At a glance
Kpow and CMAK are scored here on the same five criteria, 50 points in all: Kpow 44 out of 50, CMAK 20 out of 50. Kpow takes its best score on Access control and audit (10 out of 10) and its lowest on Cost as teams grow (7 out of 10). Cost a year: $7,380 on one cluster: $4,500 published plus $2,880. CMAK takes its best score on Cost as teams grow (10 out of 10) and its lowest on Support and maintenance (1 out of 10). Cost a year: $0 licence, $11,520 in operator time (this page's estimate).
Kpow vs CMAK, compared
Kpow meets 6 of 7 requirements on this page. One row is not a yes or no question.
Key takeaway
CMAK connects through ZooKeeper, and Kafka 4.0 removes ZooKeeper mode entirely, so it cannot reach a 4.x cluster at all. It is still good at partition reassignment and preferred-replica election, but free is the licence and not the cost: an archived Kubernetes chart and 522 open issues with no maintainer behind them. Access control is the other gap: LDAP basic auth, no OIDC, no per-topic granularity, no audit log. Kpow by Factor House bills per cluster from 4,500 US dollars, with 100 users included.
Kpow live demo
See Kpow in a working Kafka environment
You have seen how Kpow compares on paper. Open the live demo to test the workflows your platform team will depend on during an incident.
Built for platform and data teams managing shared Kafka clusters.
Try the Kpow demoWhat is CMAK?
CMAK is Cluster Manager for Apache Kafka, built at Yahoo and released under Apache 2.0. It was called Kafka Manager before it was renamed. It is a Scala and Play application, and it connects to a ZooKeeper ensemble rather than to the brokers. Its scope is administrative rather than data-plane, and one structural fact governs every section after this one: CMAK reads through ZooKeeper.
- registering and monitoring clusters from a single view
- partition reassignment and preferred-replica election
- creating and modifying topics, and managing partitions
- optional JMX polling, the thinnest form of Kafka monitoring anybody would name as such
It is genuinely good at two of those. Partition reassignment and preferred-replica election are what operators praise it for most consistently, and both are real operational work rather than a view onto somebody else’s. On a ZooKeeper-era cluster it also remains a clear way to learn Kafka’s internal model.

What is Kpow?
Kpow by Factor House is engineer-facing tooling for Apache Kafka, and it runs against whatever cluster you already have: self-managed Kafka, Amazon MSK, Confluent Cloud, Redpanda, Aiven and Instaclustr. It talks to brokers rather than to ZooKeeper, which is why the metadata question never arises. It is a single stateless JVM container, configured entirely through environment variables, with no external database, no sidecar and no persistent volume, storing its telemetry in internal Kafka topics on the cluster it is already monitoring. One instance manages up to 12 Kafka clusters.
That matters more here than it would against another commercial product. What a CMAK operator is weighing is not one interface against another. It is an application they build from source and carry themselves against one they pull and configure. One structural fact governs Kpow in the same way: it runs on top of the cluster and never runs the cluster, and it is licensed rather than free.

What is the official 2026 pricing of Kpow and CMAK?
CMAK is free under Apache 2.0, on a single self-hosted tier. There is no paid edition, no hosted offering and no support contract, so the whole cost of running it is the engineering time that carries it. For a team of five on one ZooKeeper cluster, that carry is small and the zero is real. For a platform team on six clusters with an audit requirement it is different work: an sbt build on a current JDK, a Docker image somebody in the community maintains on no schedule, a Kubernetes operator chart that is archived and read-only, and 522 open issues with nobody left to send a five hundred and twenty-third one to.
Kpow bills per cluster per year and the price is published. Enterprise starts at 4,500 US dollars per cluster with 100 users included, and Community Edition is free for up to 3 clusters and 10 users, with a 30-day trial of Enterprise on top of it. Adding an engineer does not change the bill, and the number is one somebody can put in a budget before they talk to anybody.
Where does each one run out?
