[{"data":1,"prerenderedAt":1234},["ShallowReactive",2],{"docs-nav":3,"docs-page-\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster":133},[4,27,53,68,83,98,117],{"slug":5,"label":6,"pages":7},"get-started","Get Started",[8,12,17,22],{"path":9,"title":10,"order":11},"\u002Fdocs","Welcome",0,{"path":13,"title":14,"navTitle":15,"order":16},"\u002Fdocs\u002Fget-started\u002Fquickstart","Quickstart",null,1,{"path":18,"title":19,"navTitle":20,"order":21},"\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster","Connecting to a Kafka Cluster","Clusters",2,{"path":23,"title":24,"navTitle":25,"order":26},"\u002Fdocs\u002Fget-started\u002Flicense","Licensing and Activation","License",3,{"slug":28,"label":29,"pages":30},"console","Console",[31,35,39,43,48],{"path":32,"title":33,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsole\u002Foverview","Produce and Consume Messages in the Kafka Console","Overview",{"path":36,"title":37,"navTitle":38,"order":21},"\u002Fdocs\u002Fconsole\u002Fconsuming-messages","Kafka Consumer: Reading Messages from a Topic","Consuming",{"path":40,"title":41,"navTitle":42,"order":26},"\u002Fdocs\u002Fconsole\u002Fdecoding-messages","Decoding Kafka Avro and Protobuf Messages","Decoding",{"path":44,"title":45,"navTitle":46,"order":47},"\u002Fdocs\u002Fconsole\u002Fproducing-messages","Kafka Producer: Sending Messages to a Topic","Producing",4,{"path":49,"title":50,"navTitle":51,"order":52},"\u002Fdocs\u002Fconsole\u002Freplay-forward-and-export","Replay and Export Kafka Messages","Replay & export",5,{"slug":54,"label":55,"pages":56},"topics","Topics",[57,60,64],{"path":58,"title":59,"navTitle":34,"order":16},"\u002Fdocs\u002Ftopics\u002Foverview","Browse and Inspect Kafka Topics",{"path":61,"title":62,"navTitle":63,"order":21},"\u002Fdocs\u002Ftopics\u002Fcreate-a-topic","Create a Kafka Topic: Partitions, Replication, and Retention","Create a topic",{"path":65,"title":66,"navTitle":67,"order":26},"\u002Fdocs\u002Ftopics\u002Fpartitions-and-records","Adding Kafka Partitions and Deleting Records","Partitions & records",{"slug":69,"label":70,"pages":71},"schema-registry","Schema Registry",[72,75,79],{"path":73,"title":74,"navTitle":34,"order":16},"\u002Fdocs\u002Fschema-registry\u002Foverview","Browse Kafka Schema Registry Subjects and Versions",{"path":76,"title":77,"navTitle":78,"order":21},"\u002Fdocs\u002Fschema-registry\u002Fnew-versions","Register Kafka Schemas and Publish New Versions","New versions",{"path":80,"title":81,"navTitle":82,"order":26},"\u002Fdocs\u002Fschema-registry\u002Fmock-and-lab","Avro Schema Validator and Mock Data Generator","Mock & Lab",{"slug":84,"label":85,"pages":86},"consumer-groups","Consumer Groups",[87,90,94],{"path":88,"title":89,"navTitle":34,"order":16},"\u002Fdocs\u002Fconsumer-groups\u002Foverview","Browse Kafka Consumer Groups and Assignments",{"path":91,"title":92,"navTitle":93,"order":21},"\u002Fdocs\u002Fconsumer-groups\u002Flag","Monitor Kafka Consumer Lag","Lag",{"path":95,"title":96,"navTitle":97,"order":26},"\u002Fdocs\u002Fconsumer-groups\u002Freset-offsets","Reset Kafka Consumer Group Offsets","Reset offsets",{"slug":99,"label":100,"pages":101},"data-clone","Data Clone",[102,105,109,113],{"path":103,"title":104,"navTitle":34,"order":16},"\u002Fdocs\u002Fdata-clone\u002Foverview","Clone Kafka Topics Between Clusters",{"path":106,"title":107,"navTitle":108,"order":21},"\u002Fdocs\u002Fdata-clone\u002Fscope-and-range","Configure Kafka Topic Cloning","Scope & range",{"path":110,"title":111,"navTitle":112,"order":26},"\u002Fdocs\u002Fdata-clone\u002Fmasking","Mask Sensitive Data in Kafka Messages","Masking",{"path":114,"title":115,"navTitle":116,"order":47},"\u002Fdocs\u002Fdata-clone\u002Fpre-flight","Run