Skip to content
CAI
Software that uses CAICheck a score

aws/eventbridge-kafka-connector

63.8

Adequate · 21 September 2026

2.2k

lines of production code

Java

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Apache Kafka Sink Connector for AWS EventBridge that ingests Kafka records and publishes them as events to EventBridge. It supports flexible event mapping via pluggable detail-type and timestamp mappers, and includes a claim-check mechanism to offload large payloads to S3. The connector enforces strict batching limits, handles authentication through customizable AWS credential providers, and provides comprehensive test infrastructure for validating behavior across multiple Kafka distributions.

How it got here

2023 — Connector refactoring and Java 17 migration

8 changes.

The EventBridge Kafka Connector underwent significant refactoring to support S3 payload offloading, extensible mapping interfaces, and strict 1MB batching limits. This period also included migrating the project to Java 17, upgrading AWS SDK dependencies, and establishing comprehensive end-to-end test infrastructure across multiple Kafka distributions.

2024 — Authentication refactoring and test coverage

4 changes.

The authentication module was refactored to support custom AWS credential providers and improved default credential handling via the AWS SDK's ProfileFileSupplier. Comprehensive unit tests were added for the new credentials factory, as well as for cache, offloading, and mapping components to ensure correctness and configuration validation.

Features

Introduces extensible mappers for EventBridge detail type and timestamp mapping

The connector now uses pluggable \DetailTypeMapper\ and \TimeMapper\ interfaces to determine the EventBridge detail type and event timestamp for each Kafka record. A new \DefaultDetailTypeMapper\ allows users to configure a static detail type with topic substitution or map topics to specific detail types via configuration, while a new \JsonPathDetailTypeMapper\ enables extracting the detail type dynamically from the record's JSON payload using a configurable JSON path. Additionally, a \DefaultTimeMapper\ is introduced that currently returns null (falling back to the EventBridge service timestamp), and the \DefaultEventBridgeMapper\ orchestrates these mappers to construct the final \PutEventsRequestEntry\. This change provides users with flexible, configurable ways to control how Kafka records are mapped to AWS EventBridge events.

src/main/java/software/amazon/event/kafkaconnector/mapping · high confidence

Major connector refactoring with S3 offloading, custom mappers, and improved batching

The EventBridge Kafka Connector has been significantly refactored to support new capabilities and improve reliability. Users can now offload large event payloads to an S3 bucket (claim check) using configurable JSON paths, reducing EventBridge event sizes. The connector introduces extensible mapping interfaces, allowing custom logic for both detail-type and event-time mapping via new configuration options. Batching behavior has been improved to support proper batch sending to EventBridge, and the connector now supports global EventBridge endpoints, custom AWS credential providers, and profile-based authentication. Logging has been enhanced to include Git commit identifiers for better traceability, and the internal error handling model has been updated to distinguish between retryable, report-only, and panic errors, improving dead-letter queue integration and retry logic.

src/main/java/software/amazon/event/kafkaconnector · high confidence

New E2E test infrastructure for Apache Kafka, Confluent, and Redpanda

Added end-to-end test configurations and Docker Compose setups to validate the EventBridge Sink Connector against multiple Kafka distributions. The changes introduce dedicated compose files for Apache Kafka (v4.1.1), Confluent Platform (v8.1.1), and Redpanda (v25.3.2), alongside LocalStack (v4.12.0) for AWS service simulation. Connector configurations are provided for standard EventBridge publishing and for AWS S3 offloading (claim check), with specific settings for endpoints, buckets, and field references. Logging and standalone properties are also included to support debugging and local execution of the connector within these test environments.

e2e · high confidence

Behavioural changes

Refactor StatusReporter to use standard Java scheduling and introduce utility classes

The StatusReporter class has been refactored to remove the dependency on Guava's AbstractScheduledService, replacing it with a standard Java ScheduledExecutorService for logging throughput metrics. This change also updates logging initialization to use ContextAwareLoggerFactory across PropertiesUtil and StatusReporter. Additionally, new utility classes have been added: EventBridgeEventId for wrapping EventBridge event IDs, MappedSinkRecord for pairing Kafka SinkRecords with mapped values, and ThrowingFunction/ThrowingFunctionApplyException to support functional interfaces that throw checked exceptions.

