Confluent Platform System Requirements¶
This topic provides the hardware and software requirements for Confluent Platform.
Looking for a fully managed cloud-native service for Apache Kafka®?
Sign up for Confluent Cloud and get started for free using the Cloud quick start.
Hardware¶
On-Premises¶
The following table lists machine recommendations are for installing individual Confluent Platform components. Confluent Platform supports both ARM64 and X86 hardware architecture. ARM64 is supported in Confluent Platform 7.6.0 and later.
Note that the recommended CPU resource is the same for all platforms. For example, if 12 CPUs is recommended for non-Kubernetes environment, the recommendation for a Kubernetes environment would also be 12 CPU units.
Component | Nodes | Storage | Memory | CPU |
---|---|---|---|---|
Control Center-Normal mode | 1 | 300 GB, preferably SSDs | 32 GB RAM (JVM default 6 GB) | 12 cores or more |
Control Center-Reduced infrastructure mode | 1 | 128 GB, preferably SSDs | 8 GB RAM (JVM default 4 GB) | 4 cores or more |
Broker | 3 |
|
64 GB RAM | Dual 12-core sockets |
KRaft controller | 3-5 | 64 GB SSD | 4 GB RAM | 4 cores |
Confluent Manager for Apache Flink | 2 Kubernetes pods | 10 GB (Kubernetes persistent volume) | 4 GB RAM (For managing 150 Flink applications) | 3 cores (For managing 150 Flink applications) |
Connect | 2 | Storage is only required at installation time. | 0.5 - 4 GB heap size depending on connectors | Typically not CPU-bound. More cores is better than faster cores. |
Replicator- Same as Connect for nodes, storage, memory, and CPU. (See note that follows about AWS.) | 2 | Storage is only required at installation time. | 0.5 - 4 GB heap size | More cores is better |
ksqlDB - See Capacity planning | 2 | Use SSD. Sizing depends on the number of concurrent queries and the aggregation performed. Minimum 100 GB for a basic server. | 20 GB RAM | 4 cores |
REST Proxy | 2 | Storage is only required at installation time. | 1 GB overhead plus 64 MB per producer and 16 MB per consumer | 16 cores to handle HTTP requests in parallel and background threads for consumers and producers. |
Schema Registry | 2 | Storage is only required at installation time. | 1 GB heap size | Typically not CPU-bound. More cores is better than faster cores. |
ZooKeeper | 3-5 |
Each write to ZooKeeper must be persisted in the transaction log before the client gets an ack. Using SSD reduces the ZooKeeper write latency. |
4 GB RAM | 2-4 cores |
- If you want to use RAID disks, the recommendation is:
- RAID 1 and RAID 10: Preferred
- RAID 0: 2nd preferred
- RAID 5: Not recommended
Note
If deploying Confluent Platform on AWS VMs and running Replicator as a connector, be aware that VMs with burstable CPU types (T2, T3, T3a, and T4g) will not support high throughput streaming workloads. Replicator worker nodes running on these VMs experience throughput degradation due to credits expiring, making these VMs unsuitable for Confluent Platform nodes expected to run at elevated CPU levels for a sustained period of time, and supporting workloads that are above and beyond their baseline resource rates.
Cloud¶
For information on Confluent Cloud support, see Supported Features for Confluent Cloud.
Software¶
Operating Systems¶
It is recommended that you run Confluent Platform across uniform OS, Confluent Platform, and Java versions.
Confluent Platform supports both X86 and ARM64 hardware architecture. ARM64 is supported in Confluent Platform 7.6.0 and later. For more information on required hardware, see Hardware.
Operating System | 7.8.x | 7.7.x | 7.6.x | 7.5.x | 7.4.x | 7.3.x | 7.2.x | 7.1.x |
---|---|---|---|---|---|---|---|---|
AlmaLinux 9 | yes | no | no | no | no | no | no | no |
AlmaLinux 8 | yes | no | no | no | no | no | no | no |
Amazon Linux 2023 | yes | yes | no | no | no | no | no | no |
Debian 12 (bookworm) | yes | yes | no | no | no | no | no | no |
Debian 10 (buster) [1] | no | yes | yes | yes | yes | yes | yes | yes |
Debian 9 (stretch) [1] | no | yes | yes | yes | yes | yes | yes | yes |
RHEL 9.x | yes | yes | yes | yes | yes | no | no | no |
RHEL/CentOS 8.x | yes | yes | yes | yes | yes | yes | yes | yes |
RHEL/CentOS 7.x [1] | no | no | yes | yes | yes | yes | yes | yes |
Rocky Linux 9 | yes | yes | yes | no | no | no | no | no |
Rocky Linux 8 | yes | yes | yes | no | no | no | no | no |
Ubuntu 22.04 LTS (jammy) [2] | yes | no | no | no | no | no | no | no |
Ubuntu 20.04 LTS (focal) | yes | yes | yes | yes | yes | yes | yes | yes |
Ubuntu 18.04 LTS (bionic) [1] | no | yes | yes | yes | yes | yes | yes | yes |
Ubuntu 16.04 LTS (xenial) [1] | no | yes | yes | yes | yes | yes | yes | yes |
Footnotes
[1] | (1, 2, 3, 4, 5) Support for these operating systems has been removed in Confluent Platform 7.8.x because they have reached their end of life. Support for these OSs will be removed for all versions of Confluent Platform after the 7.8.x release. You should not use these OSs in a production deployment. |
[2] | Java 11 and 17 are supported. Java 8 is not supported on this operating system. |
Additional notes about OS support:
- SELinux
Confluent Platform is supported on AlmaLinux, Amazon Linux, Debian, Oracle Linux, RHEL, CentOS, Debian, Rocky Linux and Ubuntu Operating Systems.
