Skip to content

CMAK vs Kafbat UI

Comparisons
Karel Sague·August 30, 2026·6 min read·Updated

At a glance

Kafbat UI and CMAK are scored here on the same five criteria, 50 points in all: Kafbat UI 38 out of 50, CMAK 20 out of 50. Kafbat UI takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (5 out of 10). Cost a year: This page's estimate: $8,640 in operator time. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year: This page's estimate: $11,520 in operator time.

CMAK vs Kafbat UI, compared

F1 Kpow, CMAK and Kafbat UI, side by side
Kpow CMAK Kafbat UI
How it reaches the clusterDoes it connect with ordinary Kafka client properties rather than ZooKeeper?Yes. Ordinary Kafka client properties against self-managed Kafka, Amazon MSK, Confluent Platform and Cloud, Redpanda, Aiven, NetApp Instaclustr, Google Cloud MSK and Bufstream. No. A direct connection to a ZooKeeper ensemble, which it needs to function at all. Yes. bootstrap-servers and ordinary Kafka client properties.
Kafka 4.xDoes it work against a KRaft cluster?Yes. A KRaft view for cluster information and for unregistering brokers, with KRaft metrics on the Prometheus endpoint. No. Out of reach. Kafka 4.0 operates entirely without ZooKeeper. Yes. Reachable. Nothing in the cluster configuration asks for ZooKeeper.
Newest published releaseIs the tool still being released?Yes. Version 96.4 in August 2026, after 96.3 and 96.2 in July, on a dated public changelog. No. 3.0.0.6, on 29 April 2022. The one before it was June 2020. Yes. v1.5.0, on 20 April 2026, with commits still landing in August 2026.
Access controlDoes it offer SSO and per-resource access control?Yes. LDAP, SAML, OpenID and OAuth2, with Okta, Microsoft Entra ID, Keycloak and AWS SSO named, plus role based access control at the global and the resource level. Enterprise. No. LDAP basic auth and coarse global feature flags. No per-user, per-cluster or per-topic granularity, and no SAML or OIDC. Yes. Roles scoped to topics, consumers, schemas, Connect, connectors, ksqlDB and ACLs, with OAuth, Google, GitHub, Cognito, LDAP and Active Directory.
Audit trailIs every user action recorded?Yes. Every user action on every cluster, recording who asked, what the request held and whether RBAC allowed it, readable in the UI or piped out as a webhook or a Kafka topic. Enterprise. No. None. No. Built in, written to a Kafka topic or the console. The default level records modifications and not reads.
Browsing messagesCan you search a topic's messages and read them decoded?Yes. Streaming multi-topic search with regex and built-in kJQ filters, scanning millions of messages in seconds, decoding Avro, Protobuf and JSON Schema, with results exportable. Both editions. No. No message-browsing interface. Yes. Message browsing, with custom serializer and deserializer plugins for proprietary formats.
Deployment pathDoes it ship as a maintained container image?Yes. A single stateless container, by Docker, a Kubernetes Helm chart, ECS, Fargate or a JAR, with no external database and no persistent volume. No. A source build under sbt and Scala. The community Docker image repository and the only Kubernetes Helm operator are archived and read-only. Yes. A published container and a published Helm chart, stateless unless the configuration wizard is enabled.
Licence and priceIs the software free to use at any team size?No. No. Community Edition is free at up to 3 clusters and 10 users, and Enterprise is a commercial licence starting at 4,500 US dollars per cluster per year. Yes. Free, Apache 2.0, a single self-hosted tier, with no paid edition and no support to buy. Yes. Free, Apache 2.0, with no paid tier and no seat or cluster cap. Professional services are sold separately, at no published price.

Kpow meets 7 of 8 requirements on this page.

Both projects as published in August 2026. Kpow is Factor House's product and is listed first. Its marks answer the same requirement as the other two columns.

