Server-owned destinations
The browser chooses only a configured cluster ID. Kafka, Kubernetes, Prometheus, Schema Registry, Connect and licensing endpoints are deployment configuration - not browser input.
BetterKafka is a self-hosted operations console with deployment-owned connectivity, server-side credentials, bounded reads, role-aware writes and no CDN dependency at runtime.
The browser chooses only a configured cluster ID. Kafka, Kubernetes, Prometheus, Schema Registry, Connect and licensing endpoints are deployment configuration - not browser input.
SASL, TLS and licence material use Kubernetes Secret references. Cluster APIs do not return connection credentials or mounted key material.
Message scans, topology samples, response bodies, integration calls and concurrency use configured upper bounds and cancellation.
Signed entitlement, installation and cluster-credit checks happen before Kafka clients open and again at protected API boundaries.
The proxy authenticates the browser. BetterKafka validates the session through its fixed internal user-info endpoint and reads trusted identity/group claims.
The chart creates upgrade-stable high-entropy credentials and BetterKafka issues a signed, time-bounded session cookie.
BetterKafka documents its threat model, licence trust boundaries, Helm security context and operational controls. Formal certifications, third-party penetration-test results and universal compliance claims are not implied by this website.
Review the architecture, identity model, trust boundaries, and Helm controls before enabling writes.