Every fact about the cluster (brokers, topics, leaders, ISRs, configurations, ACLs) is a record in the single-partition topic __cluster_metadata, replicated by the controllers with KRaft, Kafka 129 's Raft variant. The voters elect one active controller, the only writer; a record commits once a majority has it, so three controllers survive one failure and five survive two. Brokers are observers: they fetch the log without voting and apply it to their in-memory view. A broker that misses heartbeats is fenced and loses its leaderships, as in The In-Sync Replica Set.
# How far every voter and observer has replicated the KRaft metadata log
docker exec l3-c1 /opt/kafka/bin/kafka-metadata-quorum.sh --bootstrap-controller l3-c1:9093 \
describe --replication | awk '{printf "%-7s %-13s %-4s %s\n", $1, $3, $4, $7}'NodeId LogEndOffset Lag Status 3 898 0 Leader 1 898 0 Follower 2 898 0 Follower 6 898 0 Observer 4 898 0 Observer 5 898 0 Observer
Controller 3 leads and every node has the whole log. Controllers also write periodic snapshots, so a restarting node loads a snapshot and a short tail. --bootstrap-controller reaches the quorum even with no broker up.