Conduktor gives enterprise engineering teams the governance, security, and operational control they need to run Apache Kafka confidently at scale - across any infrastructure, any provider.
Conduktor is the enterprise control plane for Apache Kafka - built for organizations running Kafka at scale, including on Amazon MSK, who need more than native tooling provides. Console and Gateway work side by side, giving developers the velocity to ship fast and platform teams the control to enforce standards across any Kafka provider and infrastructure.
Gateway - Route. Protect. Transform.
Conduktor Gateway sits transparently between your client applications and your Kafka clusters, intercepting wire-level traffic to add the governance, security, and resilience your organization needs - without any changes to your producers, consumers, or brokers.
Gateway is built on an extensible interceptor plugin mechanism, allowing teams to apply technical and business logic dynamically at the transport layer. It is fully Apache Kafka protocol compliant and vendor-agnostic - it works with any Kafka deployment, wherever it runs.
Gateway is available as a Core base with optional add-ons:
Core - The foundational Gateway layer. Multi-tenancy via virtual clusters, external data sharing via Partner Zones, topic-level policy enforcement, consumer group isolation, and a GitOps-compatible configuration API. All add-ons require Core.
DR & Failover (add-on) - Transparent failover between Kafka clusters with zero application-side changes. Designed for high-availability requirements and zero-downtime migration or recovery.
Protect (add-on) - Field-level and full-payload encryption, data masking, and fine-grained access enforcement at the message level. Enforce data security and regulatory compliance without modifying a single producer or consumer.
Console - Visibility. Ownership. Autonomy.
Conduktor Console is the modern Kafka UI and API built for platform and data engineering teams who need to govern Kafka at scale - without becoming a bottleneck for the developers who depend on it.
Console gives platform teams an ownership model that scales. Application and topic catalogs establish accountability across your entire Kafka estate. Automated policy enforcement, approval workflows, and self-service provisioning let you set guardrails once and let developers operate within them - without opening tickets or requiring manual intervention.
Manage multiple clusters from a single control plane, including Amazon MSK, Confluent, Redpanda, Aiven, and self-managed Apache Kafka
Role-based access control at cluster, topic, and consumer group level
Application and topic catalogs with resource ownership mapping across teams
Self-service developer provisioning within automated policy guardrails
Approval workflows for access requests - no ticket queues
Health optimization with partition, retention, and configuration recommendations
Cost attribution and chargeback reporting across teams and projects
Real-time monitoring, custom alerting, and full audit logging
GitOps-compatible API for infrastructure-as-code workflows
Highlights
No code changes required - Gateway is fully transparent to your applications and brokers. Connect, apply policies, and get immediate value without touching your existing stack.
Any Kafka, any infrastructure - Both products work across every major Kafka provider. No lock-in, no migration required.
Built for regulated industries - Encryption, masking, audit trails, approval workflows, and RBAC meet the requirements of financial services, healthcare, and public sector deployments.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
The foundational Gateway layer. Multi-tenancy via virtual clusters, topic-level policy enforcement, consumer group isolation, and a GitOps-compatible configuration API. All add-ons require Core.
$20,000.00
Conduktor Gateway Protect add-on
Field-level and full-payload encryption, data masking, and fine-grained access enforcement at the message level. Enforce data security and regulatory compliance without modifying a single producer or consumer.
$10,000.00
Conduktor Gateway DR & Failover add-on
Transparent failover between Kafka clusters with zero application-side changes. Designed for high-availability requirements and zero-downtime migration or recovery.
$10,000.00
Conduktor Gateway Exchange add-on
Share Kafka data securely with external partners via isolated Partner Zones. Control topic exposure, enforce traffic quotas, and hide internal topic structure. No data duplication required.
$0.00
Conduktor Console
Conduktor Console is the modern Kafka UI and API built for platform and data engineering teams who need to govern Kafka at scale - without becoming a bottleneck for the developers who depend on it. Unit price shown for 1-100 seats. Additional Tiers with decreasing unit price are 101-250, 251-500, 501-1000, 1001+ seats.
This listing bundles two product families you buy independently. Conduktor Gateway starts with the Gateway Core unit, the required base layer. You then add optional units for Protect, DR & Failover, and Exchange—each requires Core and priced separately. Conduktor Console is licensed by seat. Its per-seat price steps down as you cross volume tiers: 1-100, 101-250, 251-500, 501-1000, and 1001+ seats. So Console cost scales with headcount, while Gateway cost scales by the number of add-on units you enable on top of Core.
Top-of-mind questions for buyers
What counts as one Gateway unit, and is there a minimum number I must buy?
Gateway is licensed per Kafka cluster, with a three-cluster minimum. Each physical cluster the Gateway proxy sits in front of counts as one unit. The Core layer is required, and each add-on you enable is counted the same per-cluster way on top of Core.
How does Console pricing change as our team grows past a seat tier boundary?
Console is billed per seat. As your seat count crosses each threshold—1-100, 101-250, 251-500, 501-1000, and 1001+—the per-seat unit price steps down. The lower rate applies within that tier band. So adding seats raises total cost while reducing the per-seat rate at higher volumes.
Do I have to buy Console to use Gateway, or can I license them separately?
Console and Gateway are independent products. You can license either alone. Console is billed per seat for Kafka operations and governance. Gateway is billed per cluster for the data-path proxy. Many teams run both, but neither requires the other. Within Gateway, the Core layer is required before any add-on.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Update cloudformation template images to use conduktor/pjy6oobf6g2l6 registry
Additional details
Usage instructions
Launch the cloudformation template from the Deployment template section below.
Support
Vendor support
For a detailed overview of your support options, please contact sales@conduktor.io
Conduktor support provides 9x5 or 24x7 support with enterprise SLAs across 4 severity levels with response times as low as 60 minutes.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Conduktor gives enterprise engineering teams the governance, security, and operational control they need to run Apache Kafka confidently at scale - across any infrastructure, any provider.
Conduktor is the Enterprise Data Management (EDM) platform focused on streaming. It accelerates data adoption across the organization and boosts efficiency and collaboration, unlocking the full potential of your data streaming infrastructure and driving faster deployment of data services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.