kafka-viewer
kafka-viewer is a lightweight local Streamlit UI for reading Kafka messages for inspection. Kafka connection details come from a local properties file. Consumer offsets are not committed or modified.
Installation
pip install kafka-viewer
Run
--config is mandatory.
kafka-viewer --config /path/to/kafka-viewer.properties
PowerShell:
kafka-viewer --config C:\path\to\kafka-viewer.properties
Configuration model
kafka-viewer uses one canonical naming convention:
- Kafka connection and consumer properties:
kafka.* - Schema Registry properties:
schema.registry.*
The parser also accepts selected Java/Spring-style aliases for compatibility (for example bootstrap.servers, ssl.truststore.location, spring.kafka.properties.*), then normalizes them into the canonical kafka.* format internally.
Configuration flow:
- Parse
.properties - Normalize aliases to
kafka.* - Validate security/SSL/SASL requirements
- Translate only supported settings into
kafka-pythonconsumer config - Report unsupported Kafka-related properties as warnings
Unknown properties are never blindly passed through to KafkaConsumer.
Supported Kafka security and connection capabilities
Supported protocols:
PLAINTEXTSSLSASL_PLAINTEXTSASL_SSL
Supported SASL mechanisms:
PLAINSCRAM-SHA-256SCRAM-SHA-512GSSAPIOAUTHBEARER
SASL credentials can be provided with either:
kafka.sasl.username+kafka.sasl.passwordkafka.sasl.jaas.config(username/password are extracted for PLAIN/SCRAM)
SSL, truststore, and keystore support
kafka-viewer supports both direct PEM paths and Java enterprise store formats.
Truststore properties:
kafka.ssl.truststore.locationkafka.ssl.truststore.type(PEM,JKS,PKCS12/PFX; optional, inferred from extension if omitted)kafka.ssl.truststore.password(used for JKS/PKCS12)kafka.ssl.truststore.cert.alias(optional JKS alias)
Keystore properties:
kafka.ssl.keystore.locationkafka.ssl.keystore.type(PEM,JKS,PKCS12/PFX; optional, inferred from extension if omitted)kafka.ssl.keystore.password(used for JKS/PKCS12)kafka.ssl.key.password(private key password or fallback decryption password)kafka.ssl.keystore.key.alias(optional JKS key alias)kafka.ssl.keystore.key.location(optional separate PEM key path)
Additional SSL properties:
kafka.ssl.endpoint.identification.algorithm(httpsornone/empty)kafka.ssl.check.hostnamekafka.ssl.protocolkafka.ssl.cipher.suiteskafka.ssl.cafilekafka.ssl.certfilekafka.ssl.keyfilekafka.ssl.passwordkafka.ssl.crlfile
For JKS/PKCS12 stores, kafka-viewer securely converts certificate and key material into short-lived local files for kafka-python. JKS conversion uses the Java keytool executable (must be available on PATH). Passwords and private key contents are never printed.
Configuration examples
Unsecured Kafka:
kafka.bootstrap.servers=localhost:9092
kafka.security.protocol=PLAINTEXT
SSL with truststore and PKCS12 keystore:
kafka.bootstrap.servers=localhost:9093
kafka.security.protocol=SSL
kafka.ssl.truststore.location=/path/to/truststore.jks
kafka.ssl.truststore.type=JKS
kafka.ssl.truststore.password=YOUR_TRUSTSTORE_PASSWORD
kafka.ssl.keystore.location=/path/to/client.p12
kafka.ssl.keystore.type=PKCS12
kafka.ssl.keystore.password=YOUR_KEYSTORE_PASSWORD
kafka.ssl.key.password=YOUR_KEY_PASSWORD
kafka.ssl.endpoint.identification.algorithm=https
SASL_SSL with PLAIN:
kafka.bootstrap.servers=localhost:9093
kafka.security.protocol=SASL_SSL
kafka.sasl.mechanism=PLAIN
kafka.sasl.username=YOUR_USERNAME
kafka.sasl.password=YOUR_PASSWORD
kafka.ssl.truststore.location=/path/to/ca.pem
kafka.ssl.truststore.type=PEM
SASL_SSL with JAAS-style credentials:
kafka.bootstrap.servers=localhost:9093
kafka.security.protocol=SASL_SSL
kafka.sasl.mechanism=SCRAM-SHA-512
kafka.sasl.jaas.config=org.apache.kafka.common.security.scram.ScramLoginModule required username="YOUR_USERNAME" password="YOUR_PASSWORD";
Schema Registry / Confluent Avro
Schema Registry support is optional.
- If
schema.registry.urlis missing, kafka-viewer uses raw/string/JSON value display behavior. - If configured, kafka-viewer attempts Confluent Avro deserialization.
- Schema Registry config stays separate from Kafka consumer config and is never passed to
KafkaConsumer.
Schema Registry example:
schema.registry.url=https://schema-registry.example.com
schema.registry.basic.auth.user.info=YOUR_USERNAME:YOUR_PASSWORD
Avro failures are non-fatal: kafka-viewer continues processing messages and shows bounded safe raw payload + safe error text for failed records.
UI consumer group generation
The UI supports:
- Manual consumer group entry
- Optional prefix input (
Group ID Prefix) Generate Temporary Group ID
If the prefix is empty, existing generation behavior is unchanged. If a prefix is set, the generated value is prefix + generated-id.
Offset behavior
kafka-viewer is intended for inspection. It does not commit consumer offsets or modify existing consumer-group progress.
Safety guidance
Keep real .properties files containing credentials out of source control. Use kafka-viewer.properties.example as a template only.
Limitations
This release provides broad practical connection/security compatibility for Kafka/Java/Spring-style deployment concepts, but not full parity with every Java client property.
Not supported:
- Protobuf deserialization
- Publishing messages
- Topic or consumer-group administration
- Arbitrary non-Kafka Java library properties
Development
python -m pytest
python -m build
Release files for kafka-viewer 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| kafka_viewer-0.3.0.tar.gz | 20.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| kafka_viewer-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 36.1 kB
Release files / kafka_viewer-0.3.0.tar.gz
| Download URL | kafka_viewer-0.3.0.tar.gz |
|---|---|
| Size | 20.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0ebac8f508388a05067620268aaf26d0ab1d63943a1dd656ab628b9689cd67da
|
|
BLAKE2b-256 checksum How to use checksums |
42d27152b9d004c2b2062174f0310ce3ad381285cc44eba0e06948b9ac6a2263
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.
Transparency logRelease files / kafka_viewer-0.3.0-py3-none-any.whl
| Download URL | kafka_viewer-0.3.0-py3-none-any.whl |
|---|---|
| Size | 15.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0c40ed1f117d006cce489072471c90bd3bee73a7e40f7f82b7841c47a5018c2e
|
|
BLAKE2b-256 checksum How to use checksums |
4ff95986a1e2e84d501bfd50ab0fecb0ae43ca56b542cf3fe3bfe0f093f8c386
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 24, 2026.
Transparency log