What Managed Takes Off You

What "Managed" Does and Doesn't Take Off Your Hands

A managed service takes over everything below the Kafka 129 protocol: machines, disks, the KRaft quorum, broker settings, patches, upgrades and failed brokers. Everything above it stays yours, because the provider cannot know what your events mean.

Who does what on each kind of Kafka platform
Task Self-managed Managed brokers Serverless
Brokers, disks, KRaft, upgrades You Provider Provider
Broker settings (Configuration Files) You Some, or none None
Topics, keys, partitions, retention You You You, within quotas
Schemas, ACLs, client settings, lag You You You
Second region for disaster recovery You Usually you Usually you

Limits replace knobs: serverless quotas refuse settings a broker would accept (MSK Serverless), and a free plan fixes retention (Aiven's Free Kafka Plan). Identity moves into the provider's model, and one region is still one region.

The protocol does not tie you to a provider (Aiven's Free Kafka Plan); the extras do: proprietary identity (MSK IAM, Entra ID), engines that speak Kafka but are not Kafka (Azure Event Hubs and Redpanda), vendor-only processing (ksqlDB's License and Status), governance that does not export (Stream Governance), and managed connectors outside Connect's REST API (MSK Connect). Each is a step in A Migration Runbook.