMAK vs Confluent Control Center. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.
Built for platform and data teams managing shared Kafka clusters.
Try the Kpow demoWhat is CMAK?
CMAK, the Cluster Manager for Apache Kafka and originally Kafka Manager, is free software built at Yahoo and released under Apache 2.0. It is written in Scala on the Play framework, and it requires a direct connection to a ZooKeeper ensemble to function at all. Its scope is Kafka cluster management rather than the data plane, which makes it a Kafka management console rather than a viewer.
- registering and monitoring clusters from one multi-cluster view
- partition reassignment and preferred-replica election
- dynamic topic configuration, partition creation and replica change
- optional JMX polling at broker and topic level
The last stable release, 3.0.0.6, was tagged on 29 April 2022. The most recent commit on master landed on 12 December 2022, and the repository has seen no push since 2 August 2023. Some 522 issues stand open with nobody triaging them. The only Kubernetes deployment path is a third-party Helm chart, archived and read-only since June 2023.

What is Confluent Control Center?
Control Center is a web management and monitoring interface bundled with Confluent Platform, Confluent’s commercial Kafka distribution. It is closed-source, licensed as part of the platform, and not available standalone. It gives one dashboard over brokers, topics, consumer groups, Kafka Connect workers, Schema Registry, ksqlDB and Kafka Streams topologies.
The prerequisite decides most evaluations: it requires the proprietary Confluent Metrics Reporter JAR in the broker classpath, and that JAR cannot be installed on Amazon MSK, on Redpanda or on Aiven. Kafka Streams topology visualisation and native ksqlDB development have no equivalent in any open-source Kafka UI, which is the capability the licence genuinely buys.
- Legacy architecture: a Kafka Streams metrics pipeline, shipped with Confluent Platform 7.x and earlier.
- Next generation: Prometheus-based, generally available with Confluent Platform 8.0 in May 2025.
- What changed: startup fell from 15 to 50 minutes to roughly one, supported scale rose from 120,000 to 400,000 replicas, and the separate metrics cluster went away.

What is the official 2026 pricing of CMAK and Confluent Control Center?
Neither of these has a price ladder to read. CMAK has no price at all, so what it costs is carry. It is distributed as source needing an sbt and Scala build, with build friction on current toolchains including an OpenJDK 17 compatibility problem. No container image is published officially. Long-running instances hang after 20 to 30 days with a RejectedExecutionException from thread-pool exhaustion, reported in 2018 and never addressed, and larger clusters with JMX polling need manual thread-pool tuning by formula.
Control Center is not sold separately, so it has no price of its own either. It is bundled with Confluent Platform under an enterprise licence that is not published, and Control Center, multi-tenancy support and encryption each carry cost above the base licence. The Platinum support tier is not available for this product. Next-generation sizing is 4 cores, 8 GB of RAM and 200 GB of storage, preferably SSD, for clusters up to 100,000 replicas, rising to 8 cores and 16 GB above that, with storage assuming 15 days of metrics retention. For fifty engineers the licence is a line item defended every year against the Kafka monitoring stack the team probably already runs in Prometheus and Grafana.
Where does each one run out?
Each tool here is marked out of 10 on five criteria, 50 points in all, and no criterion is weighted above another. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on cost as teams grow, where CMAK marks 10 and Confluent Control Center marks 2. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.
The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Kpow is self-hosted as well. What a licence buys here is not a different deployment model, it is a company under contract to ship the patched build.
CMAK
github.com/yahoo/CMAK
20 out of 50 Total
- Cost a year
- This page's estimate: $11,520 in operator time
- Newest release
- 3.0.0.6, 29 April 2022
- Needs
- A reachable ZooKeeper ensemble
- Cost as teams grow
- 10 out of 10
- Deployment footprint
- 3 out of 10
- Support and maintenance
- 1 out of 10
- Access control and audit
- 2 out of 10
- Multi-cluster reach
- 4 out of 10
Why these scores for CMAK
- Cost as teams grow 10 out of 10
- The Licence and price row of the compare figure gives Apache 2.0, free, self-hosted, with no paid tier and no commercial support. This page’s modelled cost of ownership is 11,520 US dollars a year, at 8 engineer-hours a month and 120 US dollars an hour.
