Self-hosted Kafka operations
See your Kafka cluster clearly.
Rebalance it safely.
Find the pressure points. Preview the plan. Follow every change. Kafka monitoring and safe rebalancing in one self-hosted workspace.
Monitoring is free forever - no credit card, deploy in minutes. The trial includes every licensed feature for 30 days, non-production use only. Or read the docs first.
No agents required,No external database,Your infrastructure
curl -fsSLO https://www.calinora.io/pilot-demo.yaml && docker compose -f pilot-demo.yaml upcurl.exe -fsSLO https://www.calinora.io/pilot-demo.yaml; docker compose -f pilot-demo.yaml upOne copy-paste: boots a demo Kafka broker plus Pilot at localhost:8080. Have a cluster? Point Pilot at it directly - see deployment on the product page.
Every Kafka team hits the same wall
And the incumbent fix wants JMX wiring, broker-side agents, and weeks of per-cluster tuning before it helps.
- Uneven broker load, and partition math done by hand.
- Reassignments that risk under-replication and have to be watched until they finish.
- Broker maintenance that needs a runbook and a free afternoon.
- Scaling out or replacing a broker - an OS upgrade, new hardware - takes a plan nobody has time to write.
- No attributable record of who changed what, or a way to undo it.
With Pilot this is routine work: scale out, replace a broker, or roll an OS upgrade - drained, rebalanced, and back in service without a runbook.
Know what needs your attention
Start with Kafka availability, broker load, and consumer backlog. Follow the evidence into topics and partitions. Monitoring needs no broker agents and never consumes messages.
Cluster health at a glance
See broker availability, offline partitions, under-replication, and rack findings together. Source times and missing evidence stay visible.
Find uneven broker load
Compare sampled activity, stored replica bytes, and leader distribution. Open a broker to inspect the partitions behind the imbalance.
Understand consumer backlog
Inspect group state, members, partition lag, and lag trends. Review exact offsets and retained ranges before a licensed offset reset.
We never read your data to monitor it.
Review the plan. Simulate the impact. Stay in control.
Inspect proposed moves and their projected impact before applying. Test failure and capacity scenarios, then follow execution with health checks, throttles, and per-broker limits.
Review every proposed move
Inspect current and proposed placement, reasons, and projected balance. Rack-aware proposals refresh as the cluster changes.
Deterministic plans and what-if
The same cluster snapshot and settings produce the same plan. Simulate broker or rack loss, added capacity, and traffic changes without changing Kafka.
Throttled, gated execution
Apply reviewed plans with live health checks, adjustable replication throttles, and per-broker concurrency limits. Hard health blockers prevent submission.
Median imbalance 53pp to 4.85pp across 900+ synthetic clusters, no per-cluster tuning.
Trace every change. Review the way back.
Inspect who requested a change, what was submitted, and the recorded result. Review supported reversals against the current cluster before applying them.
Audit history and reviewed reversals
Find recorded requests by actor or action and inspect their results. Supported reversals check current state first; reassignment review shows what can be restored and what is blocked.
SSO and revocable tokens
OAuth2/OIDC SSO via Entra ID, Google, GitHub, or Keycloak, plus revocable read- or write-scoped access tokens.
Distinct-approver gate
AI- and MCP-initiated changes wait for a distinct approver. Hard health blockers cannot be overridden.
Hard health blockers are non-overridable; forced soft overrides are audited.
Run it your way, own your data
Run one container against your Kafka cluster, with no external database or telemetry. Add host agents or an AI assistant when you need them, using infrastructure and providers you choose.
Single binary
Pure Go, CGO-free, on a distroless/static image. No external database - state lives on compacted Kafka topics.
Offline license validation
Ed25519-signed licenses validate offline. No phone-home, air-gap friendly.
Docker, Compose, Kubernetes
Deploy in minutes with a bootstrap-servers address - as a container, a Compose stack, or on Kubernetes.
