Conduktor gives enterprise engineering teams the governance, security, and operational control they need to run Apache Kafka confidently at scale - across any infrastructure, any provider.
Conduktor is the enterprise control plane for Apache Kafka - built for organizations running Kafka at scale, including on Amazon MSK, who need more than native tooling provides. Console and Gateway work side by side, giving developers the velocity to ship fast and platform teams the control to enforce standards across any Kafka provider and infrastructure. Gateway - Route. Protect. Transform. Conduktor Gateway sits transparently between your client applications and your Kafka clusters, intercepting wire-level traffic to add the governance, security, and resilience your organization needs - without any changes to your producers, consumers, or brokers. Gateway is built on an extensible interceptor plugin mechanism, allowing teams to apply technical and business logic dynamically at the transport layer. It is fully Apache Kafka protocol compliant and vendor-agnostic - it works with any Kafka deployment, wherever it runs. Gateway is available as a Core base with optional add-ons: Core - The foundational Gateway layer. Multi-tenancy via virtual clusters, external data sharing via Partner Zones, topic-level policy enforcement, consumer group isolation, and a GitOps-compatible configuration API. All add-ons require Core. DR & Failover (add-on) - Transparent failover between Kafka clusters with zero application-side changes. Designed for high-availability requirements and zero-downtime migration or recovery. Protect (add-on) - Field-level and full-payload encryption, data masking, and fine-grained access enforcement at the message level. Enforce data security and regulatory compliance without modifying a single producer or consumer. Console - Visibility. Ownership. Autonomy. Conduktor Console is the modern Kafka UI and API built for platform and data engineering teams who need to govern Kafka at scale - without becoming a bottleneck for the developers who depend on it. Console gives platform teams an ownership model that scales. Application and topic catalogs establish accountability across your entire Kafka estate. Automated policy enforcement, approval workflows, and self-service provisioning let you set guardrails once and let developers operate within them - without opening tickets or requiring manual intervention. - Manage multiple clusters from a single control plane, including Amazon MSK, Confluent, Redpanda, Aiven, and self-managed Apache Kafka - Role-based access control at cluster, topic, and consumer group level - Application and topic catalogs with resource ownership mapping across teams - Self-service developer provisioning within automated policy guardrails - Approval workflows for access requests - no ticket queues - Health optimization with partition, retention, and configuration recommendations - Cost attribution and chargeback reporting across teams and projects - Real-time monitoring, custom alerting, and full audit logging - GitOps-compatible API for infrastructure-as-code workflows
Highlights
No code changes required - Gateway is fully transparent to your applications and brokers. Connect, apply policies, and get immediate value without touching your existing stack.
Any Kafka, any infrastructure - Both products work across every major Kafka provider. No lock-in, no migration required.
Built for regulated industries - Encryption, masking, audit trails, approval workflows, and RBAC meet the requirements of financial services, healthcare, and public sector deployments.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
The foundational Gateway layer for the enterprise. Multi-tenancy via virtual clusters, topic-level policy enforcement, consumer group isolation, and a GitOps-compatible configuration API. Includes built-in DR & Failover: transparent failover between Kafka clusters with zero application-side changes, designed for high-availability requirements and zero-downtime migration or recovery. Also includes Exchange: share Kafka data securely with external partners via isolated Partner Zones - control topic exposure, enforce traffic quotas, and hide internal topic structure, with no data duplication required.
$30,000.00
Conduktor Gateway Protect add-on
Field-level and full-payload encryption, data masking, and fine-grained access enforcement at the message level. Enforce data security and regulatory compliance without modifying a single producer or consumer.
$10,000.00
Conduktor Console
Conduktor Console is the modern Kafka UI and API built for platform and data engineering teams who need to govern Kafka at scale - without becoming a bottleneck for the developers who depend on it. Unit price shown for 1-100 seats. Additional Tiers with decreasing unit price are 101-250, 251-500, 501-1000, 1001+ seats.
This listing bills through a contract with three components you combine as needed. Conduktor Enterprise Gateway is priced per unit and forms the base proxy layer. Conduktor Gateway Protect is a per-unit add-on that layers encryption, masking, and message-level access controls on top of the Gateway. Conduktor Console is priced per seat, with the unit price shown covering 1-100 seats. Console seats scale across five tiers (1-100, 101-250, 251-500, 501-1000, 1001+), and the per-seat price decreases as you move into higher seat bands.
Top-of-mind questions for buyers
What counts as one unit for Conduktor Enterprise Gateway and the Protect add-on?
Gateway units track the Kafka clusters the proxy sits in front of, and the seller notes a three-cluster minimum. The Protect add-on layers onto that same Gateway footprint, so its units cover the same clusters where you enable encryption, masking, and message-level access controls.
How does cost change as I add more Conduktor Console seats?
Console bills per seat across five bands: 1-100, 101-250, 251-500, 501-1000, and 1001+. The per-seat price drops as you move into higher bands. The marketplace unit price shown reflects the 1-100 seat band. You pay for the seats you assign to users.
Do I have to buy Conduktor Console to use the Gateway, or can they bill separately?
Console and Gateway are independent products that bill on their own dimensions. Console is priced per seat; Gateway is priced per unit tied to clusters. Protect is an add-on that requires Enterprise Gateway. You combine only the components you need, and charges for each appear together on one contract.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Install the Conduktor Console and Conduktor Cortex by running the provided CloudFormation template.
Support
Vendor support
For a detailed overview of your support options, please contact sales@conduktor.io Conduktor support provides 9x5 or 24x7 support with enterprise SLAs across 4 severity levels with response times as low as 60 minutes.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Conduktor gives enterprise engineering teams the governance, security, and operational control they need to run Apache Kafka confidently at scale - across any infrastructure, any provider.
Conduktor gives enterprise engineering teams the governance, security, and operational control they need to run Apache Kafka confidently at scale - across any infrastructure, any provider.
Conduktor is the Enterprise Data Management (EDM) platform focused on streaming. It accelerates data adoption across the organization and boosts efficiency and collaboration, unlocking the full potential of your data streaming infrastructure and driving faster deployment of data services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.