- Deployment footprint 3 out of 10
- Source needing an sbt and Scala build with a reported OpenJDK 17 problem, no official image, a reachable ZooKeeper ensemble, and manual thread-pool tuning by formula on larger clusters.
- Support and maintenance 1 out of 10
- The Support row of the compare figure gives none, with 522 open issues, nobody triaging them, and no release since April 2022.
- Access control and audit 2 out of 10
- The Access control and Single sign-on rows of the compare figure give LDAP basic auth and coarse global feature flags, no SAML, no OIDC, no audit log.
- Multi-cluster reach 4 out of 10
- It registers and monitors clusters from one view, but compare row What the cluster has to be limits that to clusters with a reachable ZooKeeper ensemble.
CMAK’s ZooKeeper dependency is the whole clock. Kafka 4.0 operates entirely without ZooKeeper, so the morning a KRaft cutover completes, the admin console stops working, for the team that is mid-migration and least able to lose its instruments. The maintainer acknowledged this in 2022 and nothing has shipped since. MSK, Confluent Cloud, Aiven and Redpanda Cloud either lock down the ZooKeeper endpoint or no longer expose one.
Data plane: no message browsing, no Schema Registry integration and no Kafka Connect management.
Freshness: reads come from an internal cache, so hours of catch-up replication can show as complete in seconds.
Access control: LDAP basic auth and coarse global feature flags, with no per-user, per-cluster or per-topic granularity, and no audit log.
Transport: the LDAP integration is unencrypted unless SSL is configured by hand, which the README states.
Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.
What it costs a year: nothing to license, so the bill is operator time. This page’s estimate, not a vendor price, at 8 engineer-hours a month and 120 US dollars an hour: 11,520 US dollars a year, for the sbt and Scala build on a JDK that fights it, the restart every 20 to 30 days after thread-pool exhaustion, the two archived community deployment paths and the 522 open issues with nobody to escalate to. A Kpow licence is published at 4,500 US dollars a cluster a year with 100 users included, so the free console is the dearer of the two once anybody has to keep it alive.
Compare Kpow vs CMAKAKHQ vs CMAKCMAK vs ConduktorCMAK review
Confluent Control Center
confluent.io
20 out of 50 Total
- Cost a year
- This page's estimate: $4,680 before the licence
- Needs
- Metrics Reporter JAR in the broker classpath
- Sizing
- 4 cores, 8 GB, 200 GB to 100,000 replicas
- Cost as teams grow
- 2 out of 10
- Deployment footprint
- 2 out of 10
- Support and maintenance
- 6 out of 10
- Access control and audit
- 7 out of 10
- Multi-cluster reach
- 3 out of 10
Why these scores for Confluent Control Center
- Cost as teams grow 2 out of 10
- The Licence and price row of the compare figure gives closed-source, bundled under an enterprise licence that is not published, and Control Center, multi-tenancy and encryption each carry cost above the base licence. This page’s modelled running cost before the licence is 4,680 US dollars a year, 1,800 for the sized node and 2,880 for 2 engineer-hours a month at 120 US dollars an hour.
- Deployment footprint 2 out of 10
- The Sizing row of the compare figure gives 4 cores, 8 GB and 200 GB up to 100,000 replicas, rising to 8 cores and 16 GB above that, plus the proprietary Metrics Reporter JAR in the broker classpath.
- Support and maintenance 6 out of 10
- The Support row of the compare figure gives a vendor under contract, but no public issue tracker, no Platinum tier for this product, and legacy to next generation is a migration rather than an upgrade.
- Access control and audit 7 out of 10
- The Access control and Single sign-on rows of the compare figure give RBAC with audit logging for authentication and authorisation events capped at 10,000 rules per cluster, OIDC self-managed only, SAML on Confluent Cloud, and no masking described.
