Skip to content

CMAK vs Kafdrop

Comparisons
Karel Sague·August 30, 2026·6 min read·Updated

At a glance

Kafdrop and CMAK are scored here on the same five criteria, 50 points in all: Kafdrop 23 out of 50, CMAK 20 out of 50. Kafdrop takes its best score on Cost as teams grow (10 out of 10) and its lowest on Access control and audit (0 out of 10). Cost a year: This page's estimate: $11,520 in operator time. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year: This page's estimate: $11,520 in operator time.

CMAK vs Kafdrop, compared

F1 Kpow, CMAK and Kafdrop, side by side
Kpow CMAK Kafdrop
Newest published releaseIs the tool still being released?Yes. Version 96.4 in August 2026, after 96.3 and 96.2 in July, on a dated public changelog. No. 3.0.0.6 of April 2022, with 3.0.0.5 of June 2020 before it. Last commit December 2022, last push August 2023. No. 4.2.0 of July 2025, with 4.1.0 in December 2024. Commits landed through August 2026, so recent feature work is in no published image.
Kafka without ZooKeeperDoes it work against a KRaft cluster?Yes. A KRaft view for cluster information and for unregistering brokers, with KRaft metrics on the Prometheus endpoint. No. It requires a direct ZooKeeper connection, and Kafka 4.0 has no ensemble, so it cannot address such a cluster. No. No ZooKeeper connection since 3.10.0, and all cluster information comes through the Kafka admin API. Three reports of the topic view failing against a KRaft cluster were closed as not planned.
ScopeCan you both browse messages and administer the cluster?Yes. Both. Streaming multi-topic search decoding Avro, Protobuf and JSON Schema, alongside topic creation and configuration, broker configuration, ACL management and offset management. No. Cluster administration: partition reassignment, preferred-replica election, topic configuration and replica change. No message-browsing UI. No. Message inspection: browsing in JSON, plain text, Avro and Protobuf, consumer group lag, topic creation and ACL viewing. No partition reassignment.
Clusters per deploymentCan one deployment manage more than one cluster?Yes. Up to 12 per instance, each with its own connection, Kafka Connect, schema registry and ksqlDB. Community Edition covers 3, and Enterprise sets no licensed cap. Yes. Many, registered and monitored from a single view. No. One. There is no multi-cluster management.
AuthenticationIs authentication part of the product?Yes. LDAP, SAML, OpenID and OAuth2, with Okta, Microsoft Entra ID, Keycloak and AWS SSO named, plus role based access control at the global and the resource level. Enterprise. Yes. LDAP basic auth and coarse global feature flags. No SAML, no OIDC, no per-topic granularity and no audit log. No. None in the product. The README documents an NGINX basic-auth workaround.
DeploymentDoes it ship as a maintained container image?Yes. A single stateless container, by Docker, a Kubernetes Helm chart, ECS, Fargate or a JAR, with no external database and no persistent volume. No. Source, with an sbt and Scala build. The community Docker image repository and the Kubernetes operator chart are archived and read-only. Yes. A public Docker image on Java 17 or newer, serving on port 9000, with a Helm chart in the repository.
SupportIs there a support channel under contract?Yes. Email support and an Enterprise support SLA, with priority support on Enterprise, and a community Slack channel and GitHub issues on both editions. No. None. 522 issues open with no maintainer triaging them, and no documentation site or community channel. No. GitHub issues, on a tracker with 46 issues open.
Reported scale limitA known ceiling, not a pass or a fail.Not a yes or no. Up to 12 clusters per instance, a published ceiling rather than a performance failure. Past 12 you run a second instance. Not a yes or no. Reads come from an internal cache rather than live broker APIs. Long-running instances have hung after 20 to 30 days from thread-pool exhaustion. Not a yes or no. About 5,566 consumer groups took over 30 minutes to load, and the same view returned in under a minute with that step disabled.
Licence and priceIs the software free to use at any team size?No. No. Community Edition is free at up to 3 clusters and 10 users, and Enterprise is a commercial licence starting at 4,500 US dollars per cluster per year. Yes. Free, Apache 2.0, a single self-hosted tier. No paid tier, no hosted offering and no support to buy. Yes. Free, Apache 2.0, a single tier, with no commercial offering of any kind.

