Calinora

Self-hosted Kafka operations

See your Kafka cluster clearly.
Rebalance it safely.

Find the pressure points. Preview the plan. Follow every change. Kafka monitoring and safe rebalancing in one self-hosted workspace.

Start monitoring free

Monitoring is free forever - no credit card, deploy in minutes. The trial includes every licensed feature for 30 days, non-production use only. Or read the docs first.

No agents required,No external database,Your infrastructure

macOS / Linux:
curl -fsSLO https://www.calinora.io/pilot-demo.yaml && docker compose -f pilot-demo.yaml up

One copy-paste: boots a demo Kafka broker plus Pilot at localhost:8080. Have a cluster? Point Pilot at it directly - see deployment on the product page.

Used by

  • Vattenfall

Every Kafka team hits the same wall

And the incumbent fix wants JMX wiring, broker-side agents, and weeks of per-cluster tuning before it helps.

  • Uneven broker load, and partition math done by hand.
  • Reassignments that risk under-replication and have to be watched until they finish.
  • Broker maintenance that needs a runbook and a free afternoon.
  • Scaling out or replacing a broker - an OS upgrade, new hardware - takes a plan nobody has time to write.
  • No attributable record of who changed what, or a way to undo it.

With Pilot this is routine work: scale out, replace a broker, or roll an OS upgrade - drained, rebalanced, and back in service without a runbook.

Know what needs your attention

Start with Kafka availability, broker load, and consumer backlog. Follow the evidence into topics and partitions. Monitoring needs no broker agents and never consumes messages.

  • Cluster health at a glance

    See broker availability, offline partitions, under-replication, and rack findings together. Source times and missing evidence stay visible.

  • Find uneven broker load

    Compare sampled activity, stored replica bytes, and leader distribution. Open a broker to inspect the partitions behind the imbalance.

  • Understand consumer backlog

    Inspect group state, members, partition lag, and lag trends. Review exact offsets and retained ranges before a licensed offset reset.

We never read your data to monitor it.

Review the plan. Simulate the impact. Stay in control.

Inspect proposed moves and their projected impact before applying. Test failure and capacity scenarios, then follow execution with health checks, throttles, and per-broker limits.

  • Review every proposed move

    Inspect current and proposed placement, reasons, and projected balance. Rack-aware proposals refresh as the cluster changes.

  • Deterministic plans and what-if

    The same cluster snapshot and settings produce the same plan. Simulate broker or rack loss, added capacity, and traffic changes without changing Kafka.

  • Throttled, gated execution

    Apply reviewed plans with live health checks, adjustable replication throttles, and per-broker concurrency limits. Hard health blockers prevent submission.

Median imbalance 53pp to 4.85pp across 900+ synthetic clusters, no per-cluster tuning.

Trace every change. Review the way back.

Inspect who requested a change, what was submitted, and the recorded result. Review supported reversals against the current cluster before applying them.

  • Audit history and reviewed reversals

    Find recorded requests by actor or action and inspect their results. Supported reversals check current state first; reassignment review shows what can be restored and what is blocked.

  • SSO and revocable tokens

    OAuth2/OIDC SSO via Entra ID, Google, GitHub, or Keycloak, plus revocable read- or write-scoped access tokens.

  • Distinct-approver gate

    AI- and MCP-initiated changes wait for a distinct approver. Hard health blockers cannot be overridden.

Hard health blockers are non-overridable; forced soft overrides are audited.

Run it your way, own your data

Run one container against your Kafka cluster, with no external database or telemetry. Add host agents or an AI assistant when you need them, using infrastructure and providers you choose.

  • Single binary

    Pure Go, CGO-free, on a distroless/static image. No external database - state lives on compacted Kafka topics.

  • Offline license validation

    Ed25519-signed licenses validate offline. No phone-home, air-gap friendly.

  • Docker, Compose, Kubernetes

    Deploy in minutes with a bootstrap-servers address - as a container, a Compose stack, or on Kubernetes.