Key takeaway

CMAK and Kafbat UI are both free, self-hosted web interfaces over a Kafka cluster, and their feature lists overlap enough that connection method is what actually separates them. CMAK’s last stable release, 3.0.0.6, dates to April 2022 and needs a direct ZooKeeper connection, so it cannot reach a KRaft cluster at all. Kafbat UI, the maintained continuation of the Provectus kafka-ui project, reached v1.5.0 in April 2026 and connects through bootstrap servers, with role-based access control, server-side masking and an audit log. Kpow by Factor House is licensed per cluster at a published price.

Kpow live demo

Test the trade-offs in a live Kafka UI

You have compared CMAK vs Kafbat UI. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.

Built for platform and data teams managing shared Kafka clusters.

Try the Kpow demo

What is CMAK?

CMAK is Cluster Manager for Apache Kafka, originally Kafka Manager, built at Yahoo and published under Apache 2.0. It is a Scala application on the Play framework, and its scope is administrative rather than data-plane. It requires a direct connection to a ZooKeeper ensemble to function at all.

  • registering and monitoring clusters from one view
  • creating and modifying topics, adding partitions, changing replication
  • preferred-replica election and partition reassignment
  • optional JMX polling at broker and topic level

The last stable release, 3.0.0.6, was tagged on 29 April 2022, and 3.0.0.5 before it in June 2020, so the silence since continues a cadence that had already stopped. The last push of any kind was 2 August 2023, and 522 issues stand open with nobody triaging them. The repository is public and it is not archived, and it carries 11,925 stars and 2,476 forks.

CMAK

What is Kafbat UI?

Kafbat UI is a free, Apache 2.0 web dashboard for observing and administering Kafka clusters, deployed as a container. It is the maintained continuation of the Provectus kafka-ui project, carried forward by contributors who were on that project from its inception. A search for Kafka UI still lands most engineers on the Provectus repository, which has cut no release since v0.7.2 in April 2024 and taken no commit since that July, and which carries 12,200 stars against the live one’s 2,642.

  • Access control: roles over cluster configuration, topics, consumer groups, schemas, Connect, connectors, ksqlDB and ACLs.
  • Identity: OAuth, Google, GitHub, Cognito, LDAP and Active Directory.
  • Masking: server-side removal, replacement or masking of fields by regular expression.
  • Extensibility: custom serializer and deserializer plugins, and a Swagger UI over the product’s own API.

The release record reads the way an active project’s does: v1.0.0 in March 2024 through to v1.5.0 on 20 April 2026, with commits still landing in August 2026. The company behind it sells professional services rather than a paid edition.

Kafbat UI

What is the official 2026 pricing of CMAK and Kafbat UI?

Both are Apache 2.0 with no paid tier, no seat cap and no cluster cap. The question worth asking is what free costs, and the two answers are not the same shape.

On CMAK, free costs a build. It is distributed as source needing an sbt and Scala toolchain, and current toolchains fight it: there is a reported OpenJDK 17 compatibility problem and dependency trouble on recent sbt and Scala. The container and Kubernetes paths are community projects rather than Yahoo’s, and both have stopped. There is no documentation site, no community channel and no commercial support of any kind. On Kafbat UI, free costs operator time plus whatever services contract gets negotiated: standing it up is a container and a configuration block, and the money is in Kafka architecture review, custom UI work, performance and scaling, security and compliance, and 24/7 support.

Where does each one run out?

Both are scored out of 50, as five criteria marked out of 10, and each criterion carries the same weight as the others. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on deployment footprint, where CMAK marks 3 and Kafbat UI marks 8. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.

The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Neither count is complete: 109 of CMAK’s 112 bundled jars resolve to a Maven coordinate and only 150 of Kafbat UI’s 266 do, so both figures are floors rather than totals and neither ranks the other. Running it yourself is common to both. What differs is whether somebody is contracted to produce the fix.

