New
The Zilla MCP Gateway is available — governed agent access to your APIs, services, and real-time data.
Read the launch →

Kafka-native
proxy. Multi-protocol gateway.One stateless data plane.

Zilla Kafka Gateway puts a secure, stateless edge in front of Kafka. Proxy native Kafka clients, connect non-Kafka clients, and enforce identity, schema, policy, and audit controls without changing your applications or clusters.

Available in

Community

Plus

Enterprises

Powering Global Data Driven Organizations

The Problem

Kafka was built for systems, not governed access at scale.

The wrapper farm

Exposing Kafka to apps, partners, devices, and agents means wrapper services — until the wrapper layer becomes the product.

Custom code

Duplicated logic

Ops overhead

Uneven governance

The governance gap

Isolation, identity, and edge enforcement aren't built in. You build them yourself — or go without.

Tenant isolation

Identity end-to-end

Schema at the edge

Per-tenant quotas

Field-level privacy

Audit trails

The Solution

Stateless data plane. Declaratively configured. Deployed anywhere.

Zilla Kafka Gateway runs between client traffic and your Kafka cluster as a stateless process. A single zilla.yaml defines the protocols, routes, identities, schemas, and policies at the edge. A single binary with no database, no persistent storage, and no coordination layer between gateway instances.

The wrapper farm

Scale horizontally. Restart safely. Run multiple instances without shared state or coordination

Declarative configuration

Define Kafka access, protocol mediation, schemas, and policies in one config file. Reload changes without rewriting applications.

In your perimeter

Keep data, credentials, keys, and Kafka traffic inside your network. Zilla governs access without moving data into an external platform.

Kafka-Native Proxying

Proxy Kafka traffic without changing clients.

For Kafka producers, consumers, and Kafka Connect workers, Zilla is a transparent Kafka proxy. Clients connect the same way they connect to a broker. Only bootstrap.servers changes.

The Kafka wire protocol is preserved end to end, including produces, fetches, consumer groups, transactions, idempotent producers, and Kafka Connect integrations.

Kafka wire-protocol passthrough

Standard Kafka clients in Java, Go, Python, .NET, Node, and other languages connect without SDKs, drivers, or rewrites.

Custom domains for Kafka clients

Expose Kafka through clean, governed domain names such as *.kafka.example.com

Virtual Clusters

Segment one physical Kafka cluster into isolated logical clusters for teams, tenants, partners, or environments.

Identity at the wire

Authenticate Kafka clients with SASL, SCRAM, mTLS, or AWS IAM, then enforce access at the gateway.

Partner access

Safely expose Kafka to external partners without exposing brokers direct

Policy on the passthrough path

Apply configuration rules, schema validation, and data privacy controls before Kafka traffic reaches the cluster.

Data masking and encryption

Encrypt sensitive and PII fields at the gateway before they reach Kafka, then decrypt, redact, or omit them per consumer authorization on read.Fields already stored in the clear can be redacted or encrypted on read too — protecting them retroactively from underprivileged consumers.

Any Kafka distribution

Use the same gateway in front of Apache Kafka, Amazon MSK, Confluent, Aiven, Redpanda, and Cloudera.

Performance

Zilla is built for low latency under load, with a thread-per-core runtime that stays close to Kafka’s native performance ceiling.

Baseline control at the edge

Identity, schema, and telemetry at the edge

Before client traffic reaches Kafka, Zilla applies the controls enterprises expect at the boundary.

Identity for Non-Kafka Clients

Authenticate non-Kafka clients with JWT, Azure AD, or AWS Lambda authorizers. Authenticate Kafka-native clients with SASL, SCRAM, mTLS, or AWS IAM.

Use identity to authorize routes, topics, tools, tenants, and client access patterns.

Schema Enforcement

Validate messages against the registry you already run. Reject invalid data at the edge before it reaches Kafka.

Supported registries include Confluent Schema Registry, Karapace, Apicurio, AWS Glue Schema Registry, and inline filesystem schemas.

Supported formats include Avro, JSON Schema, Protobuf, and scalar types.

Telemetry

Export Kafka-aware metrics and structured events to the systems you already use, including Prometheus, OpenTelemetry, stdout logs, CloudWatch, and Syslog.

Track request duration, response codes, produce and fetch volume, topic access, client identity, and quota violations without log spelunking.

Governance

Data quality and governance at the edge.

Define policy centrally. Enforce it at the gateway. Keep Kafka ACLs and quotas in place — and add the controls Kafka cannot provide on its own.

Configuration policy enforcement
Field level encryption and crypto shredding
Trading & Market Streaming schema validationData 

Spec-driven configuration

Zilla treats API specifications as configuration, not code generation.

OpenAPI

Expose REST endpoints backed by Kafka topics.

AsyncAPI

Define channels, operations, messages, and protocol mappings.

OpenAPI → AsyncAPI proxy

Create HTTP request-response surfaces backed by Kafka.

Protobuf

Use .proto definitions for gRPC and Kafka message contracts.

In Production

Production Kafka traffic, at
enterprise scale.

“Zilla Plus gave us exactly what we needed — secure, Kafka-native connectivity to our private MSK clusters from anywhere, without compromising security or building custom integrations. It’s accelerated our project delivery and simplified how we connect critical business systems across our ecosystem.”

Karthik Rajendran

Platform Owner, KONE

KONE

How KONE Uses Zilla Plus to Securely Bridge Amazon MSK with SAP Cloud & Beyond

Key Results

Connected MSK clusters securely without public exposure

Accelerated project delivery across SAP & third-party systems

Reduced dev overhead by eliminating custom integrations

‍“Zilla’s extensive protocol support, integrations with AWS services such as Glue Schema Registry and Secrets Manager, as well as robust logging capabilities, gives me confidence it can be a one-stop solution for all of our external MSK integration needs.”

Gordon Zardoya

Solution Architect, N Brown-Castle Fintech

N Brown

N Brown Achieves Event-Driven Partner Integrations with Zilla Plus

Key Results

Secure endpoints enabled fast partner integrations

Lead time cut, team focused on Kafka design

Unified interface across Kafka and non-Kafka apps

Developer Experience

Developer friendly. Enterprise-ready.

Zilla is open core and source available on GitHub. It runs locally for development and scales into production for enterprise Kafka access patterns.

Install and run
Docker
Homebrew
Helm
Quickstart

Run a local Kafka gateway with sample topics, protocol mappings, and working examples.

Try locally
VS Code extension

Render zilla.yaml as an interactive network diagram with inline docs and YAML intelligence.

Install extension
Benchmarks

Reproduce performance testing with the Aklivity OpenMessaging Benchmark fork.

OMB on GitHub

Still do you have Questions?

What is the Zilla Platform?
Is Zilla open source?
Does Zilla replace Kafka?
Does Zilla require Kafka?
Which Kafka services does it work with?
How is this different from an API gateway?
What is MCP, and how does Zilla support it?

Put a governed edge in front of Kafk

Proxy native Kafka clients. Connect every other client. Enforce identity, schema, policy, and audit at the gateway. For Kafka, APIs, devices, partners, and AI agents.

Transparent pricing

Start for free and scale with flexible, deploymentMi dui pharetra ut ultricies viverra tempor. Egestas erat ac amet id diam pharetra ullamcorper.-based pricing.

Pricing details

Join the Community

Mi dui pharetra ut ultricies viverra tempor. Egestas erat ac amet id diam pharetra ullamcorper.

Join Community