Kafka Quota Generator

The kafka-configs.sh commands that set a quota, and what the per-broker limit adds up to across the cluster.

Who the quota applies to

Quotas resolve by a specific precedence, and a more specific match wins outright rather than combining with a broader one.

The limits

Byte rates are PER BROKER, not cluster-wide. This is the single most misread thing about Kafka quotas.

set-quotas.sh

updates as you type

    Common mistakes

    These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

    1. Reading a byte-rate quota as a cluster limit

      Quotas are per broker. A producer_byte_rate of 10 MB/s across six brokers permits 60 MB/s from that client.

      Instead:Divide the cluster budget by the broker count.

    2. Applying a quota to the wrong entity

      Quotas resolve by a precedence over user, client-id and the defaults, and the most specific match wins. A user-level quota is silently overridden by a more specific user plus client-id one.

      Instead:Check which level you are setting and what else exists at a more specific level.

    3. Setting request_percentage without understanding the unit

      It is a percentage of one thread's time multiplied by the thread count, so the ceiling is well above 100.

      Instead:Read it against the number of network and IO threads.

    Why a Kafka quota is looser than the number you set

    Two things about quotas surprise almost everyone, and both make the limit weaker than intended.

    Byte rates are enforced per broker

    producer_byte_rate and consumer_byte_rate are limits per broker, not per cluster. A client producing to partitions spread over six brokers can move six times the number you set, and there is no cluster-wide byte rate quota at all. Sizing a quota from a total throughput figure and dividing by nothing is the usual mistake, and the error is always in the permissive direction.

    request_percentage is not out of 100

    It is a percentage of one broker's total request handler capacity, which is (num.io.threads + num.network.threads) multiplied by 100. On a broker with 8 io threads and 3 network threads that is 1100, so a value of 200 means two threads' worth. Treating 100 as the ceiling throttles a client to a single thread, which is a very effective way to make it appear broken.

    Throttling delays, it does not reject

    A throttled client is not told it was throttled. The broker holds the response back, so a producer sees latency and eventually a timeout and a consumer sees reduced throughput. Nothing in either client's error handling mentions a quota. The broker's throttle-time metrics are the only signal, which is why an unexplained slow client is worth checking against them.

    Precedence replaces rather than combines

    Quotas resolve from the most specific match to the least: the exact user and client-id pair, then user alone, then client-id alone, then the defaults. A more specific match replaces a broader one entirely rather than tightening it, so adding a user-and-client quota does not narrow an existing user quota, it overrides it for that client-id. A default user quota is the safest thing to set first, because it bounds every client nobody has thought about yet.

    What this cannot see

    It does not know your actual traffic, your broker count beyond what you typed, or what quotas already exist. A client-id quota is also not a boundary: client.id is set by the client, so anything that wants more capacity can change its own. Quota by user for anything that matters, and read back what is in force with the describe command in the output, because quotas live in cluster metadata rather than in a file in your repository.

    More kafka tools

    Kafka Confluent Wire Format Decoder The five junk bytes in front of your payload Kafka Key to Partition Mapper Which partition does this key land on? Kafka Topic Name Validator Legal, risky, or 249 characters too long? Kafka Replication Safety Checker How many brokers can you lose Kafka Producer Config Linter Will it start, and will it lose a record? Kafka Message Payload Decoder The first five bytes are usually not data Kafka Connect Source Connector Generator tasks.max is a ceiling, not a count Kafka Connect Sink Connector Generator A dead letter queue with no context headers is a pile of records Kafka Connect SMT Chain Builder The order is the transforms list Kafka MirrorMaker 2 Config Generator It renames every topic by default Kafka Partition Reassignment Generator The throttle is not optional Strimzi Kafka Resource Generator Without the cluster label, nothing happens Kafka mTLS Config Generator The certificate is the identity Kafka Schema Registry Config Generator The compatibility direction is your deployment order Kafka Exactly-Once Config Generator Half of it is worse than none Kafka Broker and KRaft Config Generator The internal topics that break a one-broker cluster Kafka Streams Config Generator application.id is four things at once Kafka Connect Worker Config Generator Security three times, or the tasks fail Kafka Retention and Unit Converter log.retention.hours does not take milliseconds Kafka Timestamp Converter Two sentinels and two meanings Kafka .properties to YAML Converter Dotted keys stay flat Kafka Streams Internal Topic Predictor Create them before Streams does Kafka ACL Generator The grant you forgot is on another resource type Kafka Topic Config Generator min.insync.replicas is the one that matters Kafka client.properties Generator The file every CLI tool asks for Kafka Producer Config Generator No password field, on purpose Kafka Consumer Config Generator The commit mode decides the semantics Kafka Disk and Retention Calculator retention.bytes is per partition Kafka Partition Count Calculator The number you can never reduce Kafka Cluster Sizing Calculator The traffic no client metric shows Kafka Consumer Lag Catch-Up Calculator Whether it ever clears, not just when Kafka Producer Batching Calculator linger.ms=0 still batches Kafka Segment and Index Sizing Why retention.ms is a lower bound Kafka Rebalance Duration Estimator What a rolling restart really costs Kafka Cost Estimator Your rates, so nothing goes stale Kafka Config Explorer by Version The answer depends on the release Kafka Default Config Reference What moved under a config you never edited Kafka OAuth Bearer Token Decoder Will Kafka accept it, and can it refresh Kafka Record Header Viewer Headers are a list, not a map Kafka Topic Regex Subscription Tester Kafka matches the whole name Kafka ACL Permission Matrix Viewer DENY beats every ALLOW Kafka Connect Config Validator The mistakes that raise no error Kafka Consumer Group Id Validator Which broker coordinates the group Kafka Partition Assignment Visualizer Leadership is the load, not replicas Kafka Consumer Assignment Visualizer The three assignors disagree Kafka ZooKeeper to KRaft Config Converter The authorizer class nobody changes Kafka Config to Strimzi Half of it belongs elsewhere Kafka Docker Compose Generator (KRaft) Reachable from inside and outside Kafka JAAS Config Decoder The line that stops SASL working Kafka CRC32C Calculator Which CRC, over which bytes Kafka Config Upgrade Checker What breaks when you upgrade Kafka Kafka Config Diff Which change actually changed something Kafka Consumer Config Linter Why the group rebalances, and where the records went Kafka Avro Schema Validator The defaults Avro accepts and rejects Kafka Schema Compatibility Checker What the registry will say, before you ask it Kafka Avro Schema Diff Which direction each change breaks Kafka Compression Comparison Measured on your bytes Kafka Delivery Semantics Exactly-once has a consumer half Kafka ksqlDB Query Builder It looks like SQL and the rules are not Kafka Connect SMT Predicate Tester negate reads backwards Kafka Streams Topology Viewer Count the repartitions Kafka Connect Pipeline Visualizer The order things really run in Kafka Protobuf Binary Decoder Works without the .proto Kafka Protobuf JSON Converter Why your JSON does not round-trip Kafka Protobuf to Avro Schema What does not survive the conversion Kafka Avro Binary Decoder Wrong schema, no error Kafka Avro JSON Converter Why the console producer rejects your line Kafka Avro Sample Data Generator Records that actually serialize Kafka JSON to Avro Schema What JSON cannot tell you Kafka JSON Schema to Avro What does not survive the conversion Kafka SASL JAAS Generator One login module, four syntaxes Kafka CLI Command Builder kcat is librdkafka, not Kafka

    Elsewhere on the site