Pre-flight Checks Before a Kafka Data Clone","Pre-flight",{"slug":118,"label":119,"pages":120},"operate","Operate",[121,125,129],{"path":122,"title":123,"navTitle":124,"order":16},"\u002Fdocs\u002Foperate\u002Fbrokers","Inspect Kafka Brokers and Cluster Configuration","Brokers",{"path":126,"title":127,"navTitle":128,"order":21},"\u002Fdocs\u002Foperate\u002Faccess-control","Inspect Kafka ACLs and Simulate Access","Access Control",{"path":130,"title":131,"navTitle":132,"order":26},"\u002Fdocs\u002Foperate\u002Factivity-logs","Review Kafka Changes in Kafma Activity Logs","Activity Logs",{"id":134,"title":19,"body":135,"description":1226,"extension":1227,"lastUpdated":1228,"meta":1229,"navTitle":20,"navigation":800,"order":21,"path":18,"seo":1230,"sitemap":1231,"stem":1232,"__hash__":1233},"docs\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster.md",{"type":136,"value":137,"toc":1202},"minimark",[138,142,147,166,175,240,245,255,259,269,273,280,290,293,297,312,315,318,374,377,386,438,441,449,464,471,474,490,493,501,508,524,531,539,545,696,703,842,855,859,870,874,877,897,900,904,910,920,923,925,928,937,940,946,965,972,980,998,1005,1009,1015,1021,1025,1031,1142,1145,1149,1165,1171,1177,1181,1198],[139,140,141],"p",{},"Connect Kafma with your cluster's bootstrap servers and authentication, then\noptionally add a Schema Registry. Connection settings stay on your device and\nare used only to reach the endpoints you configure.",[143,144,146],"h2",{"id":145},"configure-a-connection","Configure a connection",[139,148,149,150,154,155,158,159,161,162,165],{},"Open ",[151,152,153],"strong",{},"New Cluster"," from Welcome or the Clusters page. Complete ",[151,156,157],{},"General",",\nthen add the optional ",[151,160,70],{}," and ",[151,163,164],{},"Advanced"," settings if needed.",[139,167,168],{},[169,170],"img",{"alt":171,"height":172,"src":173,"width":174},"The Kafma New Cluster form with the General card expanded and the Schema Registry and Advanced cards collapsed",1440,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Fget-started\u002Fquickstart\u002Fadd-connection.png",1554,[176,177,178,191],"table",{},[179,180,181],"thead",{},[182,183,184,188],"tr",{},[185,186,187],"th",{},"Field",[185,189,190],{},"What to enter",[192,193,194,203,216,224,232],"tbody",{},[182,195,196,200],{},[197,198,199],"td",{},"Cluster Name",[197,201,202],{},"A unique name for the connection",[182,204,205,208],{},[197,206,207],{},"Bootstrap Servers",[197,209,210,211,215],{},"One or more ",[212,213,214],"code",{},"host:port"," addresses",[182,217,218,221],{},[197,219,220],{},"Environment",[197,222,223],{},"Production, Staging, Dev, or Other. Defaults to Dev",[182,225,226,229],{},[197,227,228],{},"Read-Only",[197,230,231],{},"Blocks writes through Kafma",[182,233,234,237],{},[197,235,236],{},"Authentication",[197,238,239],{},"None, SASL, SSL, or AWS IAM",[241,242,244],"h3",{"id":243},"bootstrap-servers","Bootstrap servers",[139,246,247,248,250,251,254],{},"Enter one or more brokers as ",[212,249,214],{},". You can paste a comma-, semicolon-, or\nwhitespace-separated list; Kafma removes duplicates and highlights invalid\nentries. One reachable broker is enough, but adding several improves bootstrap\navailability. Use brackets for IPv6, such as ",[212,252,253],{},"[::1]:9092",".",[241,256,258],{"id":257},"environment-and-read-only","Environment and read-only",[139,260,261,262,265,266,268],{},"Choose an environment to identify the cluster throughout Kafma. Selecting\n",[151,263,264],{},"Production"," enables ",[151,267,228],{}," automatically; turn it off only when you\nintend to write. Read-Only blocks Kafka and Schema Registry