Skip to content
CAI
Software that uses CAICheck a score

obsidiandynamics/kafdrop

49.7

Weak · 22 September 2026

4.5k

lines of production code

Java

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Kafdrop is a web-based administration tool for Apache Kafka clusters, providing a user interface to monitor brokers, topics, and consumer lag. It enables users to inspect, search, and produce messages in various formats including Avro, Protobuf, and MessagePack, while also managing Access Control Lists and topic configurations. The system supports secure connections via SASL and SSL, and can be deployed via Docker, Kubernetes Helm charts, or systemd.

How it got here

2015–2016 — Initial scaffolding and containerization

6 changes.

The project was established with foundational build infrastructure, configuration files, and documentation to support the Kafdrop application. Early development focused on containerizing the service with Docker and modernizing the user interface by migrating to Bootstrap 4, while simultaneously upgrading core dependencies like Spring Boot and Kafka libraries.

2019 — Kafka API modernization and feature expansion

12 changes.

This period focused on modernizing the underlying Kafka client libraries and expanding supported message formats to include Avro, Protobuf, and MessagePack. Significant enhancements were made to the user interface and configuration flexibility, introducing a Helm chart, INI file support, ACL management views, and a dark theme. The work also included adding security filters, health check endpoints, and comprehensive unit tests to stabilize these new capabilities.

2020–2025 — UI overhaul and deployment support

5 changes.

This period focused on a comprehensive modernization of the Kafdrop user interface, introducing new FreeMarker templates for cluster and topic management while standardizing the frontend with Bootstrap 4 and jQuery. Concurrently, the project enhanced its reliability and deployment capabilities by adding integration tests using Testcontainers and providing systemd unit files for Linux service management.

Features

Add support for Avro, Protobuf, and MessagePack message formats

Kafdrop now supports deserializing and serializing messages in Avro, Protobuf, and MessagePack formats, in addition to the existing default and integer key formats. This change introduces a new serialization/deserialization utility layer in the \kafdrop.util\ package, including specific handlers for Avro (with Schema Registry integration), Protobuf (supporting descriptor files and the \google.protobuf.Any\ type), and MessagePack. Users can now view and produce messages in these structured formats, with Protobuf messages defaulting to a collapsed JSON view for readability.

src/main/java/kafdrop/util · high confidence

Add systemd unit and startup script for Linux deployment

New users on Linux can now deploy KafDrop using a provided systemd unit file, a startup script, and installation instructions located in the contrib/systemd directory. This starter kit simplifies the process of running KafDrop as a managed service, handling common configurations such as user permissions, network binding, and service restart policies, thereby saving time compared to building a deployment from scratch.

contrib · high confidence

Added Darkly Bootswatch theme with embedded fonts

Users can now apply the 'Darkly' theme variant, which provides a dark UI with cyan accents and Lato typography. This change introduces a new theme configuration that embeds Google Fonts locally into the application's static CSS folder, ensuring consistent rendering without external network dependencies for font loading.

theme · high confidence

Added support for loading configuration from INI files

Kafdrop now supports reading configuration settings from INI-style files. This change introduces a new \kafdrop.config.ini\ package containing \IniFileReader\ to parse INI syntax (including sections, key-value pairs, comments, and line continuations), \IniFileProperties\ to hold the parsed data, and \IniFilePropertySource\ to integrate these properties into the Spring environment, allowing users to define application settings in an INI format.

src/main/java/kafdrop/config/ini · high confidence

Initial Docker containerization for Kafdrop 4

Introduces the first Docker support for the application, providing a Dockerfile based on the eclipse-temurin:25.0.4-jdk image and a startup script (kafdrop.sh) that handles environment-based configuration for Kafka properties, truststores, and keystores via base64 decoding, while exposing port 9000 and accepting command-line arguments.

src/main/docker · high confidence

Initial Helm chart release for Kafdrop

This change introduces the first version of the Helm chart for the Kafdrop application, providing the necessary Kubernetes manifests to deploy the service. The chart includes templates for a Deployment (configurable via values for JVM options, Kafka connection details, and context paths), a Service (supporting ClusterIP, NodePort, and LoadBalancer types with optional nodePort specification), and an Ingress resource (with logic to handle API version differences across Kubernetes versions 1.14–1.22+). It also adds helper templates for name generation and capability detection, a NOTES.txt file to guide users on accessing the application URL, and support for features like pod annotations, host aliases, and protobuf descriptor mounting.

chart, chart/templates · high confidence

Initial configuration and resource setup for Kafdrop

This change introduces the foundational configuration files for the application. It adds application.yml to define the server port (defaulting to 9000), servlet context path, SSL/TLS settings, Spring Boot management endpoints, and Kafka connection parameters (broker, SASL, truststore). It also includes log4j.properties and log4j2.properties to configure console logging patterns and log levels for Kafdrop and Kafka components, alongside messages.properties for standard validation error messages.

src/main/resources · high confidence

Initial project scaffolding with build and documentation assets

The repository is initialized with the core assets required to build and understand the project. This includes an .editorconfig to enforce consistent Java code formatting, a .gitignore to exclude IDE and build artifacts, and a CONTRIBUTING.md outlining the coding style and community guidelines. The Maven Wrapper (mvnw/mvnw.cmd) is added to ensure reproducible builds using a specific Maven version, and the README.md provides comprehensive documentation on features, requirements, and instructions for running the application via JAR, Docker, or Kubernetes.

