Kafka-native
proxy. Multi-protocol gateway.One stateless data plane.
Zilla Kafka Gateway puts a secure, stateless edge in front of Kafka. Proxy native Kafka clients, connect non-Kafka clients, and enforce identity, schema, policy, and audit controls without changing your applications or clusters.
Community
Plus
Enterprises

The Problem
Kafka was built for systems, not governed access at scale.
The wrapper farm
Exposing Kafka to apps, partners, devices, and agents means wrapper services — until the wrapper layer becomes the product.
Custom code
Duplicated logic
Ops overhead
Uneven governance
The governance gap
Isolation, identity, and edge enforcement aren't built in. You build them yourself — or go without.
Tenant isolation
Identity end-to-end
Schema at the edge
Per-tenant quotas
Field-level privacy
Audit trails


The Solution
Stateless data plane. Declaratively configured. Deployed anywhere.
Zilla Kafka Gateway runs between client traffic and your Kafka cluster as a stateless process. A single zilla.yaml defines the protocols, routes, identities, schemas, and policies at the edge. A single binary with no database, no persistent storage, and no coordination layer between gateway instances.
The wrapper farm
Scale horizontally. Restart safely. Run multiple instances without shared state or coordination
Declarative configuration
Define Kafka access, protocol mediation, schemas, and policies in one config file. Reload changes without rewriting applications.
In your perimeter
Keep data, credentials, keys, and Kafka traffic inside your network. Zilla governs access without moving data into an external platform.



Kafka-Native Proxying
Proxy Kafka traffic without changing clients.
For Kafka producers, consumers, and Kafka Connect workers, Zilla is a transparent Kafka proxy. Clients connect the same way they connect to a broker. Only bootstrap.servers changes.
The Kafka wire protocol is preserved end to end, including produces, fetches, consumer groups, transactions, idempotent producers, and Kafka Connect integrations.
Kafka wire-protocol passthrough
Standard Kafka clients in Java, Go, Python, .NET, Node, and other languages connect without SDKs, drivers, or rewrites.
Custom domains for Kafka clients
Expose Kafka through clean, governed domain names such as *.kafka.example.com
Virtual Clusters
Segment one physical Kafka cluster into isolated logical clusters for teams, tenants, partners, or environments.
Identity at the wire
Authenticate Kafka clients with SASL, SCRAM, mTLS, or AWS IAM, then enforce access at the gateway.
Partner access
Safely expose Kafka to external partners without exposing brokers direct
Policy on the passthrough path
Apply configuration rules, schema validation, and data privacy controls before Kafka traffic reaches the cluster.
Data masking and encryption
Encrypt sensitive and PII fields at the gateway before they reach Kafka, then decrypt, redact, or omit them per consumer authorization on read.Fields already stored in the clear can be redacted or encrypted on read too — protecting them retroactively from underprivileged consumers.
Any Kafka distribution
Use the same gateway in front of Apache Kafka, Amazon MSK, Confluent, Aiven, Redpanda, and Cloudera.


Identity, schema, and telemetry at the edge
Before client traffic reaches Kafka, Zilla applies the controls enterprises expect at the boundary.
Identity for Non-Kafka Clients
Authenticate non-Kafka clients with JWT, Azure AD, or AWS Lambda authorizers. Authenticate Kafka-native clients with SASL, SCRAM, mTLS, or AWS IAM.
Use identity to authorize routes, topics, tools, tenants, and client access patterns.
Schema Enforcement
Validate messages against the registry you already run. Reject invalid data at the edge before it reaches Kafka.
Supported registries include Confluent Schema Registry, Karapace, Apicurio, AWS Glue Schema Registry, and inline filesystem schemas.
Supported formats include Avro, JSON Schema, Protobuf, and scalar types.
Telemetry
Export Kafka-aware metrics and structured events to the systems you already use, including Prometheus, OpenTelemetry, stdout logs, CloudWatch, and Syslog.
Track request duration, response codes, produce and fetch volume, topic access, client identity, and quota violations without log spelunking.


