# Get more teams building on IBM Confluent

Conduktor adds a developer UI, self-service with policies the platform team sets, and encryption in a Kafka proxy to IBM Confluent and IBM Event Streams.

[Talk to Us](https://www.conduktor.io/contact/demo?src=partners-ibm)
[Get Started Free →](https://www.conduktor.io/get-started?src=partners-ibm)

Trusted by platform teams at

## Streaming spreads when every team can build on it.

IBM Confluent gives you a solid streaming platform. What decides how far it spreads across your IBM Kafka estate, IBM Confluent or Event Streams, is how quickly a new team gets productive. With Conduktor, the first team's templates, policies, and topic catalog are already in place for the second, and every team after that starts further ahead.

## How Conduktor fits with IBM Kafka

Your teams work through Console. Your applications reach IBM Confluent through Gateway. No broker plugins on your IBM clusters.

![Three layers: your developers, platform teams, security and AI assistants use Conduktor Console (UI, API, MCP); your applications go through Conduktor Gateway, a Kafka proxy, and the Schema Registry Proxy; both sit on IBM Confluent Cloud, IBM Confluent Platform, and IBM Event Streams](https://www.conduktor.io/assets/images/partners/ibm-architecture.svg)

## What faster adoption looks like

Results from Conduktor customers across Kafka platforms.

- **1** — hour — Team onboarding — Down from three weeks: a Fortune 500 retailer now puts a new team on Kafka in an hour.
- **4** — x — Kafka applications — CDC Informatique went from 40 to 160 Kafka applications in three years, with a five-person platform team.
- **5** — x — Kafka applications — Swiss Post grew Kafka usage fivefold, with 800+ users under RBAC.

## What Conduktor adds to IBM Confluent

### Developers build and debug on their own

Browse, produce, and replay messages, and check consumer lag, within each developer's permissions.

### Self-service topics and access

Teams create topics and request access through templates and policies you define.

### Encryption and masking in Gateway

Field-level and full-payload encryption, masking, and data quality rules, applied in the Kafka proxy.

### MCP server for AI assistants

Read-only access to clusters, topics, and consumer groups, limited to each user's permissions.

### Schema Registry access control

Per-subject read and write permissions in front of IBM Confluent Schema Registry.

### Migrate from IBM Event Streams to IBM Confluent

Switch the backing cluster in Gateway instead of changing every client's bootstrap servers.

### Zero-cost virtual clusters

Isolated namespaces for teams or partners on one physical cluster, with no extra Kafka cluster to run.

## What IBM Confluent covers, and what Conduktor adds

IBM Confluent runs the platform. Conduktor covers what teams would otherwise build or do by hand around it.

| | IBM Confluent gives you | Conduktor adds |
|---|---|---|
| Access | RBAC with predefined roles, and Control Center for operators | Granular RBAC you compose: pick the operations per resource, scope them by name, prefix, or wildcard, and assign them to team groups from your IdP. Teams manage their own members and approve access to what they own, and Conduktor provisions the matching DeveloperRead and DeveloperWrite role bindings |
| Encryption | Client-side field encryption, configured through Schema Registry data contracts in each client | Encryption at the proxy, with or without a schema, and no client library changes |
| Cluster moves | Cluster Linking to replicate data between clusters | Cluster switching at the proxy, so applications don't redeploy when the cluster changes |

Console and Gateway deploy with Helm on Red Hat OpenShift under the default `restricted-v2` security context, and both work without internet access. For the full comparison, see [Confluent + Conduktor](https://www.conduktor.io/partners/confluent).

## Read more customer stories

- [CDC Informatique: 4x Kafka Growth, Flat Team](https://www.conduktor.io/customer-stories/cdc-informatique-governed-kafka-self-service)
- [Retail: 99% Faster Kafka Onboarding](https://www.conduktor.io/customer-stories/one-hour-kafka-onboarding-retail-streaming-operations)
- [European Airline: 25 Clusters to Confluent Cloud](https://www.conduktor.io/customer-stories/leading-european-airline-migrates-kafka-to-confluent-cloud-with-conduktor)

## Frequently Asked Questions

**How does Conduktor speed up IBM Confluent adoption?**

Developers browse, test, and debug in Console without help from the platform team. Self-service gives them topics and access as soon as a request fits your policies. Gateway encrypts and masks on the Kafka protocol, so data that security kept off the platform can move onto it.

