A managed service takes over everything below the Kafka 129 protocol: machines, disks, the KRaft quorum, broker settings, patches, upgrades and failed brokers. Everything above it stays yours, because the provider cannot know what your events mean.
| Task | Self-managed | Managed brokers | Serverless |
|---|---|---|---|
| Brokers, disks, KRaft, upgrades | You | Provider | Provider |
| Broker settings (Configuration Files) | You | Some, or none | None |
| Topics, keys, partitions, retention | You | You | You, within quotas |
| Schemas, ACLs, client settings, lag | You | You | You |
| Second region for disaster recovery | You | Usually you | Usually you |
Limits replace knobs: serverless quotas refuse settings a broker would accept (MSK Serverless), and a free plan fixes retention (Aiven's Free Kafka Plan). Identity moves into the provider's model, and one region is still one region.
The protocol does not tie you to a provider (Aiven's Free Kafka Plan); the extras do: proprietary identity (MSK IAM, Entra ID), engines that speak Kafka but are not Kafka (Azure Event Hubs and Redpanda), vendor-only processing (ksqlDB's License and Status), governance that does not export (Stream Governance), and managed connectors outside Connect's REST API (MSK Connect). Each is a step in A Migration Runbook.