# Triagic + Confluent / Kafka: ticket investigations over your infrastructure, read-only

> Confluent / Kafka in Triagic: Inspect topics, consumer-group lag, schemas, and connectors, and read messages to trace one that never arrived.

Source: https://triagic.com/integrations/confluent

## What you can ask

- Ask Confluent / Kafka which import-worker pods restarted today and why
- In Confluent / Kafka, is the payments service running the version we deployed at 16:02?
- Pull the last 200 log lines from the failing container in Confluent / Kafka
- Which Confluent / Kafka workspace changed last week, and what did the plan touch?
- Is the consumer group for order events in Confluent / Kafka lagging, and by how much?

## What the agent can do

Every tool the Confluent / Kafka server annotates as read-only. An explicit allowlist of read tools passed to the server; produce-message, delete-topics and every create tool are dropped.

## Connect in three steps

1. **Mint a read-only credential in Confluent / Kafka.** Create a dedicated user or token that can only read. An explicit allowlist of read tools passed to the server; produce-message, delete-topics and every create tool are dropped.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then Confluent / Kafka. Fill in: Bootstrap servers (required): Comma-separated broker addresses, ports included.; Kafka API key (required): Confluent Cloud → Cluster → API keys. Keys are per-cluster.; Kafka API secret (required)
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts Confluent / Kafka locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/infrastructure#confluent--kafka

## Read-only, by construction

An explicit allowlist of read tools passed to the server; produce-message, delete-topics and every create tool are dropped.

## FAQ

**Can Triagic change anything in Confluent / Kafka?**
No. An explicit allowlist of read tools passed to the server; produce-message, delete-topics and every create tool are dropped. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect Confluent / Kafka?**
Bootstrap servers, Kafka API key, Kafka API secret. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does Confluent / Kafka cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [Kubernetes](https://triagic.com/integrations/kubernetes)
- [Docker](https://triagic.com/integrations/docker)
- [Terraform](https://triagic.com/integrations/terraform)
