Sign inSign up

orchestalabs/broka-orchestrator

By orchestalabs

•Updated about 4 hours ago

BROKA is a self-hosted operations console for message brokers.

Image
Developer tools
Monitoring & observability
0

1.1K

orchestalabs/broka-orchestrator repository overview

⁠BROKA — API service (broka-orchestrator)

The API behind the BROKA console: users, teams, roles, environments, connections, settings, alerts and the sealed audit trail. It keeps its state in PostgreSQL, applies its database migrations as it starts, and runs as a single replica by design. Broker credentials are stored encrypted with the key-encrypting key (BROKA_KEK) you provide. It is called by broka-ui and broka-broker on the Compose network and publishes no port.

Health checks: GET /health (liveness) and GET /health/ready (with a database check).

⁠What BROKA is

BROKA is a self-hosted operations console for message brokers. BROKA Community is free, runs on your own infrastructure and needs no account. It covers Apache Kafka and Kafka-compatible brokers: clusters, brokers, topics, consumer groups and lag, ACLs, Schema Registry, producing and browsing messages, with roles, environments and a tamper-evident audit trail around every change.

  • Read-only and guarded environments; a reason is asked before destructive operations.
  • Offset resets are previewed before anything moves, and each partition's before and after goes to the audit trail.
  • One permission model and one audit trail across every connection.

BROKA Commercial adds Redis, RabbitMQ, Apache Artemis and Memcached. Its images are not published here.

⁠Run it

BROKA runs as four containers: broka-ui, broka-orchestrator, broka-broker and PostgreSQL. They are not meant to be run one by one; the Compose recipe wires them together.

  1. Download compose.yml and .env.example from https://broka.dev/download⁠ into a directory of their own.

  2. Copy .env.example to .env and generate the four secrets it asks for. The Compose file ships no defaults: while one is empty, docker compose up stops before creating any container. Keep BROKA_KEK safe: replace it and every stored broker credential becomes unreadable.

  3. Start it:

    docker compose up -d
    
  4. Open http://localhost:3000 (or the address your reverse proxy serves) and create the first administrator.

Full guide: https://broka.dev/docs/deployment/docker-compose⁠ · Production checklist: https://broka.dev/guides/production-deployment-checklist⁠

⁠Verify the image

Every image is signed with BROKA's image-signing key and carries a CycloneDX SBOM attestation. With cosign 3 or later, for the version you run:

cosign verify --key https://broka.dev/keys/cosign.pub orchestalabs/broka-orchestrator:<version>
cosign verify-attestation --key https://broka.dev/keys/cosign.pub --type cyclonedx orchestalabs/broka-orchestrator:<version> > /dev/null

⁠Tags

TagMeaning
x.y.zOne release. Pin this in production (BROKA_VERSION in .env)
x.yLatest patch of that minor release
latestLatest release
sha-…The commit the image was built from

The Tags tab lists every published version; the release notes say what each one changed. Images are built for linux/amd64. Run the same version of all three images together.

⁠Licence

BROKA is distributed under the BROKA Licence Agreement (https://broka.dev/licence⁠), which you accept by running a BROKA image. Community is free of charge; it is not open-source software.

Tag summary

Content type

Image

Digest

sha256:7bac433b5…

Size

105.7 MB

Last updated

about 4 hours ago

docker pull orchestalabs/broka-orchestrator