Free monitoring, proposals, and what-if forever; a license only for mutations.
curl -fsSLO https://www.calinora.io/pilot-demo.yaml && docker compose -f pilot-demo.yaml upcurl.exe -fsSLO https://www.calinora.io/pilot-demo.yaml; docker compose -f pilot-demo.yaml upOne copy-paste boots a demo broker next to Pilot. In production, point a single container at your bootstrap-servers address - state lives on compacted topics in your own cluster; nothing else to install.
That is the short version - each outcome carries more underneath.
See every capability, grouped by outcomeMeasured, not promised
One engine, 3 to 1,000 brokers - published results up to 600,000 partitions.
- 53pp to 4.85pp
53pp to 4.85pp
median imbalance across 900+ synthetic benchmark clusters, no per-cluster tuning
- 600,000 partitions
600,000 partitions
across 200 brokers: the plan cuts imbalance from 41.9pp to 4.26pp
- Identical plans
Identical plans
on 10 cold-start runs against the same cluster - same moves, same bytes scheduled
When balance is structurally unreachable, the engine names the metric it cannot fix and stops. Read the benchmark methodology on the blog.
Your cluster. Your infrastructure. Your control.
Monitoring and planning run inside your infrastructure, with no telemetry. The optional assistant sends context to your chosen LLM provider. Keep it local or leave it disabled for an offline workflow.
- No external database
- Pilot keeps its state and audit records in your Kafka cluster.
- One container
- A single binary with the UI included. No JMX setup or broker agents required for monitoring.
- Offline license validation
- Validate licenses locally. Supply licenses and agent binaries yourself for air-gapped operation.
- Your identity provider
- OAuth2/OIDC SSO (Entra ID, Google, GitHub, Keycloak) with allow-lists, plus scoped revocable tokens.
- Reviewable change history
- Inspect recorded actions and outcomes. Supported reversals are reviewed against current state before applying.
- AI never acts alone
- AI- and MCP-initiated changes wait for approval from a distinct identity.
Monitoring is free forever
Apply changes per broker when you are ready - no per-seat pricing, cancel any time. Enterprise gets the same product with custom contracts and invoicing.
Questions platform teams ask first
More detail in the documentation.
How long does installation take, and what are the dependencies?
Minutes. Calinora Pilot is a single pure-Go binary with no external database and no librdkafka. Run it with Docker or Compose - the only required configuration is a bootstrap-servers address.
Does it consume my messages?
No. Monitoring is metadata-only - partition activity is inferred from watermark deltas and log-dir sizes. Your message payloads are never read for monitoring.
Does it install anything on my brokers?
No. Pilot is agentless by default and talks to your cluster over the standard Kafka protocol. An optional mTLS agent exists for on-broker tasks like rolling restarts, and you add it only where you need it.
What is free, and what needs a license?
Monitoring, rebalancing proposals, and what-if simulation are free forever, with unlimited viewers and clusters. A license is required only when you apply a change to the cluster.
Where does my data go? Can I run air-gapped?
Nowhere by default, apart from two optional calls to our own servers - license auto-fetch and agent binary download - both of which can be turned off. Everything runs inside your infrastructure, state is stored on compacted Kafka topics in your own cluster, and license validation is offline (Ed25519 signatures, no phone-home). Cluster data only leaves if you point the optional AI assistant at a cloud LLM. Air-gapped operation is supported.
How does it compare to Cruise Control?
No JMX wiring, no broker-side agents, no per-cluster tuning. Pilot samples metadata only, keeps rack-aware proposals always ready, and its plans are deterministic - the same cluster yields the identical plan on every run.
What happens when a license expires?
Nothing happens to your cluster. Pilot drops back to free monitoring mode - dashboards, health checks, proposals, and metrics keep running, and self-healing stops applying changes until the license is renewed. There is no phone-home and no kill switch.
See your Kafka cluster clearly. Rebalance it safely.
One command, demo broker included - no agents, no external database. Monitoring is free forever.
curl -fsSLO https://www.calinora.io/pilot-demo.yaml && docker compose -f pilot-demo.yaml upcurl.exe -fsSLO https://www.calinora.io/pilot-demo.yaml; docker compose -f pilot-demo.yaml up