Kpow meets 7 of 8 requirements on this page. One row is not a yes or no question.

Both projects as published in August 2026. Kpow is Factor House's product and is listed first. Its marks answer the same requirement as the other two columns.

Key takeaway

CMAK and Kafdrop are not substitutes: CMAK is an administration console with no message browsing, and Kafdrop is a message viewer with no partition reassignment. Both are free, self-hosted Apache 2.0 web interfaces over a Kafka cluster somebody else runs, and neither has anybody under contract. CMAK requires a ZooKeeper ensemble, which Apache Kafka 4.0 removed, so it cannot address such a cluster. Kafdrop has needed none since 3.10.0, but three reports of its topic view failing under KRaft were closed as not planned. Kpow by Factor House is licensed per cluster at a published price.

Kpow live demo

Test the trade-offs in a live Kafka UI

You have compared CMAK vs Kafdrop. Open a live Kpow environment to test the everyday workflows a shared Kafka platform needs.

Built for platform and data teams managing shared Kafka clusters.

Try the Kpow demo

What is CMAK?

CMAK is Cluster Manager for Apache Kafka, originally Kafka Manager, built at Yahoo and released under Apache 2.0. It runs on Scala and the Play framework, and its scope is administrative rather than data-plane.

  • registering and monitoring several clusters from one view
  • creating and modifying topics, and managing partitions
  • preferred-replica election and partition reassignment
  • optional JMX polling at broker and topic level

The newest tagged release is 3.0.0.6 of April 2022, and 3.0.0.5 of June 2020 before it, so the cadence had already slowed before it stopped. The last commit on master is December 2022 and the last push of any kind is August 2023. 522 issues stand open. The repository is not archived, and it carries 11,925 stars, which is why it keeps appearing on shortlists.

CMAK

What is Kafdrop?

Kafdrop is an open-source Kafka web UI on Spring Boot, Apache 2.0, maintained by the Obsidian Dynamics team. It runs as a stateless Java process against standard broker protocols with no separate backend datastore, which keeps setup to a single container. Requirements are Java 17 or newer and Kafka 0.11.0 or newer, the UI serves on port 9000, and TLS and SASL to brokers are documented.

  • view brokers and topics
  • browse messages in JSON, plain text, Avro and Protobuf
  • view consumer groups with combined and per-partition lag
  • create topics, view ACLs, and reach Azure Event Hubs

The repository carries 6,154 stars, is not archived, and has 46 issues open, with commits landing through August 2026 including a Spring Boot 4.1 upgrade and Java 25 in December 2025. The newest tagged release is 4.2.0 of July 2025, so the 2026 feature work sits in no published image.

Kafdrop

What is the official 2026 pricing of CMAK and Kafdrop?

Neither of these has a price, so the whole cost is operator time. There is no SLA on either, because there is nobody under contract on either. The difference is that one of them has a tracker somebody still reads.

For a team of five, Kafdrop is genuinely cheap: one container, minimal overhead, and five engineers who all hold cluster credentials anyway. CMAK at five people costs an sbt and Scala build on a current JDK, or a community Docker image whose repository is now archived and read-only, before anybody sees a topic. At fifty they separate for different reasons. Kafdrop has no authentication to give fifty people, and that is settled rather than pending: the request was opened in January 2026 and closed as not planned in February. CMAK has LDAP basic authentication and coarse global feature flags, which is authentication without authorisation. Both end at a reverse proxy that secures the front door and changes nothing inside it.

Where does each one run out?

Both tools are marked out of 10 on the same five criteria, for a total out of 50, and every criterion counts once. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on deployment footprint, where CMAK marks 3 and Kafdrop marks 10. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.