The scoring is the same on both sides: five criteria, 10 points each, 50 in all, with every criterion counting once. Nothing sits behind a multiplier, so a total is the sum of its five marks and a reader can recompute it. The five are cost as teams grow, deployment footprint, support and maintenance, access control and audit, and multi-cluster reach, because those are the questions a Kafka interface is actually measured against after the first month: a second cluster, an access review with a date on it, an upgrade nobody owns, and a bill that moves when the team does. The widest gap between the two marks is on support and maintenance, where CMAK marks 1 and Kpow marks 9. The marks come from the same matrix used on every comparison on this site, so a tool scores the same here as it does anywhere else, and the reason behind each mark is in the card below, under Why these scores.
The dependency figures in the cards below were read on 24 September 2026 from each project’s published release artefact and matched against the NVD and GitHub advisory databases, so they move whenever a release or an advisory lands. Kpow is self-hosted as well. What a licence buys here is not a different deployment model, it is a company under contract to ship the patched build.
Rank 1 Kpow
44 out of 50 Total
Try Kpow in the live demo No signup needed.
- Cost a year
- $7,380 on one cluster: $4,500 published plus $2,880
- Kafka 4.x
- Yes. It talks to brokers, not ZooKeeper
- Clusters per instance
- Up to 12
- Cost as teams grow
- 7 out of 10
- Deployment footprint
- 9 out of 10
- Support and maintenance
- 9 out of 10
- Access control and audit
- 10 out of 10
- Multi-cluster reach
- 9 out of 10
Why these scores for Kpow
- Cost as teams grow 7 out of 10
- Per cluster and published, Enterprise from 4,500 US dollars with 100 users included and Community Edition free for 3 clusters and 10 users, docked because RBAC, masking and audit are held back from the free tier. On this page, CMAK scores 10 because it is free, and this number can go in a budget before anybody is contacted.
- Deployment footprint 9 out of 10
- One stateless container configured by environment variables, with no database, sidecar or persistent volume. This page sets a container you pull and configure against an application built from source with sbt and carried yourself.
- Support and maintenance 9 out of 10
- Shipping continuously, with priority support on Enterprise and community Slack and docs on Community. This page adds a 30-day Enterprise trial on top of that, against no support tier, no documentation site and no community channel.
- Access control and audit 10 out of 10
- Per-resource RBAC, single sign-on, server-side masking and a full audit log in the product on Enterprise. This page sets that against LDAP basic auth and coarse global feature flags with no audit log at all.
- Multi-cluster reach 9 out of 10
- Up to 12 clusters per instance across MSK, Confluent Cloud, Redpanda, Aiven and Instaclustr, held at 9 by the per-instance cap of 12. On this page, it talks to brokers rather than ZooKeeper, so the managed services CMAK cannot reach are in scope.
It is a commercial licence, and a team that will not carry one is not the buyer. It runs on top of the cluster rather than running it, same as CMAK. The difference is what the licence buys: a role model, an audit trail and support behind it, published as one number per cluster rather than negotiated case by case.
Kpow answers each one on the other side: it talks to brokers rather than to ZooKeeper, so the metadata question never arises, message browsing is in the product, and role-based access control, single sign-on and a full audit log ship on Enterprise, with priority support behind it.
It also reaches clusters CMAK cannot: Amazon MSK, Confluent Cloud, Redpanda, Aiven and Instaclustr, as one stateless container with no database or persistent volume behind it, and the price is published per cluster rather than negotiated case by case.
Staying patched: the image built on 5 August 2026 bundles 311 libraries. The argument here is contractual accountability rather than speed.
What it costs a year: 7,380 US dollars a year on one cluster: the published 4,500 per cluster with 100 users included, plus 2,880 of modelled operator time at 120 US dollars an engineer hour, which is this page’s estimate rather than a vendor price. Community Edition is free for up to 3 clusters and 10 users, with a 30-day Enterprise trial on top. The free tool on this page comes to 11,520 a year on the same model, and on the day the cluster moves to KRaft that spend buys nothing at all, because CMAK cannot connect to it.
20 out of 50 Total
- Cost a year
- $0 licence, $11,520 in operator time (this page's estimate)
- Newest published release
- 3.0.0.6, 29 April 2022
- Kafka 4.x
- No. ZooKeeper mode was removed in 4.0
- Cost as teams grow
- 10 out of 10
- Deployment footprint
- 3 out of 10
- Support and maintenance
- 1 out of 10
- Access control and audit
- 2 out of 10
- Multi-cluster reach
- 4 out of 10
Why these scores for CMAK
- Cost as teams grow 10 out of 10
- Apache 2.0, one free tier, nothing to buy. On this page, for a team of five on one ZooKeeper cluster the zero is real, and the whole cost is the engineering time that carries it.
- Deployment footprint 3 out of 10
- A source build with sbt and Scala, community Docker images, the only Kubernetes chart archived, and a ZooKeeper ensemble required. This page gives an sbt build on a current JDK, an image somebody in the community maintains on no schedule, and a chart that is archived and read-only.
- Support and maintenance 1 out of 10
- Last release April 2022, 522 untriaged issues, and no support tier, documentation site or community channel. This page dates 3.0.0.6 to 29 April 2022, with the last commit on master in December of the same year.
- Access control and audit 2 out of 10
- LDAP basic auth and coarse global feature flags, with no SAML, no OIDC, no per-topic granularity and no audit log. This page adds that credentials pass in plaintext unless SSL is configured by hand, and enabling ZooKeeper ACLs breaks the connection outright.
- Multi-cluster reach 4 out of 10
- Many clusters from one view, but ZooKeeper-based clusters only, so nothing on Kafka 4.x and little that is managed. On this page, MSK, Confluent Cloud, Aiven and Redpanda Cloud either lock down or no longer expose ZooKeeper endpoints.
CMAK has no KRaft support and a hard ZooKeeper dependency. Kafka 4.0, released on 18 March 2025, removes ZooKeeper mode entirely, which was the direction set out in KIP-500 and confirmed in KIP-833. The incompatibility is total rather than partial: not a degraded view of a KRaft cluster, but no view. Managed services cut the same way from the other side, because MSK, Confluent Cloud, Aiven and Redpanda Cloud either lock down or no longer expose ZooKeeper endpoints.
Releases: 3.0.0.6 on 29 April 2022, and the last commit on master is December of the same year.
Freshness: reads come from an internal cache rather than live broker APIs, so a reassignment can look as though it has not taken effect.
Access control: LDAP basic auth and coarse global feature flags, with no SAML, no OIDC, no per-topic granularity and no audit log.
Hardening: credentials pass in plaintext unless SSL is configured by hand, and enabling ZooKeeper ACLs breaks the connection outright.
Staying patched: the last release is from April 2022 and nothing has been committed since August 2023. It bundles ZooKeeper 3.5.7, carrying an authorization bypass that scores 9.1 and has been public since October 2023, 1,079 days. No release is coming to carry a fix. 109 of its 112 bundled jars resolve to a Maven coordinate, so its counts are floors rather than totals.
What it costs a year: nothing to licence, and the whole bill is the engineering time that carries it. This page’s estimate rather than a vendor price, at 120 US dollars an engineer hour: eight hours a month covering an sbt build on a current JDK, a community Docker image maintained on no schedule, an archived and read-only Kubernetes chart and 522 open issues with nobody to send a five hundred and twenty-third one to is 11,520 US dollars a year. Kpow on one cluster is its published 4,500 plus 2,880 of the same modelled operator time, so 7,380 a year, and it is the only one of the two a Kafka 4.x cluster can be seen from at all.
How do you switch, or run both?