Rank 1

Kafbat UI

kafbat.io

38 out of 50 Total

Cost a year
This page's estimate: $8,640 in operator time
Newest release
v1.5.0, 20 April 2026
Audit trail
Built in, written to a Kafka topic
Cost as teams grow
10 out of 10
Deployment footprint
8 out of 10
Support and maintenance
5 out of 10
Access control and audit
6 out of 10
Multi-cluster reach
9 out of 10
Why these scores for Kafbat UI
Cost as teams grow 10 out of 10
The Licence and price row of the compare figure gives free, Apache 2.0, with no paid tier and no seat or cluster cap, and professional services sold separately at no published price. This page’s modelled cost of ownership is 8,640 US dollars a year, at 6 engineer-hours a month and 120 US dollars an hour.
Deployment footprint 8 out of 10
The Deployment path row of the compare figure gives a published container and a published Helm chart, stateless unless the configuration wizard is enabled, which then needs a mounted volume.
Support and maintenance 5 out of 10
The Newest published release row of the compare figure gives v1.5.0 on 20 April 2026 with commits still landing in August 2026, against five releases across 2025 and no support commitment of its own.
Access control and audit 6 out of 10
The Access control and Audit trail rows of the compare figure give roles scoped to topics, consumers, schemas, Connect, connectors, ksqlDB and ACLs across six identity provider types, with an audit log that defaults to modifications and not reads.
Multi-cluster reach 9 out of 10
The How it reaches the cluster row of the compare figure gives bootstrap-servers and ordinary Kafka client properties, so another cluster is another configuration entry, with no cap.

Kafbat UI’s exposure is organisational rather than technical. Release cadence is the honest concern: five releases across 2025, and one since. Commits are still landing, so the project is alive, though the release list alone would not say so. It publishes no support commitment of its own, so response times come from a services engagement.

Audit level: defaults to modifications only, so who looked at a payload is not captured until an operator raises it.

Audit topic: must not be compacted, because records carry no key, and it defaults to one partition.

Masking: protects what the Messages page displays, pattern-driven per cluster, so coverage depends on the patterns written.

Dynamic config: anything set through the configuration wizard is lost on restart without a mounted volume.

Staying patched: v1.5.0 shipped in April 2026 and nothing has shipped since. In the 157 days after it, at least 20 high or critical advisories were published against libraries that release bundles, including a critical in netty. Only 150 of its 266 bundled jars resolve to a Maven coordinate, so that is a floor rather than a total, and the state of the release itself is unmeasured. Kafbat does publish a security policy, which AKHQ and Kafdrop do not.

What it costs a year: no licence, no seat cap and no cluster cap, so the bill is operator time. This page’s estimate, not a vendor price, at 6 engineer-hours a month and 120 US dollars an hour: 8,640 US dollars a year, for the container and Helm chart, the masking patterns that cover only what somebody writes, and an audit topic that must not be compacted. Support is a services contract quoted separately, at no published price.

Rank 2

CMAK

github.com/yahoo/CMAK

20 out of 50 Total

Cost a year
This page's estimate: $11,520 in operator time
Newest release
3.0.0.6, 29 April 2022
Kafka 4.x
Out of reach, it needs ZooKeeper
Cost as teams grow
10 out of 10
Deployment footprint
3 out of 10
Support and maintenance
1 out of 10
Access control and audit
2 out of 10
Multi-cluster reach
4 out of 10
Why these scores for CMAK
Cost as teams grow 10 out of 10
The Licence and price row of the compare figure gives free, Apache 2.0, a single self-hosted tier, with no paid edition and no support to buy. This page’s modelled cost of ownership is 11,520 US dollars a year, at 8 engineer-hours a month and 120 US dollars an hour.
Deployment footprint 3 out of 10
The Deployment path row of the compare figure gives a source build under sbt and Scala, with the community Docker image repository and the only Kubernetes Helm operator archived and read-only.
Support and maintenance 1 out of 10
The Newest published release row of the compare figure gives 3.0.0.6 on 29 April 2022, the one before it June 2020, and 522 issues open with nobody triaging them.
Access control and audit 2 out of 10
The Access control and Audit trail rows of the compare figure give LDAP basic auth and coarse global feature flags, no SAML or OIDC, and no audit trail at all.
Multi-cluster reach 4 out of 10
It registers clusters from one view, but compare row Kafka 4.x puts a KRaft cluster out of reach entirely.