**What is IBM Confluent?**

IBM Confluent is the Confluent data streaming platform, built on Apache Kafka, which IBM acquired in March 2026. It is sold as IBM Confluent Cloud and IBM Confluent Platform, and IBM now delivers its new streaming work through it rather than Event Streams.

**Does Conduktor work with IBM Confluent?**

Yes. IBM Confluent Cloud and IBM Confluent Platform are Confluent Cloud and Confluent Platform. Conduktor connects over the standard Kafka protocol, works with Confluent Schema Registry, and can manage access as Confluent RBAC role bindings.

**Can we run Kafka tooling on Red Hat OpenShift?**

Yes. Console and Gateway deploy with Helm and run under OpenShift's default `restricted-v2` security context constraint, without a custom SCC. Both run without internet access: the license is checked locally and images can come from your private registry.

**We're early with streaming on IBM. Is Conduktor too soon?**

Developers get value from the first topic: seeing and debugging data is where new teams lose the most time. Setting ownership and naming rules before the tenth team arrives also costs less than cleaning up after the fiftieth. The free Community Edition covers 50 users and 3 clusters.

**Can our developers use AI assistants with Kafka?**

Yes, with governance. Console's MCP server, in preview, gives assistants read-only access limited to each user's permissions. Any MCP client that supports remote servers with token authentication can connect, including IBM Bob and watsonx Orchestrate.

**Can Conduktor manage IBM MQ connectors?**

Yes. Console manages Kafka Connect connectors whatever their type, including IBM MQ source and sink connectors: check status, restart, pause, and manage offsets. These permissions can be delegated to the team that owns each connector.

**Does Conduktor work with IBM Event Streams?**

Event Streams exposes the Kafka APIs, so Console and Gateway connect to it as a Kafka cluster. On IBM Cloud, clients authenticate with SASL over TLS using an IBM Cloud API key, and must send SNI. On the self-managed edition, SCRAM-SHA-512, mutual TLS, and OAuth are available. We validate your edition, authentication, networking, and the features you need during the evaluation; schema registry compatibility is checked separately.

**Can Conduktor help migrate from Event Streams to IBM Confluent?**

Yes. Console inventories topics and consumer groups on both clusters, and Insights flags what is better retired than migrated. Gateway lets applications keep one bootstrap address, then switches the backing cluster at the proxy, with a way back. Data replication itself runs on MirrorMaker or Cluster Linking.

**Does Gateway add a component to operate?**

Yes. Gateway sits in the data path, so you run it with the same care as your brokers: at least three stateless instances behind your load balancing. In exchange you get one place to enforce encryption, policies, and routing, instead of logic spread across every application.

**Which key management systems does Gateway encryption support?**

AWS KMS, Azure Key Vault, Google Cloud KMS, HashiCorp Vault, and Fortanix. Master keys never leave your KMS.

**Can we control access to schemas too?**

Yes. The [Schema Registry Proxy](https://www.conduktor.io/schema-registry-proxy), in early access, adds per-subject read and write permissions in front of a Confluent-compatible registry such as IBM Confluent Schema Registry, with an audit log of every schema change.

**How does Conduktor relate to IBM Event Endpoint Management?**

Event Endpoint Management publishes Kafka topics in a catalog and controls access to them through its Event Gateway. Conduktor covers the developer experience and self-service in Console, and field-level encryption, virtual clusters, and failover in Gateway, across every Kafka platform you connect.

**Do I need to change my IBM Confluent setup?**

No broker plugins. Conduktor needs credentials and permissions on each cluster, Gateway provisions its own internal topics, and applications are pointed at Gateway when you want enforcement.

# Running Kafka on IBM?

Tell us how many teams you want on IBM Confluent next year. We'll show you what onboarding them looks like with Conduktor.

[Talk to Us](https://www.conduktor.io/contact/demo?src=partners-ibm)