writes made through\nKafma.",[241,270,272],{"id":271},"credentials","Credentials",[139,274,275,276,279],{},"Kafma stores credentials locally through Electron ",[212,277,278],{},"safeStorage","; the connection\nconfiguration stores references instead of plaintext. Available protection\ndepends on your operating system and desktop environment.",[281,282,288],"pre",{"className":283,"code":285,"language":286,"meta":287},[284],"language-text","{{env:KAFKA_PASSWORD}}\n","text","",[212,289,285],{"__ignoreMap":287},[139,291,292],{},"To avoid storing a secret, enter an environment-variable reference in any secret\nfield. Kafma resolves it when connecting and does not store its value.",[241,294,296],{"id":295},"advanced-settings","Advanced settings",[139,298,299,300,303,304,307,308,311],{},"Keep ",[151,301,302],{},"Kafka Version"," on ",[151,305,306],{},"Auto Detect"," unless compatibility requires an\nexplicit version. Use ",[151,309,310],{},"Configuration"," for additional Kafka client properties.",[143,313,236],{"id":314},"authentication",[139,316,317],{},"Choose the method required by your broker:",[176,319,320,330],{},[179,321,322],{},[182,323,324,327],{},[185,325,326],{},"Method",[185,328,329],{},"Use for",[192,331,332,340,358,366],{},[182,333,334,337],{},[197,335,336],{},"None",[197,338,339],{},"Local or development brokers without authentication",[182,341,342,345],{},[197,343,344],{},"SASL",[197,346,347,350,351,354,355],{},[212,348,349],{},"PLAIN",", ",[212,352,353],{},"SCRAM-SHA-256\u002F512",", or ",[212,356,357],{},"OAUTHBEARER",[182,359,360,363],{},[197,361,362],{},"SSL",[197,364,365],{},"TLS or mTLS with client certificates",[182,367,368,371],{},[197,369,370],{},"AWS IAM",[197,372,373],{},"Amazon MSK with IAM access control",[241,375,344],{"id":376},"sasl",[139,378,379,382,383,254],{},[151,380,381],{},"Use TLS"," is on by default. Turn it off only when the broker requires\n",[212,384,385],{},"SASL_PLAINTEXT",[176,387,388,398],{},[179,389,390],{},[182,391,392,395],{},[185,393,394],{},"Mechanism",[185,396,397],{},"Typical use",[192,399,400,409,419,429],{},[182,401,402,406],{},[197,403,404],{},[212,405,349],{},[197,407,408],{},"Confluent Cloud and other managed brokers",[182,410,411,416],{},[197,412,413],{},[212,414,415],{},"SCRAM-SHA-256",[197,417,418],{},"Brokers configured for SCRAM-256",[182,420,421,426],{},[197,422,423],{},[212,424,425],{},"SCRAM-SHA-512",[197,427,428],{},"Brokers configured for SCRAM-512",[182,430,431,435],{},[197,432,433],{},[212,434,357],{},[197,436,437],{},"OAuth\u002FOIDC-backed brokers",[139,439,440],{},"Match the mechanism configured for your credentials; the two SCRAM variants are\nnot interchangeable.",[139,442,443],{},[169,444],{"alt":445,"height":446,"src":447,"width":448},"Kafma's SASL authentication settings for a Kafka cluster: Use TLS, mechanism, credentials, and an optional CA certificate",776,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster\u002Fauth-sasl.png",1398,[139,450,451,453,454,456,457,460,461,254],{},[212,452,349],{}," and SCRAM use a username and password. ",[212,455,357],{}," accepts either\n",[151,458,459],{},"Client Credentials",", which Kafma exchanges and refreshes automatically, or a\n",[151,462,463],{},"Static Token",[139,465,466,467,470],{},"With TLS enabled, leave ",[151,468,469],{},"CA Cert"," blank to use the system trust store, or\nprovide a PEM certificate for a private CA.",[241,472,362],{"id":473},"ssl",[139,475,476,477,479,480,482,483,161,486,489],{},"Use ",[151,478,362],{}," for TLS or mTLS. Broker certificate verification is on by default;\nleave ",[151,481,469],{}," blank to use the system trust store, or provide a private CA.