Confluent

Enterprise only Premium Partner
Related Documentation
Made by
Kong Inc.
Supported Gateway Topologies
hybrid db-less traditional
Supported Konnect Deployments
hybrid cloud-gateways serverless
Compatible Protocols
grpc grpcs http https
Priority
752
Minimum Version
Kong Gateway - 3.8
Related Resources

With Kafka at its core, Confluent offers complete, fully managed, cloud-native data streaming that’s available everywhere your data and applications reside. Using the Confluent plugin, you can send HTTP request data to Apache Kafka by constructing Kafka messages from incoming Kong Gateway HTTP requests.

Kong Gateway also provides Kafka Log and Kafka Upstream plugins for publishing logs and messages to an Apache Kafka topic:

Note: This plugin has the following known limitations:

  • The message format is not customizable.
  • Kong Gateway supports Kafka 4.0 starting from version 3.10.

Authentication

The Confluent plugin supports the following authentication options for Confluent Cloud connections:

Auth method

Description

Example

API key (cluster_api_key / cluster_api_secret) Authenticates using a Confluent Cloud API key and secret via SASL/PLAIN. –
SASL/OAUTHBEARER (oauthbearer) v3.15+ Authenticates using short-lived OAuth 2.0 access tokens fetched automatically by Kong Gateway.

Kong Gateway uses the client_credentials grant to retrieve tokens from the configured oauthbearer.token_endpoint_url, caches them until expiry, and presents them in the SASL/OAUTHBEARER handshake. When oauthbearer is set, it takes precedence over cluster_api_key/cluster_api_secret.
SASL/OAUTHBEARER authentication

Schema registry support v3.11+

The Confluent plugin supports integration with Confluent Schema Registry for AVRO and JSON schemas.

Schema registries provide a centralized repository for managing and validating schemas for data formats like AVRO and JSON. Integrating with a schema registry allows the plugin to validate and serialize/deserialize messages in a standardized format.

Using a schema registry with Kong Gateway provides several benefits:

  • Data validation: Ensures messages conform to a predefined schema before being processed.
  • Schema evolution: Manages schema changes and versioning.
  • Interoperability: Enables seamless communication between different services using standardized data formats.
  • Reduced overhead: Minimizes the need for custom validation logic in your applications.

To learn more about Kong’s supported schema registry, see:

How schema registry validation works

When a producer plugin is configured with a schema registry, the following workflow occurs:

 
sequenceDiagram
autonumber
    participant Client
    participant Kong as Confluent plugin
    participant Registry as Schema Registry
    participant Kafka
    
    activate Client
    activate Kong
    Client->>Kong: Send request
    deactivate Client
    activate Registry
    Kong->>Registry: Fetch schema from registry
    Registry-->>Kong: Return schema
    deactivate Registry
    Kong->>Kong: Validate message against schema
    Kong->>Kong: Serialize using schema
    activate Kafka
    Kong->>Kafka: Forward to Kafka
    deactivate Kong
    deactivate Kafka
  

If validation fails, the request is rejected with an error message.

Configure schema registry

To configure Schema Registry with the Confluent plugin, use the config.schema_registry parameter in your plugin configuration.

For sample configuration values, see:

Accept plain JSON for Avro schemas v3.16+

By default, an Avro schema requires every union-typed value to be wrapped in a single-key object that names the union branch. For example, a field declared as ["null", "string"] must be sent as {"string": "hello"} or {"null": null}. This forces HTTP clients to understand Avro’s wire encoding to call your API.

Set payload_encoding: simple_json on the value_schema or the key_schema to let the Confluent plugin accept plain JSON instead, and resolve union branches against the schema itself:

Value

Resolution

null, or a nullable field is omitted Encoded as the union’s null branch.
A value matching exactly one non-null branch Encoded as that branch.
A value matching more than one non-null branch (for example a JSON number against ["int", "long"] or ["float", "double"]) Encoded using the first matching branch, in the order the branches are declared in the schema. An integer that doesn’t fit in a 32-bit signed range is always encoded as long, even if int is declared first.
A value that doesn’t match any branch of the union The request is rejected with an error that includes the JSON path and the branches that were considered.

This resolution applies at every level of the payload, including fields inside nested records, arrays, and maps. Logical types (for example timestamps, decimals, or UUIDs) are passed through unchanged once their union is resolved.

If a record field is omitted from the request body, the plugin falls back to the field’s schema default, if one exists. Otherwise, the field must be nullable, or the plugin rejects the request as missing a required field.

Because an Avro-tagged value like {"string": "hello"} already matches a single branch by name, simple_json accepts it as-is. This lets you migrate clients from avro_json to simple_json one at a time, instead of all at once.

For a sample configuration, see Simple JSON encoding for Avro schemas.

Kafka record headers v3.15+

The Confluent plugin can forward HTTP request headers as Kafka record headers, which are per-record key/value metadata that lives alongside the message key and value. This lets consumers read routing, tracing, or tenancy context without parsing the message payload.

Configure the config.headers block to control which headers are forwarded:

Use config.headers.name_mappings to rename an HTTP header to a different Kafka record header key.

Use config.headers.repeated_headers_behavior to control how duplicate HTTP headers are handled: retain_duplicates (default) creates a separate record header per value, take_first uses only the first value, and concatenate_by_comma joins all values with a comma.

Note: The config.forward_headers setting embeds request headers inside the message body. config.headers is a separate configuration block that sets native Kafka record headers on the produced record.

Message compression v3.16+

The Confluent plugin can compress message batches from a producer before sending them to the Kafka broker, using config.compression_type. Compression reduces network bandwidth between Kong Gateway and the broker, broker disk usage, and cross-broker replication cost.

This applies only to the Kong Gateway-to-broker traffic flow. It’s independent of any HTTP-level Content-Encoding between clients and Kong Gateway, and works the same way in both sync and async producer modes.

Codec

Ratio

Speed

Notes

none (default) N/A N/A No compression. Preserves current behavior on upgrade.
gzip Highest Slowest Best when bandwidth or storage is the binding constraint and producer CPU is cheap.
snappy Moderate Fast A common default for throughput-sensitive Kafka workloads.
lz4 Moderate Fastest Recommended codec for most workloads: similar ratio to Snappy, typically faster.

Note: zstd isn’t available as a producer-side codec, because it requires Kafka Produce API v7+ negotiation. The consume side can already decompress zstd batches written by other producers.

Compression happens at the producer batch level. Confluent compresses the entire outgoing record batch as a single unit before it’s sent. Compression efficiency improves with batch size, so it’s most effective in async mode, where the plugin already accumulates messages before flushing to the broker. In sync mode, batches are typically smaller, but compression is still available and can be worthwhile for larger payloads.

If config.compression_type is misconfigured or compression fails at runtime, Confluent logs a warning and sends the batch uncompressed rather than dropping it.

For an example, see Compress messages before sending to Kafka.

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!