Governance
Data quality and governance at the edge.
Define policy centrally. Enforce it at the gateway. Keep Kafka ACLs and quotas in place — and add the controls Kafka cannot provide on its own.
Achieve secure, real-time data sharing across banks, fintechs, and partners by exposing Kafka streams as governed APIs with fine-grained access controls. Leverage open standards such as OpenAPI and AsyncAPI, making it easier to meet regulatory requirements while accelerating innovation in Open Banking ecosystems.
Unify real-time data from payments, accounts, and digital channels into secure, governed APIs. This enables instant fraud deEncrypt sensitive fields at the gateway before data reaches Kafka. On read, decrypt, redact, or omit fields based on the consumer’s authorization.
Keys stay in your KMS, including AWS KMS, HashiCorp Vault Transit, and KMIP-compatible backends. Two key models are supported: registryless (per-user KEK, Conduktor-style) and registry-backed (Confluent-style) — each with different strengths.
For GDPR erasure, destroy the per-user KEK instead of rewriting Kafka history — well-suited to the registryless model, where discarding the key permanently shreds that entity’s data.tection, personalized financial experiences, and compliance-ready customer insights, all with the speed and reliability financial services demand.
Accelerate digital financial application development by securely exposing Kafka-based trading and market data as low-latency, governed APIs. With multi-protocol access and built-in compliance controls, developers can quickly build trading platforms, analytics tools, and customer-facing apps that operate at market scale with confidence.





Spec-driven configuration
Zilla treats API specifications as configuration, not code generation.
OpenAPI
Expose REST endpoints backed by Kafka topics.
AsyncAPI
Define channels, operations, messages, and protocol mappings.
OpenAPI → AsyncAPI proxy
Create HTTP request-response surfaces backed by Kafka.
Protobuf
Use .proto definitions for gRPC and Kafka message contracts.


Baader Bank
German private bank running latency- and stability-sensitive financial workloads on a Kafka backbone exposed through the gateway.
Enphase Energy
Residential solar energy platform connecting home devices and downstream systems through the gateway's MQTT and HTTP surfaces.
N Brown
UK online retailer using the gateway for partner-facing data access and customer-portal traffic.


Developer Experience
Developer friendly. Enterprise-ready.
Zilla is open core and source available on GitHub. It runs locally for development and scales into production for enterprise Kafka access patterns.
Install and run
Quickstart
Run a local Kafka gateway with sample topics, protocol mappings, and working examples.
VS Code extension
Render zilla.yaml as an interactive network diagram with inline docs and YAML intelligence.
Benchmarks
Reproduce performance testing with the Aklivity OpenMessaging Benchmark fork.


Still do you have Questions?
Suspendisse a arcu fermentum ligula eleifend ultricies. Vestibulum
Suspendisse a arcu fermentum ligula eleifend ultricies. Vestibulum
Suspendisse a arcu fermentum ligula eleifend ultricies. Vestibulum
Suspendisse a arcu fermentum ligula eleifend ultricies. Vestibulum
Suspendisse a arcu fermentum ligula eleifend ultricies. Vestibulum
Suspendisse a arcu fermentum ligula eleifend ultricies. Vestibulum
Suspendisse a arcu fermentum ligula eleifend ultricies. Vestibulum


Put a governed edge in front of Kafk
Proxy native Kafka clients. Connect every other client. Enforce identity, schema, policy, and audit at the gateway. For Kafka, APIs, devices, partners, and AI agents.
Transparent pricing
Start for free and scale with flexible, deploymentMi dui pharetra ut ultricies viverra tempor. Egestas erat ac amet id diam pharetra ullamcorper.-based pricing.
Join the Community
Mi dui pharetra ut ultricies viverra tempor. Egestas erat ac amet id diam pharetra ullamcorper.












