Skip to main content
Connect your Apache Kafka clusters to enable Alex (Cloud Engineer) and Tony (Database Engineer) to monitor topic health, analyze consumer lag, and optimize streaming performance. Kafka connections are submitted as a JSON credentials file with separate API key pairs per scope (Confluent Cloud) or a bootstrap address (self-hosted).

Supported platforms

Prerequisites

  • A Confluent Cloud account with at least one Kafka environment and cluster, OR a self-hosted Kafka 2.8+ (KRaft mode) or 3.x cluster reachable from CloudThinker.
  • For Confluent Cloud: admin access to create API keys at confluent.cloud/settings/api-keys.
  • Network access from CloudThinker to the cluster’s bootstrap servers and REST endpoints.

Setup

1

Collect the cluster fields

Go to confluent.cloud, open Environments, and select the environment you want to connect — its ID (env-xxxxx) appears in the URL. Open Clusters, click your target cluster, and collect BOOTSTRAP_SERVERS, KAFKA_REST_ENDPOINT, and KAFKA_CLUSTER_ID. Keep the environment ID as KAFKA_ENV_ID.
2

Create scoped API keys

Go to Settings → API keys and click + Add API Key. Choose Service Account for production workloads, or My Account for development. Create one key pair per scope you want to enable — Kafka cluster at minimum; Schema Registry, Flink, Cloud resource management, and Tableflow optionally. Save each generated key and secret.
3

Collect optional scope fields

  • Schema Registry: in the environment, open Stream Governance → Schema Registry and collect SCHEMA_REGISTRY_ENDPOINT.
  • Flink: open Flink → Compute pools, click the target pool, and collect FLINK_COMPUTE_POOL_ID; FLINK_ENV_ID is the environment ID and FLINK_REST_ENDPOINT follows your provider and region. FLINK_ORG_ID is under Settings → Organizations.
4

Add the connection in CloudThinker

Navigate to Connections → Kafka. Create a JSON file with the fields for the scopes you enabled (see the template) and upload it in the connection form.Click Connect. CloudThinker verifies the credentials and shows a Connected status.

Scope-based credential model

Each API key and secret pair grants access to one resource scope. Start with Kafka-only fields, then add the other scopes later.

Connection field template

Fill values for your enabled scopes and remove the blocks you do not use:

Connection details

Connection fields are submitted as a JSON credentials file. Fields vary by platform and enabled scope — see the templates in Setup.
CloudThinker supports partial scope onboarding — start with Kafka-only fields and add Schema Registry, Flink, Cloud API, or Tableflow credentials later.

Required permissions

Confluent Cloud: create separate API key and secret pairs per scope, from a Service Account. Restrict Kafka ACLs to the specific topics CloudThinker needs. Cloud Management credentials require at minimum the MetricsViewer role. Self-hosted Kafka: no API keys are required. Ensure the broker’s bootstrap address is network-reachable from CloudThinker on port 9092.
Grant each API key only the scope it needs. Start with Kafka-only credentials and add additional scopes incrementally.

Agent capabilities

Once connected, Alex and Tony can:

Verify the connection

Example prompts

Troubleshooting

Verify the broker is running, that the broker port (default 9092) is open and not blocked by a firewall, and that the bootstrap address is correct and reachable from CloudThinker. For local development, ensure Kafka is bound to an accessible IP, not just 127.0.0.1.
When using partial scope onboarding, remove the entire key-value pair for unused scopes. Empty-string values cause validation errors:
This Kafka-only file is correct because the Schema Registry keys are absent entirely, not present as "".
Verify the SCHEMA_REGISTRY_ENDPOINT URL is correct and reachable from CloudThinker. For self-hosted, ensure port 8081 is open. For Confluent Cloud, confirm the Schema Registry API key has the correct permissions for your environment.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Scope-limited API keys — grant only the scopes CloudThinker needs; start with Kafka-only and add scopes incrementally
  • Network restrictions — restrict bootstrap and REST endpoints to CloudThinker’s egress IPs via security groups or firewall rules

Alex Agent

Cloud infrastructure and streaming optimization agent

AWS Connection

Setup instructions for AWS cloud resources