Partition reassignment and preferred-replica election are what CMAK is most consistently praised for, and they are exactly the operations lightweight viewers do not cover. The limits are structural.

Data plane: no message browsing, no Schema Registry integration, no Kafka Connect management and no ksqlDB.

Freshness: reads come from an internal cache rather than live broker APIs.

Access control: LDAP basic auth and coarse global feature flags, with no SAML, no OIDC and no per-topic granularity, which is what RBAC for Kafka has to mean if it means anything.

Longevity: long-running instances hang after 20 to 30 days from thread-pool exhaustion, reported in 2018 and never addressed.

Credentials also pass in plaintext unless SSL is configured by hand, which the README states and which is a hole in any Kafka security architecture. There is no audit log, enabling ZooKeeper ACLs breaks the connection outright, and managed services either lock down or no longer expose ZooKeeper endpoints.

Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.

What it costs a year: nothing to license, so the bill is operator time. This page’s estimate, not a vendor price, at 8 engineer-hours a month and 120 US dollars an hour: 11,520 US dollars a year, for the sbt and Scala build on a JDK that fights it, the restart every 20 to 30 days after thread-pool exhaustion, the two archived community deployment paths and the 522 open issues with nobody to escalate to. A Kpow licence is published at 4,500 US dollars a cluster a year with 100 users included, so the free console is the dearer of the two once anybody has to keep it alive.

Which should you pick?

Kafbat UI scores 38 against CMAK’s 20 and is the pick for almost any team choosing between them, because it connects through bootstrap servers and reaches a KRaft cluster CMAK cannot address at all. CMAK is worth keeping only for partition reassignment on ZooKeeper. Both are community projects with no support commitment, so a team that needs a vendor under contract should shortlist Kpow by Factor House.

Stay on CMAK if:

  • the cluster is on ZooKeeper and staying there
  • the tool is for a small group who already hold cluster access
  • partition reassignment and preferred-replica election are most of its use

Move to Kafbat UI if:

  • the cluster is on Kafka 4.x, or a KRaft migration is scheduled
  • anybody needs to browse messages, a schema registry, Kafka Connect or ksqlDB
  • more than a handful of people need access, and not all the same access
  • an auditor is going to ask who did what

The move itself costs less than it looks, with one exception. CMAK holds no cluster state of its own, so removing it changes nothing on the brokers and there is nothing to export, and any single sign-on in front of it is a reverse proxy that gets re-pointed. What has to be replaced is the partition-reassignment workflow, and an operator who leaned on it should work that out before the cutover rather than during one. Running both while the migration runs is fine for as long as the ensemble is there. If the shortlist is still open, the wider field of best free Kafka UI tools is worth a pass. Where the auditor’s question is the whole reason for the move, the best tools for Kafka audit logging narrow it further.

Kpow: governance with a vendor behind it

Both of these are free because nobody is under contract to keep them running. CMAK has 522 open issues and nobody triaging them, and Kafbat UI publishes no support commitment of its own, and what response time you get comes from a services contract negotiated separately, not from the licence. Kpow by Factor House is licensed per cluster at a published price, and that price buys role-based access control across topics, Connect, ksqlDB and schemas, in one stateless JVM container with no external database, from a vendor who answers for it.

Governance that nobody is on the hook for isn’t governance an auditor will accept. Kpow puts a vendor behind the number.

Kpow

How these tools were scored

Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total.

Sources

Related reading