BROKA is a self-hosted operations console for message brokers.
1.1K
broka-orchestrator)The API behind the BROKA console: users, teams, roles, environments, connections, settings, alerts and the
sealed audit trail. It keeps its state in PostgreSQL, applies its database migrations as it starts, and runs as a
single replica by design. Broker credentials are stored encrypted with the key-encrypting key (BROKA_KEK) you
provide. It is called by broka-ui and broka-broker on the Compose network and publishes no port.
Health checks: GET /health (liveness) and GET /health/ready (with a database check).
BROKA is a self-hosted operations console for message brokers. BROKA Community is free, runs on your own infrastructure and needs no account. It covers Apache Kafka and Kafka-compatible brokers: clusters, brokers, topics, consumer groups and lag, ACLs, Schema Registry, producing and browsing messages, with roles, environments and a tamper-evident audit trail around every change.
BROKA Commercial adds Redis, RabbitMQ, Apache Artemis and Memcached. Its images are not published here.
BROKA runs as four containers: broka-ui, broka-orchestrator, broka-broker and PostgreSQL. They are not
meant to be run one by one; the Compose recipe wires them together.
Download compose.yml and .env.example from https://broka.dev/download into a directory of their own.
Copy .env.example to .env and generate the four secrets it asks for. The Compose file ships no defaults:
while one is empty, docker compose up stops before creating any container. Keep BROKA_KEK safe: replace it
and every stored broker credential becomes unreadable.
Start it:
docker compose up -d
Open http://localhost:3000 (or the address your reverse proxy serves) and create the first administrator.
Full guide: https://broka.dev/docs/deployment/docker-compose · Production checklist: https://broka.dev/guides/production-deployment-checklist
Every image is signed with BROKA's image-signing key and carries a CycloneDX SBOM attestation. With cosign 3 or later, for the version you run:
cosign verify --key https://broka.dev/keys/cosign.pub orchestalabs/broka-orchestrator:<version>
cosign verify-attestation --key https://broka.dev/keys/cosign.pub --type cyclonedx orchestalabs/broka-orchestrator:<version> > /dev/null
| Tag | Meaning |
|---|---|
x.y.z | One release. Pin this in production (BROKA_VERSION in .env) |
x.y | Latest patch of that minor release |
latest | Latest release |
sha-… | The commit the image was built from |
The Tags tab lists every published version; the release notes say what each one changed. Images are built for
linux/amd64. Run the same version of all three images together.
BROKA is distributed under the BROKA Licence Agreement (https://broka.dev/licence), which you accept by running a BROKA image. Community is free of charge; it is not open-source software.
Content type
Image
Digest
sha256:7bac433b5…
Size
105.7 MB
Last updated
about 4 hours ago
docker pull orchestalabs/broka-orchestrator