Free monitoring, proposals, and what-if forever; a license only for mutations.

macOS / Linux:
curl -fsSLO https://www.calinora.io/pilot-demo.yaml && docker compose -f pilot-demo.yaml up

One copy-paste boots a demo broker next to Pilot. In production, point a single container at your bootstrap-servers address - state lives on compacted topics in your own cluster; nothing else to install.

That is the short version - each outcome carries more underneath.

See every capability, grouped by outcome

Measured, not promised

One engine, 3 to 1,000 brokers - published results up to 600,000 partitions.

53pp to 4.85pp

53pp to 4.85pp

median imbalance across 900+ synthetic benchmark clusters, no per-cluster tuning

600,000 partitions

600,000 partitions

across 200 brokers: the plan cuts imbalance from 41.9pp to 4.26pp

Identical plans

Identical plans

on 10 cold-start runs against the same cluster - same moves, same bytes scheduled

When balance is structurally unreachable, the engine names the metric it cannot fix and stops. Read the benchmark methodology on the blog.

Your cluster. Your infrastructure. Your control.

Monitoring and planning run inside your infrastructure, with no telemetry. The optional assistant sends context to your chosen LLM provider. Keep it local or leave it disabled for an offline workflow.

No external database
Pilot keeps its state and audit records in your Kafka cluster.
One container
A single binary with the UI included. No JMX setup or broker agents required for monitoring.
Offline license validation
Validate licenses locally. Supply licenses and agent binaries yourself for air-gapped operation.
Your identity provider
OAuth2/OIDC SSO (Entra ID, Google, GitHub, Keycloak) with allow-lists, plus scoped revocable tokens.
Reviewable change history
Inspect recorded actions and outcomes. Supported reversals are reviewed against current state before applying.
AI never acts alone
AI- and MCP-initiated changes wait for approval from a distinct identity.

Monitoring is free forever

Apply changes per broker when you are ready - no per-seat pricing, cancel any time. Enterprise gets the same product with custom contracts and invoicing.

See pricing and checkout

Questions platform teams ask first

More detail in the documentation.

How long does installation take, and what are the dependencies?

Minutes. Calinora Pilot is a single pure-Go binary with no external database and no librdkafka. Run it with Docker or Compose - the only required configuration is a bootstrap-servers address.

Does it consume my messages?

No. Monitoring is metadata-only - partition activity is inferred from watermark deltas and log-dir sizes. Your message payloads are never read for monitoring.

Does it install anything on my brokers?

No. Pilot is agentless by default and talks to your cluster over the standard Kafka protocol. An optional mTLS agent exists for on-broker tasks like rolling restarts, and you add it only where you need it.

What is free, and what needs a license?

Monitoring, rebalancing proposals, and what-if simulation are free forever, with unlimited viewers and clusters. A license is required only when you apply a change to the cluster.

Where does my data go? Can I run air-gapped?

Nowhere by default, apart from two optional calls to our own servers - license auto-fetch and agent binary download - both of which can be turned off. Everything runs inside your infrastructure, state is stored on compacted Kafka topics in your own cluster, and license validation is offline (Ed25519 signatures, no phone-home). Cluster data only leaves if you point the optional AI assistant at a cloud LLM. Air-gapped operation is supported.

How does it compare to Cruise Control?

No JMX wiring, no broker-side agents, no per-cluster tuning. Pilot samples metadata only, keeps rack-aware proposals always ready, and its plans are deterministic - the same cluster yields the identical plan on every run.

What happens when a license expires?

Nothing happens to your cluster. Pilot drops back to free monitoring mode - dashboards, health checks, proposals, and metrics keep running, and self-healing stops applying changes until the license is renewed. There is no phone-home and no kill switch.

See your Kafka cluster clearly. Rebalance it safely.

One command, demo broker included - no agents, no external database. Monitoring is free forever.

macOS / Linux:
curl -fsSLO https://www.calinora.io/pilot-demo.yaml && docker compose -f pilot-demo.yaml up
Start monitoring free