Confluent is not accountable for Security-Enhanced Linux (SELinux) policy development, support, or enforcement. If you experience issues running Confluent Platform with SELinux enabled on a supported Linux Operating System, contact your OS provider for assistance.
- Windows
- Windows is not currently supported for Confluent Platform. Windows 8.1 and later and Windows 2016 and later are supported by the C/C++ and .NET clients.
- macOS
- macOS 10.14 and later is supported for testing and development purposes only.
- File descriptors
- For the file descriptor requirement for Kafka, see File Descriptors and mmap.
- ulimit
- Control Center requires many open RocksDB files. Set the
ulimit
for the number of open files to a minimum value of 16384 using theulimit -n
command. For the other Confluent Platform components, specifically Schema Registry and Replicator, you can leave theulimit
as the OS default. - RHEL with TLS
When you install Confluent Platform on RHEL8 with TLS encryption, you must add DH Key Size JVM Parameters for each component. For more information, see Strong crypto defaults in RHEL 8 and deprecation of weak crypto algorithms.
Set the following component-level environment variables to the argument:
- Control Center:
CONTROL_CENTER_OPTS=-Djdk.tls.ephemeralDHKeySize=2048
- Schema Registry:
SCHEMA_REGISTRY_OPTS=-Djdk.tls.ephemeralDHKeySize=2048
- Kafka, ZooKeeper, and Connect:
KAFKA_OPTS=-Djdk.tls.ephemeralDHKeySize=2048
- REST Proxy:
KAFKAREST_OPTS=-Djdk.tls.ephemeralDHKeySize=2048
- ksqlDB:
KSQL_OPTS=-Djdk.tls.ephemeralDHKeySize=2048
- Control Center:
- atime
The
atime
mount option impacts performance, because every read operation on a file system causes a write operation.Confluent recommends disabling the tracking of
atime
by setting thenoatime
option when you mount Kafka data disks.
Java¶
You need to separately install the correct version of Java before you start the Confluent Platform installation process.
The following table lists Java support in Confluent Platform by version. Note the following:
- Java 8 was deprecated in Confluent Platform version 7.4.x and will be removed in a future version.
- Ubuntu 22.04 supports Java versions 17 and 11, and does not support Java 8 in Confluent Platform 7.8.x.
- Docker images support Java versions 17 or 11. For more information, see Docker.
- Eclipse Temurin (formerly known as AdoptOpenJDK), OpenJDK, Zulu OpenJDK, and Oracle are supported with Confluent Platform.
- You should use the full JDK to help Confluent Support with troubleshooting and to provide better support if you experience issues with Confluent Platform.
Confluent Platform | Recommended | Supported |
---|---|---|
7.8.x | 17 | 17, 11, 8 * |
7.7.x | 17 | 17, 11, 8 * |
7.6.x | 17 | 17, 11, 8 * |
7.5.x | 17 | 17, 11, 8 * |
7.4.x | 17 | 17, 11, 8 * |
7.3.x | 17 | 17, 11, 8 |
7.2.x | 11 | 11, 8 |
7.1 | 11 or 8 | 11, 8 |
* Java 8 is deprecated, and will be removed in a future version.
From a security perspective, you should always use the latest released patch version because older versions may have security vulnerabilities.
Java 9 and 10 are not supported in Confluent Platform as those versions are short-term rapid release versions.
For more information about Java versions, see Java Version History.
Docker¶
Optional: Docker version 1.11 or later running on a supported operating system. This is required if you are installing Confluent Platform by using the Docker images.
Network¶
Control Center relies heavily on Kafka, so a fast and reliable network is important for performance. Modern datacenter networking speed of 1 GbE, 10 GbE should be sufficient.
Ports¶
The table below lists the network services and ports exposed as part of Confluent Platform.
All services listed below use the TCP protocol.
All ports listed below are the default ports, and in most cases you can configure each service to listen on a different port of your choice.
Ports that are indicated to be Internal Only need to be accessible by components within Confluent Platform, not by users or clients of the platform.
When deploying Confluent Platform, ensure that your networking rules allow for the required access to the various components and services.
Component and Service | Default Port | Internal Only? |
---|---|---|
ZooKeeper | ||
|
2888 | Yes |
|
3888 | Yes |
|
2181 | No |
|
2182 | No |
|
7770 | No |
KRaft Controller | ||
|
9093 | Yes |
|
7770 | No |
Kafka Broker | ||
|
9091 | Yes |
|
9092 | No |
|
8090 | No |
|
8090 | No |
|
7771 | No |
(Standalone) REST Proxy | 8082 | No |
Confluent Control Center | 9021 | No |
Kafka Connect | ||
|
8083 | No |
|
7773 | No |
ksqlDB Server | ||
|
8088 | No |
|
7774 | No |
Schema Registry | ||
|
8081 | No |
|
7772 | No |
[*] Reserve the Jolokia ports only when you deploy Confluent Platform using Ansible.
Synchronize time¶
Clock synchronization on each Kafka broker is required to ensure the full system functions
correctly. For example, secure network communication with the brokers that rely on
TLS certificate verification may fail if clocks are not synchronized. Clock synchronization
can be achieved using utilities like ntpd
that implement the Network Time Protocol (NTP).