- Multi-cluster reach 3 out of 10
- The What the cluster has to be row of the compare figure has the Metrics Reporter JAR unable to be installed on Amazon MSK, Redpanda or Aiven, so its reach ends at Confluent Platform.
Control Center is scoped to one distribution, and inside that scope it is heavier than it looks. It cannot monitor Amazon MSK, Redpanda or Aiven at all, and MSK’s native IAM authentication is not supported.
Single sign-on: OIDC only on self-managed deployments. SAML is Confluent Cloud only, so a SAML-only identity provider has no supported path.
RBAC: access rules cap at 10,000 per cluster, and metrics cannot be sent without enabling full management. See RBAC for Kafka.
GitOps: changes apply directly to cluster state rather than through a Git-managed manifest.
Legacy interceptors: roughly 50 internal topics added to broker metadata, and at high consumer group counts they can overwhelm the product.
Kafka Streams can also enter a rebalancing loop on startup and leave the interface on a loading spinner for 20 to 30 minutes. Moving from legacy to next generation is a migration rather than an upgrade: historical metrics do not carry across, and the guidance is 7 to 15 days running both in parallel.
What it costs a year: the licence is bundled into Confluent Platform and is not published, so only the running cost can be priced here. This page’s estimate, not a vendor price: about 150 US dollars a month for the dedicated node the sizing guidance asks for, 4 cores, 8 GB of RAM and 200 GB of SSD, is 1,800 US dollars a year, and 2 engineer-hours a month at 120 US dollars an hour is another 2,880, so 4,680 a year before a single licence dollar, and Control Center, multi-tenancy and encryption each carry cost above the base licence.
Compare Kpow vs Confluent Control CenterConfluent Control Center vs Kafbat UIConfluent Control Center vs KafdropConfluent Control Center review
Which should you pick?
These two tie at 20 out of 50 and neither is a general answer: CMAK cannot reach a KRaft cluster at all, and Confluent Control Center needs Confluent’s proprietary reporter on every broker, so it cannot watch Amazon MSK, Redpanda or Aiven. Control Center is the pick only inside Confluent Platform. For a mixed estate with governance included, shortlist Kpow by Factor House at a published per-cluster price.
Take Control Center if:
- you are already on Confluent Platform
- Kafka Streams topology visualisation is a requirement
- ksqlDB development integration is a requirement
Keep CMAK, with a date on it, if:
- the cluster is still on ZooKeeper
- the daily work is partition reassignment and preferred-replica election
- nobody on the team needs to read a message from the interface
If you are not on Confluent Platform, this is a distribution purchase rather than a console purchase, and it should be evaluated as one. These two sit on the same lists of the best Kafka management tools, compared feature by feature, and the feature comparison is not what decides it: a team on Amazon MSK, Redpanda or Aiven can run neither, and the reassignment work CMAK does well is not covered by the viewers on any list of the best free Kafka UI tools. Where the real job is watching connectors rather than the whole platform, the best tools to monitor Kafka Connect connectors are scored on their own rubric.
Kpow: not gated by what the cluster is
Both of these decide what they can see before they see a single broker: CMAK by whether a ZooKeeper ensemble is reachable, and Control Center by whether the cluster is running Confluent Platform with the proprietary Metrics Reporter JAR already in the broker classpath. Neither answer travels: a KRaft cutover ends CMAK on the day it completes, and a cluster on Amazon MSK, Redpanda or Aiven was never eligible for Control Center at all. Kpow by Factor House connects to self-managed Kafka, MSK, Confluent Cloud, Redpanda, Aiven and Instaclustr from the same install, runs as a single stateless container with no external database, and stores its own telemetry in internal Kafka topics rather than a side system. It is licensed per cluster at a published price, so which cluster you run stops being the first question.
The cluster you actually have doesn’t have to disqualify the console you use to run it. See what Kpow reaches and settle the gating question for good.

How these tools were scored
Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total.
Sources
- KIP-833: Mark KRaft as Production Ready
- KIP-500: Replace ZooKeeper with a Self-Managed Metadata Quorum