(repo-wide) · high confidence

Introduction of new Kafdrop UI templates for cluster, topic, and message management

The application now includes a comprehensive set of new FreeMarker templates that define the user interface for managing Kafka clusters and topics. Users can now view a cluster overview with broker and topic summaries, inspect detailed broker information, and manage Access Control Lists (ACLs). Topic management features include a dedicated detail page showing partition health and consumer lag, the ability to create new topics, and the option to delete existing ones. Message interaction has been significantly enhanced with a new message inspector that supports viewing, searching, and sending messages (including headers), as well as formatting JSON and handling Protobuf message types.

src/main/resources/templates · high confidence

New ACL view and refined topic management controls

Kafdrop now includes a dedicated ACL overview page, exposing Access Control List details via the new AclController and the /acl endpoint. Topic management has been updated to respect configuration flags: the TopicController now checks the topic.createEnabled and topic.deleteEnabled settings before allowing creation or deletion actions, ensuring these operations are only available when explicitly permitted by the application configuration.

src/main/java/kafdrop/controller · high confidence

New configuration classes for CORS, health checks, and Kafka connectivity

This change introduces a suite of new configuration classes in the kafdrop.config package to enhance application setup and monitoring. Users can now customize Cross-Origin Resource Sharing (CORS) behavior via properties like cors.enabled and cors.allowOrigins. A new HealthCheckConfiguration component exposes application health status through JMX and actuator endpoints. Kafka connectivity is now managed by KafkaConfiguration, which supports loading broker settings, security protocols, and external property files from the classpath or file system. Additional configurations include MessageFormatConfiguration for default message/key formats, ProtobufDescriptorConfiguration for loading .desc files, SchemaRegistryConfiguration for schema registry connections, and OASConfiguration for OpenAPI documentation.

src/main/java/kafdrop/config · high confidence

New model classes for ACLs, brokers, and consumer lag

The application now includes new view objects (VOs) to support displaying Access Control Lists (AclVO), broker details including rack and controller status (BrokerVO), and per-partition consumer lag calculations (ConsumerPartitionVO, ConsumerTopicVO, ConsumerVO). Additionally, cluster summary metrics (ClusterSummaryVO) and topic partition details with offline replica visibility (TopicPartitionVO) are now available in the model layer.

src/main/java/kafdrop/model · high confidence

Behavioural changes

Block HTTP TRACK method and add custom environment setup

The application now includes a filter that blocks the HTTP TRACK method, returning a 405 Method Not Allowed error to prevent potential security issues. Additionally, the startup process now supports loading custom INI configuration files from a specified directory and allows overriding logging configuration via environment properties.

src/main/java/kafdrop · high confidence

Migrate UI styling to Bootstrap 4 with Bootswatch Darkly theme

The application's visual presentation has been updated by replacing the previous custom CSS framework with Bootstrap 4.3.1 and the Bootswatch Darkly theme. This change introduces a dark color scheme (dark backgrounds with light text) and modernizes the layout system to use Bootstrap's flexbox-based grid, affecting the appearance of tables, forms, buttons, and navigation elements across the interface.

src/main/resources/static/css · high confidence

Replaced legacy Kafka clients with high-level admin, consumer, and producer services

The service layer has been rewritten to use the modern Kafka Admin, Consumer, and Producer APIs, replacing the previous implementation. This change introduces dedicated services for cluster administration (including topic creation and deletion), message consumption (with support for searching, header inspection, and transaction markers), and message production (allowing manual message insertion with headers). It also adds robust error handling for authorization and version incompatibility issues, and introduces a BuildInfo service to display version and build time on the cluster overview.

src/main/java/kafdrop/service · high confidence

Standardized base template with Bootstrap 4 and jQuery 3.5.1

The application now uses a new shared FreeMarker template (template.ftlh) that serves as the base layout for all pages. This change updates the frontend dependencies to Bootstrap 4.5.3 and jQuery 3.5.1 (slim version), adds a favicon link, and includes Font Awesome for icons. Users will see the updated styling and layout provided by these newer library versions across the interface.

src/main/resources/templates/lib · high confidence

Test coverage

Added generated Protobuf test fixtures for Person message; Added integration tests with Testcontainers for Kafka; Added test resources for Protobuf and SASL\_SSL configuration; Added unit tests for ConsumerPartitionVO and TopicPartitionVO models.

Dependencies

Added Maven Wrapper with version 3.3.4 and Maven 3.9.16

The project now includes a Maven Wrapper (\.mvn/wrapper/maven-wrapper.properties\) to ensure consistent builds across environments. The wrapper is configured to use version 3.3.4 and will download Apache Maven 3.9.16 from the official Maven repository.