\nFor mTLS, provide a matching ",[151,484,485],{},"Client Key",[151,487,488],{},"Client Cert"," as PEM. Private\nkeys must be unencrypted; Kafma accepts PKCS#8, RSA, and EC PEM keys.",[241,491,370],{"id":492},"aws-iam",[139,494,495],{},[169,496],{"alt":497,"height":498,"src":499,"width":500},"Kafma's AWS IAM authentication settings for an Amazon MSK cluster: credential source, region, profile name, and assume role ARN",728,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster\u002Fauth-aws-iam.png",1390,[139,502,503,504,507],{},"Set ",[151,505,506],{},"AWS Region"," to the cluster's region, then choose a credential source:",[509,510,511,518],"ul",{},[512,513,514,517],"li",{},[151,515,516],{},"Default credential chain"," — uses the AWS SDK credential chain; optionally\nspecify a profile.",[512,519,520,523],{},[151,521,522],{},"Manual"," — enter an access key ID and secret access key, plus a session\ntoken for temporary credentials.",[139,525,526,527,530],{},"Add an ",[151,528,529],{},"Assume role ARN"," if Kafma should assume a role before signing\nrequests.",[241,532,534,535,538],{"id":533},"map-clientproperties-settings","Map ",[212,536,537],{},"client.properties"," settings",[139,540,541,542,544],{},"If the cluster already works from the CLI, map its ",[212,543,537],{}," settings\nto Kafma:",[176,546,547,559],{},[179,548,549],{},[182,550,551,556],{},[185,552,553,554],{},"In ",[212,555,537],{},[185,557,558],{},"In Kafma",[192,560,561,572,584,596,607,626,637,660,672,685],{},[182,562,563,568],{},[197,564,565],{},[212,566,567],{},"security.protocol=PLAINTEXT",[197,569,570],{},[151,571,336],{},[182,573,574,579],{},[197,575,576],{},[212,577,578],{},"security.protocol=SASL_SSL",[197,580,581,583],{},[151,582,344],{},", Use TLS on",[182,585,586,591],{},[197,587,588],{},[212,589,590],{},"security.protocol=SASL_PLAINTEXT",[197,592,593,595],{},[151,594,344],{},", Use TLS off",[182,597,598,603],{},[197,599,600],{},[212,601,602],{},"security.protocol=SSL",[197,604,605],{},[151,606,362],{},[182,608,609,621],{},[197,610,611,614,615,614,617,614,619],{},[212,612,613],{},"sasl.mechanism=PLAIN"," \u002F ",[212,616,415],{},[212,618,425],{},[212,620,357],{},[197,622,623,624],{},"Select the matching ",[151,625,394],{},[182,627,628,633],{},[197,629,630],{},[212,631,632],{},"sasl.mechanism=AWS_MSK_IAM",[197,634,635],{},[151,636,370],{},[182,638,639,652],{},[197,640,641,644,645,648,649],{},[212,642,643],{},"username","\u002F",[212,646,647],{},"password"," in ",[212,650,651],{},"sasl.jaas.config",[197,653,654,161,657],{},[151,655,656],{},"Username",[151,658,659],{},"Password",[182,661,662,667],{},[197,663,664],{},[212,665,666],{},"ssl.truststore.location",[197,668,669,671],{},[151,670,469],{},", as PEM",[182,673,674,679],{},[197,675,676],{},[212,677,678],{},"ssl.keystore.location",[197,680,681,161,683,671],{},[151,682,485],{},[151,684,488],{},[182,686,687,693],{},[197,688,689,692],{},[212,690,691],{},"ssl.endpoint.identification.algorithm="," (empty)",[197,694,695],{},"No direct equivalent — see below",[139,697,698,699,702],{},"Java ",[212,700,701],{},".jks"," files must be converted to PEM before use:",[281,704,708],{"className":705,"code":706,"language":707,"meta":287,"style":287},"language-bash shiki shiki-themes kafma-dark","# Client key and certificate, out of the keystore\nkeytool -importkeystore -srckeystore kafka.client.keystore.jks \\\n  -destkeystore client.p12 -deststoretype PKCS12\nopenssl pkcs12 -in client.p12 -nokeys -out client-cert.pem\nopenssl pkcs12 -in client.p12 -nodes -nocerts -out client-key.pem\n\n# CA certificate, out of the truststore\nkeytool -exportcert -rfc -alias caroot \\\n  -keystore kafka.client.truststore.jks -file