Supported platforms
Prerequisites
- A Confluent Cloud account with at least one Kafka environment and cluster, OR a self-hosted Kafka 2.8+ (KRaft mode) or 3.x cluster reachable from CloudThinker.
- For Confluent Cloud: admin access to create API keys at confluent.cloud/settings/api-keys.
- Network access from CloudThinker to the cluster’s bootstrap servers and REST endpoints.
Setup
- Confluent Cloud
- Self-hosted Kafka
1
Collect the cluster fields
Go to confluent.cloud, open Environments, and select the environment you want to connect — its ID (
env-xxxxx) appears in the URL. Open Clusters, click your target cluster, and collect BOOTSTRAP_SERVERS, KAFKA_REST_ENDPOINT, and KAFKA_CLUSTER_ID. Keep the environment ID as KAFKA_ENV_ID.2
Create scoped API keys
Go to Settings → API keys and click + Add API Key. Choose Service Account for production workloads, or My Account for development. Create one key pair per scope you want to enable — Kafka cluster at minimum; Schema Registry, Flink, Cloud resource management, and Tableflow optionally. Save each generated key and secret.
3
Collect optional scope fields
- Schema Registry: in the environment, open Stream Governance → Schema Registry and collect
SCHEMA_REGISTRY_ENDPOINT. - Flink: open Flink → Compute pools, click the target pool, and collect
FLINK_COMPUTE_POOL_ID;FLINK_ENV_IDis the environment ID andFLINK_REST_ENDPOINTfollows your provider and region.FLINK_ORG_IDis under Settings → Organizations.
4
Add the connection in CloudThinker
Navigate to Connections → Kafka. Create a JSON file with the fields for the scopes you enabled (see the template) and upload it in the connection form.Click Connect. CloudThinker verifies the credentials and shows a Connected status.
Scope-based credential model
Each API key and secret pair grants access to one resource scope. Start with Kafka-only fields, then add the other scopes later.Connection field template
Fill values for your enabled scopes and remove the blocks you do not use:Connection details
Connection fields are submitted as a JSON credentials file. Fields vary by platform and enabled scope — see the templates in Setup.CloudThinker supports partial scope onboarding — start with Kafka-only fields and add Schema Registry, Flink, Cloud API, or Tableflow credentials later.
Required permissions
Confluent Cloud: create separate API key and secret pairs per scope, from a Service Account. Restrict Kafka ACLs to the specific topics CloudThinker needs. Cloud Management credentials require at minimum the MetricsViewer role. Self-hosted Kafka: no API keys are required. Ensure the broker’s bootstrap address is network-reachable from CloudThinker on port 9092.Agent capabilities
Once connected, Alex and Tony can:Verify the connection
Example prompts
Troubleshooting
Connection refused or timeout
Connection refused or timeout
Verify the broker is running, that the broker port (default 9092) is open and not blocked by a firewall, and that the bootstrap address is correct and reachable from CloudThinker. For local development, ensure Kafka is bound to an accessible IP, not just
127.0.0.1.Validation errors on a partial-scope JSON file
Validation errors on a partial-scope JSON file
When using partial scope onboarding, remove the entire key-value pair for unused scopes. Empty-string values cause validation errors:This Kafka-only file is correct because the Schema Registry keys are absent entirely, not present as
"".Schema Registry connection fails
Schema Registry connection fails
Verify the
SCHEMA_REGISTRY_ENDPOINT URL is correct and reachable from CloudThinker. For self-hosted, ensure port 8081 is open. For Confluent Cloud, confirm the Schema Registry API key has the correct permissions for your environment.Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Scope-limited API keys — grant only the scopes CloudThinker needs; start with Kafka-only and add scopes incrementally
- Network restrictions — restrict bootstrap and REST endpoints to CloudThinker’s egress IPs via security groups or firewall rules
Related
Alex Agent
Cloud infrastructure and streaming optimization agent
AWS Connection
Setup instructions for AWS cloud resources