.mvn · high confidence

Upgrade to Bootstrap 4.5.3

The frontend static assets have been updated to use Bootstrap v4.5.3, replacing the previous version. This upgrade brings the latest bug fixes and features from the Bootstrap framework to the application's user interface components.

src/main/resources/static/js · high confidence

Upgrade to Spring Boot 4.1.1 and update core dependencies

The project's build manifest has been updated to use Spring Boot 4.1.1 as the parent, bringing in the latest framework features and security patches. Key library versions have been bumped, including Protobuf to 3.25.9, Testcontainers to 2.0.5, Kafka libraries to 8.3.2, and Avro to 1.12.2. Additionally, the project now targets multi-architecture builds (linux/amd64, linux/arm64) and includes specific exclusions for transitive dependencies like lz4-java and slf4j-log4j12 to prevent conflicts.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 50 (-10.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 97 (+2.4)
  • Architecture 100 → 91 (-9.0)
  • Maturity 56 → 54 (-2.1)
  • Readiness 59 → 61 (+2.1)
  • Security 52 → 56 (+3.4)
  • Accessibility 37 (new)

Resolved (30)

  • (anonymous) (cognitive 24) (src/main/resources/static/js/powerFilter.js)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (5 lines × 2) (src/main/java/kafdrop/controller/MessageController.java)
  • Duplicated block (6 lines × 2) (src/main/java/kafdrop/controller/MessageController.java)
  • Duplicated block (6 lines × 2) (src/main/java/kafdrop/service/KafkaMonitorImpl.java)
  • Duplicated block (7 lines × 2) (src/main/java/kafdrop/controller/MessageController.java)
  • Duplicated block (7 lines × 2) (src/main/java/kafdrop/util/AvroMessageDeserializer.java)
  • Duplicated block (9 lines × 2) (src/main/java/kafdrop/service/KafkaMonitorImpl.java)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0005 (src/main/docker/Dockerfile)
  • Medium IaC: CKV_DOCKER_3 (src/main/docker/Dockerfile)
  • …and 10 more

New (38)

  • (anonymous) (cognitive 25) (src/main/resources/static/js/powerFilter.js)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (17 lines × 2) (src/main/java/kafdrop/service/KafkaMonitorImpl.java)
  • Duplicated block (5 lines × 2) (src/main/java/kafdrop/controller/MessageController.java)
  • Duplicated block (5 lines × 2) (src/main/java/kafdrop/controller/MessageController.java)
  • Duplicated block (6 lines × 2) (src/main/java/kafdrop/util/AvroMessageDeserializer.java)
  • Duplicated block (8–9 lines × 2) (src/main/java/kafdrop/controller/MessageController.java)
  • Further sole-owners (lower concentration)
  • High IaC: WD-COMPOSE-0002 (docker-compose/kafka-kafdrop/docker-compose.yaml)
  • High IaC: WD-COMPOSE-0002 (docker-compose/kafka-kafdrop/docker-compose.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 18 more

Changes since last survey

  • 25 commits — 24 feature/other, 1 fixes

By area

  • (root) — 17 commits
  • src/main — 5 commits
  • .github/workflows — 2 commits
  • .mvn/wrapper — 1 commit

Notable commits

  • fix: fix: make one offset request (#868)
  • change: Added feat allow user to add header to message and duplicate message (#856)
  • change: Show highest last offset and its partition on topic detail (#864)
  • change: build(deps): bump actions/setup-java from 5 to 6 (#879)
  • change: build(deps): bump actions/stale from 10 to 11 (#862)
  • change: build(deps): bump at.yawk.lz4:lz4-java from 1.11.1 to 1.11.2 (#874)
  • change: build(deps): bump at.yawk.lz4:lz4-java from 1.11.2 to 1.11.3 (#885)
  • change: build(deps): bump eclipse-temurin in main/docker (#878)
  • change: build(deps): bump kafka-libs.version from 8.2.1 to 8.3.1 (#857)
  • change: build(deps): bump kafka-libs.version from 8.3.1 to 8.3.2 (#886)
  • change: build(deps): bump org.apache.avro:avro from 1.12.1 to 1.12.2 (#872)
  • change: build(deps): bump org.apache.maven.wrapper:maven-wrapper (#875)
  • change: build(deps): bump org.apache.maven:apache-maven from 3.9.8 to 3.9.16 (#871)
  • change: build(deps): bump org.msgpack:msgpack-core from 0.9.11 to 0.9.12 (#850)
  • change: build(deps): bump org.projectlombok:lombok from 1.18.46 to 1.18.48 (#883)
  • change: build(deps): bump org.springdoc:springdoc-openapi-starter-webmvc-ui (#869)
  • change: build(deps): bump org.springdoc:springdoc-openapi-starter-webmvc-ui (#884)
  • change: build(deps): bump org.springframework.boot:spring-boot-starter-parent (#876)
  • change: build(deps-dev): bump io.fabric8:docker-maven-plugin (#873)
  • change: build(deps-dev): bump org.apache.maven.plugins:maven-compiler-plugin (#882)
  • …and 5 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

obsidiandynamics/kafdrop was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit fc60f5ec6582dfe69bd2fbcef693bb600d4379fc — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.