SECURITY

Designed to stay
inside your boundary.

BetterKafka is a self-hosted operations console with deployment-owned connectivity, server-side credentials, bounded reads, role-aware writes and no CDN dependency at runtime.

Server-owned destinations

The browser chooses only a configured cluster ID. Kafka, Kubernetes, Prometheus, Schema Registry, Connect and licensing endpoints are deployment configuration - not browser input.

Secret references

SASL, TLS and licence material use Kubernetes Secret references. Cluster APIs do not return connection credentials or mounted key material.

Bounded workloads

Message scans, topology samples, response bodies, integration calls and concurrency use configured upper bounds and cancellation.

Fail-closed licensing

Signed entitlement, installation and cluster-credit checks happen before Kafka clients open and again at protected API boundaries.

IDENTITY & AUTHORIZATION

Fit the authentication model you operate.

External identity

Trusted OAuth2 Proxy

The proxy authenticates the browser. BetterKafka validates the session through its fixed internal user-info endpoint and reads trusted identity/group claims.

  • Optional Kubernetes SubjectAccessReview
  • Viewer, editor and admin resolution
  • Local login explicitly disabled
No external proxy

Local administrator

The chart creates upgrade-stable high-entropy credentials and BetterKafka issues a signed, time-bounded session cookie.

  • Enabled only when proxy mode is absent
  • Secret-backed credentials
  • Logout and expiry handling
WHAT WE CLAIM

Specific controls, not compliance theatre.

BetterKafka documents its threat model, licence trust boundaries, Helm security context and operational controls. Formal certifications, third-party penetration-test results and universal compliance claims are not implied by this website.

Restricted container security contextOptional NetworkPolicy, PDB and HPAStructured mutation logsResponse masking rulesPackaged frontend assetsVersioned OpenAPI contract
SECURE SELF-HOSTING

Evaluate the deployment before rollout.

Review the architecture, identity model, trust boundaries, and Helm controls before enabling writes.

Start free trialRead deployment docs
Copied to clipboard