Kafka via SAP Cloud Connector (SCC)
Kafka via SAP Cloud Connector: Secure Hybrid Access Without Compromises
The KaTe Kafka Adapter now connects private Kafka infrastructure through SAP Cloud Connector while preserving full TLS, SNI and hostname verification.
KaTe GmbH has expanded the KaTe Kafka Adapter for SAP Integration Suite with secure private-network connectivity through SAP Cloud Connector. The update enables SAP Cloud Integration and SAP Edge Integration Cell to access private Kafka environments without changing broker advertisements or weakening TLS security.
Kafka brokers, Schema Registry services and OAuth 2.0 identity providers can each use SAP Cloud Connector or the public network independently. Therefore, hybrid Kafka architectures can follow the network and security design that fits each individual service.
Secure hybrid Kafka connectivity for SAP Integration Suite
For organisations that run Apache Kafka in hybrid environments, private Kafka brokers, Schema Registry services and OAuth 2.0 identity providers can now be reached through SAP Cloud Connector where required. At the same time, each endpoint can continue to use the public network independently when that is the right architectural choice.
This matters because Kafka landscapes rarely follow a one-size-fits-all network model. An organisation may operate private Kafka brokers while using a public identity provider, or it may keep its Schema Registry in a separate network zone. The KaTe Kafka Adapter for SAP Integration Suite supports these combinations without forcing every Kafka-related service through the same connection path.
No custom broker advertisement rewriting and no TLS compromises
A frequent challenge in hybrid Kafka deployments is handling the broker addresses advertised to clients. The updated adapter avoids custom broker advertisement rewriting for SAP Cloud Connector connectivity. Consequently, teams do not need to introduce an additional address-translation layer simply to establish secure access from SAP Integration Suite to private Kafka services.
Equally important, the connection preserves TLS, Server Name Indication (SNI) and hostname verification. Established certificate validation therefore remains in place instead of being bypassed to make a hybrid connection work.
What this update clarifies for SAP integration teams
The following points are part of this product announcement. They explain the practical impact of the update rather than presenting a separate FAQ.
Can SAP Integration Suite reach a private Kafka broker through SAP Cloud Connector?
Yes. The KaTe Kafka Adapter can connect SAP Cloud Integration to private Kafka brokers through SAP Cloud Connector. The same capability is available for SAP Edge Integration Cell, enabling hybrid integration architectures that combine cloud-based integration with private Kafka services.
Do Kafka, Schema Registry and OAuth 2.0 identity providers have to use the same network route?
No. Each endpoint can be configured independently. Kafka brokers, Schema Registry services and OAuth 2.0 identity providers can use SAP Cloud Connector or the public network according to the organisation’s network architecture and security requirements.
Does private connectivity require weaker TLS validation or custom address rewriting?
No. The integration preserves full TLS, SNI and hostname verification. It also does not require custom broker advertisement rewriting for the SAP Cloud Connector connection path.
A practical option for SAP Cloud Integration and Edge Integration Cell
The enhancement is designed for SAP integration teams that need to connect SAP systems with event-driven Kafka platforms across cloud and private network boundaries. Whether an architecture uses SAP Cloud Integration, SAP Edge Integration Cell or a combination of both, the adapter enables a clear separation between integration logic and network-routing decisions.
The result is true hybrid Kafka connectivity: private where necessary, public where appropriate and consistently secured throughout.
This product update is published by KaTe GmbH. For technical details and a discussion of your integration architecture, please use the Kafka Adapter product page linked above.
This could also be interesting for you:

