Security context
Non-root container execution, read-only root filesystem, dropped capabilities, seccomp, and Secret references.
Deploy a self-hosted Kafka UI with Kubernetes-native secrets, probes, resources, optional network policy, and server-owned cluster connections.
After payment, the BetterKafka account provides a one-time activation key and a pinned chart/image release. The setup flow generates values locally in the browser; Kafka endpoints and credentials are not sent to billing or licensing.
--wait, check rollout health, and open the console.kubectl --namespace monitoring create secret generic better-kafka-license \
--from-file=activation-key=./activation-keyThe key is read from a local file. Do not place it in --set, a URL, source control, or a support message.
Non-root container execution, read-only root filesystem, dropped capabilities, seccomp, and Secret references.
Startup, readiness and liveness probes plus optional PodDisruptionBudget and autoscaling configuration.
Optional ingress and NetworkPolicy rules with fixed Kafka, licensing, Kubernetes, Prometheus, Connect, and Schema Registry destinations.
The customer account supplies the pinned, licensed release coordinates after payment. The public site does not publish an internal registry path as if it were generally available.
Yes. Start with mutation capabilities disabled, then add only the Kafka ACLs, Kubernetes RBAC, and product roles you have reviewed.
Add stable server-configured cluster entries in Helm values; each entry uses one licensed cluster credit.
No. BetterKafka connects to existing Apache Kafka, Bitnami, or Strimzi-backed clusters.
Verify your email, save the one-time key, and continue with the same Helm workflow.