Running both is fine, and for most teams it is what happens for a while. Neither tool owns cluster state, so the second one is a container and a configuration block rather than a migration, and CMAK keeps working right up until the KRaft cutover and not one day after it. There are four steps, and only one has a date on it.
- Stand the new tool up beside CMAK, before the cutover. Both read the same cluster.
- Re-point the single sign-on. Anything in front of CMAK is a reverse proxy that moves rather than being rebuilt.
- Replace partition reassignment and preferred-replica election, which a lightweight Kafka UI often does not cover.
- Turn CMAK off when ZooKeeper goes. It holds no state of its own.
The well-trodden practitioner path off CMAK runs to AKHQ or Kafbat UI, and either is reasonable where the requirement really is a viewer.
Which should you pick?
Kpow by Factor House is the pick for any team whose cluster is moving to KRaft, scoring 44 against CMAK’s 20, because CMAK reads Kafka through ZooKeeper, which Kafka 4.0 removed, and it has shipped nothing since April 2022. CMAK still scores 10 on cost against Kpow’s 7, and it remains usable for partition reassignment on a ZooKeeper cluster that is going nowhere.
Stay on CMAK if:
- the cluster is staying on ZooKeeper
- the work in front of you is partition reassignment on a small estate
- nobody is asking for an audit trail
Move if:
- the KRaft migration is on a roadmap with a date attached
- a managed service is anywhere in the estate
- RBAC for Kafka has to be answerable per user and per topic rather than per instance
Those three conditions usually describe one team rather than three, because losing ZooKeeper access is what sends somebody to the access-control section in the first place. One team leaving a licensed platform compared the open-source options, CMAK among them, and chose Kpow on consumer lag and offset visibility. Ranking CMAK against the best Kafka management tools matters less than the fact that it is already wired to your brokers.
Partition reassignment is the one job CMAK is still praised for, and Kafka partition rebalancing tools sets out what still covers it on a cluster that no longer runs ZooKeeper.
We talked about my experience in the UK finance software sector, and what 'Enterprise' developers need in order to focus on shipping work that adds value to their team and business rather than fighting otherwise fantastic open-source software.
Derek Troy-West, Co-founder and CEO of Factor House
Why does nobody schedule the admin screen?
CMAK earns credit on its home turf. It was built at Yahoo for exactly this job, and partition reassignment and preferred-replica election are what operators still praise it for most consistently: real operational work on a ZooKeeper-era cluster, not a view onto somebody else’s. Registering and monitoring several clusters from one screen is straightforward, and on a stable ZooKeeper cluster it remains a clear way to learn Kafka’s internal model.
But its whole worldview runs through ZooKeeper, and Kafka 4.0 removed ZooKeeper mode entirely: not a degraded view of a KRaft cluster, no view at all. There is no message browsing of any kind, access control is LDAP basic auth with no SAML, no OIDC and no audit log, and there is no support tier to call when any of that goes wrong. Kpow answers each one on the other side: it talks to brokers rather than to ZooKeeper, so the metadata question never arises, message browsing is in the product, and role-based access control, single sign-on and a full audit log ship on Enterprise, with priority support behind it.
It also reaches clusters CMAK cannot: Amazon MSK, Confluent Cloud, Redpanda, Aiven and Instaclustr, as one stateless container with no database or persistent volume behind it, and the price is published per cluster rather than negotiated case by case. The Community Edition is free for up to 3 clusters and 10 users, which is enough to start on Kpow and run the evaluation against your own migration timeline. CMAK reads the cluster through ZooKeeper. Kpow just reads the cluster.
How these tools were scored
Every option is scored from 0 to 10 on each criterion, from the evidence and sources this page cites, and the reason for each score is on its card. Each criterion counts once, for a total out of 50. This page is published by Factor House, which makes Kpow. Every option is scored on the same rubric and the same sources: Kpow's per-criterion scores are set the same way as every other option's and are not adjusted, and the weights apply to every option alike. Kpow ranks first on its total of 44 out of 50. The other options follow by total.