src/main/java/software/amazon/event/kafkaconnector/util · high confidence

Strict EventBridge batching with 1MB size limit

The connector now enforces strict batching rules when sending events to EventBridge: batches are limited to a maximum of 10 items and a combined payload size strictly less than 1MB. If an individual event exceeds the 1MB limit, it is isolated into its own batch and logged as a warning, allowing downstream handling (such as dropping or sending to a dead-letter topic) rather than causing a batch failure. This change introduces the \EventBridgeBatchingStrategy\ interface and its \DefaultEventBridgeBatching\ implementation to manage this logic, replacing previous behavior that may not have adhered to these specific constraints.

src/main/java/software/amazon/event/kafkaconnector/batch · high confidence

Support for custom AWS credential providers and improved default credential handling

The authentication module now allows users to supply a custom AWS credentials provider class via configuration; if the class implements Kafka's Configurable interface, it is automatically initialized with the connector's configuration. Additionally, the default credentials provider has been refactored to explicitly leverage the AWS SDK's ProfileFileSupplier for automatic credential reloading and to properly handle named profiles, replacing the previous hardcoded default behavior. The class has also been renamed from EventBridgeCredentialsProvider to EventBridgeAwsCredentialsProviderFactory to reflect its new role as a factory for various provider types.

src/main/java/software/amazon/event/kafkaconnector/auth · high confidence

Test coverage

Added tests for EventBridge credentials provider factory; Added tests for EventBridge mapping components; Added tests for StatusReporter logging behavior; Added tests for cache and S3 offloading components; Expanded test coverage for EventBridge Kafka Connector.

Dependencies

Major dependency upgrades, Java 17 migration, and AWS SDK expansion

The project has upgraded its build target to Java 17 and significantly updated its dependency landscape. The AWS SDK for Java is bumped to version 2.50.1, introducing new S3 and SQS client dependencies alongside the existing AWS CRT client. A critical security fix addresses [CVE redacted] by explicitly overriding the json-smart library version to 2.6.0, required by the upgraded JsonPath 3.0.0. Other notable updates include Jackson to 2.21.3, Logback to 1.6.1, and the removal of the Guava dependency in favor of standard Java libraries. Test dependencies have also been refreshed, including JUnit Jupiter to 6.1.2, Mockito to 5.23.0, and Testcontainers to 2.0.5.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 65 → 64 (-1.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-0.5)
  • Architecture 100 → 100 (-0.3)
  • Maturity 64 → 58 (-6.2)
  • Readiness 56 → 57 (+1.2)
  • Security 70 → 68 (-1.4)

Resolved (7)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further sole-owners (lower concentration)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Scanner failed to run — not a clean result
  • Test reliability not included

New (32)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Medium: security finding (details withheld)
  • No ADRs found
  • No assertions: startConnector (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConnectorS3IT.java)
  • No assertions: validAwsCredentialProviderClass (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validBusArn (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validBusArnGovCloud (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validDetailTypeMultiple (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validDetailTypeSingleWithVariable (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validEmptyOffloadingDefaultFieldRef (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validEmptyOffloadingDefaultS3Bucket (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validEmptyRoleArn (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validEndpointId (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validEndpointIdEmptyString (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validEndpointIdNullValue (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validID (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • No assertions: validOffloadingDefaultFieldRef (src/test/java/software/amazon/event/kafkaconnector/EventBridgeSinkConfigValidatorTest.java)
  • …and 12 more

Changes since last survey

  • 6 commits — 6 feature/other, 0 fixes

By area

  • (repo) — 6 commits

Notable commits

  • change: Merge pull request #736 from aws/dependabot/maven/org.junit.jupiter-junit-jupiter-6.1.2
  • change: Merge pull request #742 from aws/dependabot/github_actions/actions/checkout-7.0.1
  • change: Merge pull request #743 from aws/dependabot/maven/com.mycila-license-maven-plugin-5.1.1
  • change: Merge pull request #747 from aws/dependabot/maven/ch.qos.logback-logback-classic-1.6.1
  • change: Merge pull request #748 from aws/dependabot/maven/aws.java.sdk.version-2.50.1
  • change: Merge pull request #749 from aws/dependabot/maven/commons-codec-commons-codec-1.22.1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

aws/eventbridge-kafka-connector was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6f66ab323dd52fab16268d4145710803218f1fac — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.