ca-cert.pem\n","bash",[212,709,710,718,738,752,774,795,802,808,827],{"__ignoreMap":287},[711,712,714],"span",{"class":713,"line":16},"line",[711,715,717],{"class":716},"sA0dC","# Client key and certificate, out of the keystore\n",[711,719,720,724,728,731,735],{"class":713,"line":21},[711,721,723],{"class":722},"sLaUg","keytool",[711,725,727],{"class":726},"sUqoa"," -importkeystore",[711,729,730],{"class":726}," -srckeystore",[711,732,734],{"class":733},"sJl8Q"," kafka.client.keystore.jks",[711,736,737],{"class":733}," \\\n",[711,739,740,743,746,749],{"class":713,"line":26},[711,741,742],{"class":726},"  -destkeystore",[711,744,745],{"class":733}," client.p12",[711,747,748],{"class":726}," -deststoretype",[711,750,751],{"class":733}," PKCS12\n",[711,753,754,757,760,763,765,768,771],{"class":713,"line":47},[711,755,756],{"class":722},"openssl",[711,758,759],{"class":733}," pkcs12",[711,761,762],{"class":726}," -in",[711,764,745],{"class":733},[711,766,767],{"class":726}," -nokeys",[711,769,770],{"class":726}," -out",[711,772,773],{"class":733}," client-cert.pem\n",[711,775,776,778,780,782,784,787,790,792],{"class":713,"line":52},[711,777,756],{"class":722},[711,779,759],{"class":733},[711,781,762],{"class":726},[711,783,745],{"class":733},[711,785,786],{"class":726}," -nodes",[711,788,789],{"class":726}," -nocerts",[711,791,770],{"class":726},[711,793,794],{"class":733}," client-key.pem\n",[711,796,798],{"class":713,"line":797},6,[711,799,801],{"emptyLinePlaceholder":800},true,"\n",[711,803,805],{"class":713,"line":804},7,[711,806,807],{"class":716},"# CA certificate, out of the truststore\n",[711,809,811,813,816,819,822,825],{"class":713,"line":810},8,[711,812,723],{"class":722},[711,814,815],{"class":726}," -exportcert",[711,817,818],{"class":726}," -rfc",[711,820,821],{"class":726}," -alias",[711,823,824],{"class":733}," caroot",[711,826,737],{"class":733},[711,828,830,833,836,839],{"class":713,"line":829},9,[711,831,832],{"class":726},"  -keystore",[711,834,835],{"class":733}," kafka.client.truststore.jks",[711,837,838],{"class":726}," -file",[711,840,841],{"class":733}," ca-cert.pem\n",[139,843,844,847,848,850,851,854],{},[212,845,846],{},"-nodes"," produces the unencrypted private key Kafma requires. For a private CA,\nprovide ",[151,849,469],{}," instead of disabling certificate verification. Turning off\n",[151,852,853],{},"Verify Broker Cert"," disables both hostname and certificate-chain validation.",[143,856,858],{"id":857},"confluent-cloud-and-aws-msk","Confluent Cloud and AWS MSK",[139,860,861,862,864,865,161,867,869],{},"Both shortcuts open ",[151,863,153],{}," with ",[151,866,264],{},[151,868,228],{},"\nenabled. Review the prefilled settings, and turn off Read-Only only if you\nintend to write.",[241,871,873],{"id":872},"confluent-cloud","Confluent Cloud",[139,875,876],{},"The preset selects SASL\u002FPLAIN over TLS and opens Schema Registry with Basic\nAuth.",[878,879,880,885,892],"ol",{},[512,881,882,884],{},[151,883,207],{}," — copy the Kafka endpoint from Confluent Cloud.",[512,886,887,161,889,891],{},[151,888,656],{},[151,890,659],{}," — enter the cluster API key and secret.",[512,893,894,896],{},[151,895,70],{}," — optionally enter its URL and its own API key and\nsecret.",[139,898,899],{},"Kafka and Schema Registry use separate credentials; a cluster API key cannot\nauthenticate with Schema Registry.",[241,901,903],{"id":902},"aws-msk","AWS MSK",[139,905,906,907,909],{},"The preset selects ",[151,908,370],{}," with the default credential chain.",[139,911,912,913,916,917,919],{},"Copy the IAM bootstrap servers from ",[151,914,915],{},"View client information"," in the MSK\nconsole, then set ",[151,918,506],{}," to the cluster's region. Use the IAM