The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Neither count is complete: 109 of CMAK’s 112 bundled jars resolve to a Maven coordinate and only 66 of Kafdrop’s 118 do, so both figures are floors rather than totals and neither ranks the other. Kpow is self-hosted as well. What a licence buys here is not a different deployment model, it is a company under contract to ship the patched build.

Rank 1

Kafdrop

github.com/obsidiandynamics/kafdrop

23 out of 50 Total

Cost a year
This page's estimate: $11,520 in operator time
Newest release
4.2.0, July 2025
Scope
Message inspection, no partition reassignment
Cost as teams grow
10 out of 10
Deployment footprint
10 out of 10
Support and maintenance
2 out of 10
Access control and audit
0 out of 10
Multi-cluster reach
1 out of 10
Why these scores for Kafdrop
Cost as teams grow 10 out of 10
The Licence and price row of the compare figure gives free, Apache 2.0, a single tier, with no commercial offering of any kind. This page’s modelled cost of ownership is 11,520 US dollars a year, at 8 engineer-hours a month and 120 US dollars an hour.
Deployment footprint 10 out of 10
The Deployment row of the compare figure gives a public Docker image on Java 17 or newer serving on port 9000, with a Helm chart in the repository and no separate backend datastore.
Support and maintenance 2 out of 10
The Newest published release row of the compare figure gives 4.2.0 of July 2025, with GitHub issues the only channel and three KRaft failure reports closed as not planned.
Access control and audit 0 out of 10
The Authentication row of the compare figure gives none in the product, an NGINX basic-auth workaround in the README, and write operations left exposed.
Multi-cluster reach 1 out of 10
The Clusters per deployment row of the compare figure gives one, with no multi-cluster management.

Kafdrop has needed no ZooKeeper connection since 3.10.0 and takes all cluster information through the Kafka admin API, but KRaft is still where it runs out. KRaft has been available since Kafka 3.3 and mandatory from Kafka 4.0, and three reports of the topic view failing against a KRaft cluster were closed as not planned, two of them in 2025.

Authentication: none in the product. The README documents an NGINX basic-auth workaround.

Write operations: exposed, so an unprotected instance makes accidental topic deletion possible. The read-only toggle has sat in a pull request since November 2020.

Reach: one cluster per deployment, no message search by key or value, and message format set per topic by hand.

Scale: 5,566 consumer groups took over 30 minutes to load, and the same view returned in under a minute with that step disabled.

Staying patched: 4.3.0 shipped on 31 August 2026 bundling Tomcat 11.0.22, which had carried three critical advisories since 25 August, six days earlier. One of them, CVE-2026-65905, scores 9.8 and is an authentication bypass, and all three are still in the current release. Three releases have shipped in two years. Only 66 of its 118 bundled jars resolve to a Maven coordinate, so those counts are floors rather than totals.

What it costs a year: no licence at any size, so the bill is operator time and exposure. This page’s estimate, not a vendor price, at 8 engineer-hours a month and 120 US dollars an hour: 11,520 US dollars a year, which buys the container, the NGINX basic-auth workaround standing in front of it, one deployment for every cluster, and no audit trail to hand a reviewer.

Rank 2

CMAK

github.com/yahoo/CMAK

20 out of 50 Total

Cost a year
This page's estimate: $11,520 in operator time
Newest release
3.0.0.6, April 2022
Scope
Cluster administration, no message browsing
Cost as teams grow
10 out of 10
Deployment footprint
3 out of 10
Support and maintenance
1 out of 10
Access control and audit
2 out of 10
Multi-cluster reach
4 out of 10
Why these scores for CMAK
Cost as teams grow 10 out of 10
The Licence and price row of the compare figure gives free, Apache 2.0, a single self-hosted tier, with no paid tier, no hosted offering and no support to buy. This page’s modelled cost of ownership is 11,520 US dollars a year, at 8 engineer-hours a month and 120 US dollars an hour.
Deployment footprint 3 out of 10
The Deployment row of the compare figure gives source with an sbt and Scala build, and both community paths, the Docker image repository and the Kubernetes operator chart, archived and read-only.
Support and maintenance 1 out of 10
The Support row of the compare figure gives none, with 522 issues open and no maintainer triaging them, and no documentation site or community channel.
Access control and audit 2 out of 10
The Authentication row of the compare figure gives LDAP basic auth and coarse global feature flags, with no SAML, no OIDC, no per-topic granularity and no audit log.
Multi-cluster reach 4 out of 10
The Clusters per deployment row of the compare figure gives many, registered and monitored from a single view, but only clusters that still run a ZooKeeper ensemble.

