BlogsConfluentConfluent Private Cloud Broker Density and Policy Enforcement

Confluent Private Cloud Broker Density and Policy Enforcement

Confluent Private Cloud Broker Density and Policy Enforcement

7
posts
2020–2026

This release enhances Confluent Cloud's secure networking capabilities by detailing options for both public and private integrations. For public endpoints, it covers Public Egress IPs for firewall rules and AWS Gateway/Azure VNet Service Endpoints for traffic within cloud provider networks. For private endpoints, it introduces DNS Forwarding for VPC/VNet Peering or Transit Gateway setups and Egress Access Points for AWS PrivateLink, enabling secure connections to data sources and sinks without t

2026

Proven: Up to 73% Fewer Brokers With Confluent Private Cloud – and More

5/19/2026

This post provides detailed benchmarking data proving Confluent Private Cloud's (CPC) ability to reduce broker count by up to 73% while matching Apache Kafka's latency SLAs. It highlights CPC's superior tail latency (up to 83% lower) and its elimination of the 'latency cliff' for predictable performance at saturation. The post also details how CPC achieves exponential savings for large-scale workloads with high partition counts. Furthermore, it pre-announces two major upcoming features: CPC Centralized Policy Enforcement (with early access for Gateway Field Level Encryption, Gateway Payload Encryption, and Deep Schema Validation) and broker-native multi-tenancy for CPC, which introduces logical Kafka clusters (LKCs) on shared physical Kafka clusters (PKCs) with isolation, quotas, and observability.

2025

Introducing Confluent Private Cloud

10/29/2025

Introduces Confluent Private Cloud, a new deployment model for private environments. Key technical contributions include: Confluent Private Cloud Gateway, a protocol-aware proxy for centralized authentication, authorization, encryption, and routing without client code changes; Intelligent Replication, a new push-based replication mode that complements Kafka's pull-based approach to improve throughput and reduce latency; and the integration of Unified Stream Manager (USM) for hybrid management and monitoring across on-prem and cloud environments.

Unified Stream Manager GA in Confluent Platform 8.1

10/29/2025

Introduces Unified Stream Manager (USM) for Confluent Platform 8.1, enabling centralized governance and observability for on-premises and private cloud Kafka deployments. USM unifies schema management by making Confluent Cloud Schema Registry the single source of truth, with on-premises instances acting as read-only caches. It integrates client-side field-level encryption for data protection. Observability is enhanced with a single view of hybrid platform health, a unified data catalog via Data Portal, and end-to-end data stream tracing. The architecture uses a USM agent and a secure, private network connection (AWS PrivateLink) to Confluent Cloud, sharing only metadata and telemetry.

Introducing Private Network Interface (PNI) on AWS: Lower Kafka Networking Costs by 50%

8/1/2025

Introduces Private Network Interface (PNI) on AWS as a new private networking option for Confluent Cloud, designed to reduce networking costs and enhance security. PNI leverages AWS Elastic Network Interfaces (ENIs) for secure, low-latency, high-throughput connectivity directly within the customer's VPC. It eliminates the cost-security trade-offs of VPC peering and PrivateLink by offering centralized security policy enforcement, freedom from IP address management, and reduced data transfer costs. The post details cost savings achieved through PNI on both Enterprise and Freight clusters, with specific examples showing significant reductions compared to PrivateLink. It also highlights the elimination of cross-AZ networking costs and reduced data transfer/processing fees as key drivers of these savings. A case study with Indeed illustrates the practical implementation and benefits of PNI and Freight for cost-efficient and secure data infrastructure.

Cluster Linking for Azure Private Link is available in Confluent Cloud

2/28/2025

Introduces Cluster Linking support for Azure Private Link, enabling secure, private data replication between Kafka clusters within Azure private networks. This eliminates the need for public networking for multi-cluster replication and data mobility, reducing operational overhead and enhancing security for disaster recovery, migration, and data sharing scenarios.

2024

Secure Integrations With Any Cloud, Any Network | Confluent Cloud

4/9/2024

This post details how Confluent Cloud enables secure integrations with external data sources and sinks through various networking features. It explains the use of Public Egress IPs for IP-based firewalling, AWS Gateway and Azure VNet Service Endpoints for secure traffic within cloud networks, DNS Forwarding for resolving private FQDNs in peered networks, and Egress Access Points for PrivateLink connections. It provides specific examples for AWS S3 Sink Connector and HTTP source connector, outlining configuration steps and underlying technologies like TLS, VPC Interface Endpoints, and Azure Private Endpoints.

2020

Confluent Cloud Now Supports AWS PrivateLink for Secure Network Connectivity

8/6/2020

This post details the addition of AWS PrivateLink support for Confluent Cloud Dedicated clusters, enabling secure, private network connectivity from customer VPCs. It explains the benefits over VPC peering, such as avoiding IP address coordination and enforcing one-way connectivity. The technical implementation involved updating networking infrastructure to use Network Load Balancers for PrivateLink service endpoints and building new automation for self-serve creation and registration of customer AWS accounts.