endpoint,\nnot the TLS-only endpoint.",[139,921,922],{},"Keep the default credential chain if the AWS CLI or SSO already works on this\nmachine; otherwise enter credentials manually. The AWS identity needs MSK\ndata-plane permissions for the clusters, topics, and consumer groups you use,\nplus write access if you intend to produce.",[143,924,70],{"id":69},[139,926,927],{},"Add an optional Schema Registry to browse subjects and decode or validate\nschema-based messages. Its settings are stored with the cluster connection.",[139,929,930,933,934,254],{},[151,931,932],{},"Standard"," supports registries that implement the Confluent API, including\nConfluent, Redpanda, and Apicurio. AWS Glue is currently marked ",[151,935,936],{},"Coming soon",[139,938,939],{},"Use the registry root URL for Confluent and Redpanda. For Apicurio, include the\nConfluent-compatible API path exposed by your version, for example:",[281,941,944],{"className":942,"code":943,"language":286,"meta":287},[284],"https:\u002F\u002Fapicurio.example.com\u002Fapis\u002Fccompat\u002Fv7\n",[212,945,943],{"__ignoreMap":287},[139,947,948,949,350,951,350,954,957,958,960,961,964],{},"Authentication supports ",[151,950,336],{},[151,952,953],{},"Basic Auth",[151,955,956],{},"Bearer Token",", and ",[151,959,362],{},".\nSSL requires an ",[212,962,963],{},"https:\u002F\u002F"," URL and accepts a CA certificate plus an optional\nclient key and certificate.",[139,966,967,968,971],{},"Use the card's ",[151,969,970],{},"Test"," button to verify Schema Registry separately from Kafka.",[139,973,974],{},[169,975],{"alt":976,"height":977,"src":978,"width":979},"Kafma's Schema Registry settings for a Kafka cluster: registry type, URL, the authentication options, and the card's own Test button",834,"https:\u002F\u002Fmedia.kafma.app\u002Fdocs\u002Fget-started\u002Fconnect-to-a-cluster\u002Fschema-registry.png",1420,[139,981,982,983,985,986,989,990,993,994,997],{},"When a connection first becomes ",[151,984,264],{}," and writable without a registry,\n",[151,987,988],{},"Save"," offers ",[151,991,992],{},"Configure SR"," or ",[151,995,996],{},"Save without SR",". Without a registry,\nKafma cannot validate produced messages against a schema before sending them.",[139,999,1000,1001,254],{},"After connecting, see ",[1002,1003,1004],"a",{"href":73},"Subjects and versions",[143,1006,1008],{"id":1007},"test-then-save","Test, then save",[139,1010,476,1011,1014],{},[151,1012,1013],{},"Test Connection"," to validate the form and reach the cluster. It becomes\navailable when all required fields are valid, and a successful test shows the\nnumber of reachable brokers.",[139,1016,1017,1018,1020],{},"Testing is optional. ",[151,1019,988],{}," stores the connection and opens its Console, where\nKafma connects to the cluster.",[143,1022,1024],{"id":1023},"troubleshooting","Troubleshooting",[139,1026,1027,1028,1030],{},"Start with the error shown by ",[151,1029,1013],{},":",[176,1032,1033,1043],{},[179,1034,1035],{},[182,1036,1037,1040],{},[185,1038,1039],{},"Message",[185,1041,1042],{},"What to check",[192,1044,1045,1055,1065,1075,1088,1098,1108,1120,1128],{},[182,1046,1047,1052],{},[197,1048,1049],{},[212,1050,1051],{},"Connection refused",[197,1053,1054],{},"The broker is running and the port is correct",[182,1056,1057,1062],{},[197,1058,1059],{},[212,1060,1061],{},"Host not found",[197,1063,1064],{},"The hostname and local DNS",[182,1066,1067,1072],{},[197,1068,1069],{},[212,1070,1071],{},"Connection timed out",[197,1073,1074],{},"The firewall, security group, or VPN",[182,1076,1077,1082],{},[197,1078,1079],{},[212,1080,1081],{},"Broker advertised an unreachable address",[197,1083,1084,1085],{},"The broker's ",[212,1086,1087],{},"advertised.listeners",[182,1089,1090,1093],{},[197,1091,1092],{},"TLS required or TLS handshake failed",[197,1094,1095,1097],{},[151,1096,381],{}," and the listener port",[182,1099,1100,1103],{},[197,1101,1102],{},"Certificate not trusted or hostname mismatch",[197,1104,1105,1107],{},[151,1106,469],{}," and the broker hostname",[182,1109,1110,1115],{},[197,1111,1112],{},[212,1113,1114],{},"Invalid username or password",[197,1116,1117,1118],{},"The credentials and SASL ",[151,1119,394],{},[182,1121,1122,1125],{},[197,1123,1124],{},"mTLS or client-certificate errors",[197,1126,1127],{},"The client key, certificate, and CA",[182,1129,1130,1135],{},[197,1131,1132],{},[212,1133,1134],{},"AWS IAM access denied",[197,1136,1137,1138,1141],{},"The access key, ",[212,1139,1140],{},"kafka-cluster:Connect"," permission, and AWS Region",[139,1143,1144],{},"When every bootstrap server is unreachable, Kafma tests each one and summarizes\nthe result.",[143,1146,1148],{"id":1147},"manage-connections","Manage connections",[139,1150,1151,1152,1154,1155,350,1158,354,1161,1164],{},"Select the current cluster at the top of the sidebar to open ",[151,1153,20],{},". From\nthere, use a connection's menu to ",[151,1156,1157],{},"Edit",[151,1159,1160],{},"Pin to top",[151,1162,1163],{},"Delete",". A\ncluster must be disconnected before you can edit it.",[139,1166,1167,1168,1170],{},"Existing secrets remain unchanged unless you replace them. Configuration\nchanges appear in ",[1002,1169,132],{"href":130}," with secret\nvalues redacted. Deleting a connection also removes its stored secrets.",[139,1172,1173,1174,254],{},"Kafma Free supports one active cluster. If Pro access ends, the most recently\nselected cluster remains available while the others stay saved and locked. See\n",[1002,1175,1176],{"href":23},"Licensing and activation",[143,1178,1180],{"id":1179},"next-steps","Next steps",[509,1182,1183,1188,1193],{},[512,1184,1185],{},[1002,1186,1187],{"href":32},"Use the Console",[512,1189,1190],{},[1002,1191,1192],{"href":73},"Browse Schema Registry subjects",[512,1194,1195],{},[1002,1196,1197],{"href":23},"Review licensing and activation",[1199,1200,1201],"style",{},"html pre.shiki code .sA0dC, html code.shiki .sA0dC{--shiki-default:#787D86}html pre.shiki code .sLaUg, html code.shiki .sLaUg{--shiki-default:#FFFFFF}html pre.shiki code .sUqoa, html code.shiki .sUqoa{--shiki-default:#E7E8EA}html pre.shiki code .sJl8Q, html code.shiki .sJl8Q{--shiki-default:#83CFAE}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":287,"searchDepth":26,"depth":26,"links":1203},[1204,1210,1217,1221,1222,1223,1224,1225],{"id":145,"depth":21,"text":146,"children":1205},[1206,1207,1208,1209],{"id":243,"depth":26,"text":244},{"id":257,"depth":26,"text":258},{"id":271,"depth":26,"text":272},{"id":295,"depth":26,"text":296},{"id":314,"depth":21,"text":236,"children":1211},[1212,1213,1214,1215],{"id":376,"depth":26,"text":344},{"id":473,"depth":26,"text":362},{"id":492,"depth":26,"text":370},{"id":533,"depth":26,"text":1216},"Map client.properties settings",{"id":857,"depth":21,"text":858,"children":1218},[1219,1220],{"id":872,"depth":26,"text":873},{"id":902,"depth":26,"text":903},{"id":69,"depth":21,"text":70},{"id":1007,"depth":21,"text":1008},{"id":1023,"depth":21,"text":1024},{"id":1147,"depth":21,"text":1148},{"id":1179,"depth":21,"text":1180},"Connect Kafma to self-hosted or managed Kafka with SASL, SSL\u002FmTLS, OAuth, AWS IAM, and Schema Registry, including Confluent Cloud and Amazon MSK.","md","2026-08-01",{},{"title":19,"description":1226},{"loc":18},"docs\u002Fget-started\u002Fconnect-to-a-cluster","yPSk3I6tay1whTO6qzh6pJw3Hd7vIn2tbyJ6XlFdIfs",1785561255700]