CMAK requires a direct connection to a ZooKeeper ensemble, and that one fact governs everything else. Apache Kafka 4.0 supports KRaft only, with ZooKeeper mode removed, so CMAK cannot address such a cluster at all. The maintainer acknowledged this in 2022 and no implementation has shipped since. Managed services either lock down or no longer expose ZooKeeper endpoints, and enabling ZooKeeper ACLs breaks the connection outright.

Data plane: no message browsing, and no Schema Registry, Kafka Connect or ksqlDB integration.

Freshness: reads come from an internal cache, and hours of catch-up replication have shown as complete in seconds.

Access control: no SAML, no OIDC, no per-user or per-topic granularity and no audit log.

Deployment: both community paths, the Docker image repository and the Kubernetes operator chart, are archived and read-only.

Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.

What it costs a year: nothing to license, so the bill is operator time. This page’s estimate, not a vendor price, at 8 engineer-hours a month and 120 US dollars an hour: 11,520 US dollars a year, for the sbt and Scala build on a JDK that fights it, the restart every 20 to 30 days after thread-pool exhaustion, the two archived community deployment paths and the 522 open issues with nobody to escalate to. A Kpow licence is published at 4,500 US dollars a cluster a year with 100 users included, so the free console is the dearer of the two once anybody has to keep it alive.

Which should you pick?

These two are not substitutes: CMAK administers a ZooKeeper cluster and cannot reach Kafka 4.0, and Kafdrop browses messages with no authentication and no partition reassignment. Kafdrop scores 23 against CMAK’s 20. A team that needs both jobs on one governed surface, with RBAC and an audit view included, should shortlist Kpow by Factor House at a published per-cluster price.

Neither, if the cluster is on Kafka 4. CMAK cannot address a cluster with no ZooKeeper, and Kafdrop’s KRaft position is three declined reports, so for a team already committed to a KRaft cutover this pair is the wrong shortlist.

Pick Kafdrop if:

  • what you need is a window onto one cluster rather than a console for operating it
  • the job is local development, a dev cluster, or ad-hoc inspection of a topic
  • a handful of people who already hold credentials are the whole audience
  • nobody untrusted can reach it on the network

Keep CMAK, for now, if:

  • the cluster is ZooKeeper-era
  • partition reassignment and preferred-replica election are what it gets used for
  • its replacement date is already in the same calendar as the KRaft cutover

Moving to Kafdrop means going back to kafka-reassign-partitions.sh or across to Cruise Control for reassignment, because Kafdrop does not do it at all. For a wider shortlist, the best free Kafka UI tools covers the field both of these sit in, and the comparison of the best tools to reassign Kafka partitions covers the work Kafdrop leaves behind.

Kpow: access control that lives inside the product

Neither of these authorises a person inside the product itself. CMAK’s LDAP integration is basic auth plus coarse global feature flags, with no per-topic granularity and no audit log, and Kafdrop ships with no authentication at all, and the README’s answer is an NGINX basic-auth workaround sitting in front of it, which is also what leaves write operations exposed on an unprotected instance. Kpow by Factor House authenticates and authorises users in the product itself rather than at a reverse proxy, runs on KRaft with no ZooKeeper dependency, and ships as a single stateless JVM container with no external database or sidecar. It is licensed per cluster rather than per user, so bringing on another engineer never changes what access control costs.

Access control bolted on at the network edge is access control nobody can audit. Kpow puts it back inside the tool people actually use.

Kpow

How these tools were scored

Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. The options are listed by total.

Sources

Related reading