KSML

This guide explains what KSML is, how the Axual Platform runs KSML applications, what they can connect to, and where each part of KSML is documented.

Type

Explanation

Goal

Understand how KSML applications run on the Axual Platform and which component is responsible for each part.

Audience

Platform Operators and architects planning or supporting KSML applications on an Axual installation.

When to use

Use this guide before enabling KSML on an Instance, or when deciding where a KSML question belongs.

Contents

What KSML is

KSML is Axual’s low-code stream processing language. A KSML application is a Kafka Streams topology written in YAML rather than in Java. The definition names the topics to read and write, and the operations between them. The KSML runner executes it as a Kafka Streams application.

KSML is open source and has its own release cycle. The component versions in the Axual 2026.3 Release Notes list the version a platform release ships with.

How the platform runs KSML applications

On the Axual Platform, nobody installs KSML directly. An application owner creates a Managed KSML application in Self-Service and supplies its definition, and the platform deploys and runs it. Three components share that work:

  • Self-Service and Platform Manager hold the application, its definition, its deployment size and its credentials.

  • The Runtime Provisioner receives start and stop requests from Platform Manager. It installs one release of the KSML Helm chart per application into its Kubernetes cluster.

  • The KSML runner inside each release executes the definition against the Kafka cluster.

Because the Runtime Provisioner owns the deployment, it is the only KSML-related component an operator installs. Operators decide how KSML applications are deployed, such as the namespace, service account and pod settings. These decisions go through the Provisioner’s configuration rather than through a KSML chart of their own. Before any application can start, a Tenant Admin must connect the Instance to a Provisioner.

Schemas and authentication

A KSML application reads and writes through the same Kafka cluster and schema registry as any other application on its Instance. It can use schemas from Apicurio Registry or from a Confluent-compatible registry, whichever the Instance is configured with. For Apicurio Registry, Platform Manager provisions the registry credentials automatically.

One limitation applies: a KSML application must use the same authentication method as the one configured for its Kafka cluster in Self-Service. On a cluster that offers several methods, the application can’t pick a different one.

Where KSML is documented

KSML documentation is split by who needs it: