Tech riderRev. 2 Oct 2026
  1. 1Runs onAPI, Linux, Mac, self-hosted, Web
  2. 2CostsFree plan
  3. 3Deployment modelself hosted
  4. 4Proxy architecturesidecar
  5. 5mTLS supportYes
  6. 6Traffic policiesYes
  7. 7Multi-cluster supportYes
  8. 8Supported platformsKubernetes, OpenShift, Universal (VMs), bare metal
8 lines stated Written from the maker's own pages: kuma.io
The Kuma homepage

Overview

Kuma is an open-source control plane for managing service meshes and microservices across Kubernetes, virtual machines, and bare-metal environments. It supports single-zone or multi-zone deployments across clouds, regions, and Kubernetes clusters, and one control plane can serve multiple meshes. Its traffic policies cover HTTP and TCP routing, health checks, circuit breaking, retries, timeouts, fault injection, and rate limiting. Security features include mutual TLS and mesh traffic permissions. Observability includes service maps, traces, access logs, metrics, and OpenTelemetry, with documented integrations for Prometheus, Grafana, Jaeger, and Datadog. Interfaces include Kubernetes CRDs, a GUI, a REST API, and a CLI; Envoy is bundled as the data-plane proxy. Kuma is self-hosted and available under a free open-source plan. Its installation guide provides Linux and macOS downloads, and documents macOS CLI installation through Homebrew. The Kubernetes quickstart describes the GUI as read-only. Production guidance covers secrets management, API access and authentication, proxy membership, certificates, and Kubernetes RBAC.

Who it is for

Kuma suits teams managing service meshes across Kubernetes, VMs, or bare metal, including multi-zone or multi-mesh deployments. It is for organizations prepared to self-host and configure production security.

What is good

  • Supports Kubernetes, VMs, and bare-metal environments.
  • One control plane can support multiple meshes.
  • Traffic policies include retries, timeouts, and rate limiting.
  • Provides CRDs, GUI, REST API, and CLI.

What to know first

  • Self-hosted deployment requires operating the control plane.
  • The Kubernetes quickstart describes the GUI as read-only.
  • Production setup includes security configuration for APIs and certificates.

Verdict

Kuma offers a broad set of traffic, security, and observability capabilities across varied deployment environments. Plan for self-hosting, and note that the GUI is read-only in the Kubernetes quickstart context.

Kuma plans and pricing

All plans
Open source Free Open-source control plane; supports Kubernetes, VMs, and bare metal kuma.io · 2 Oct 2026

Compared on service mesh platforms

Deployment model
self_hostedkuma.io
Proxy architecture
sidecarkuma.io
mTLS support
Yeskuma.io
Traffic policies
Yeskuma.io
Multi-cluster support
Yeskuma.io
Supported platforms
Kubernetes, OpenShift, Universal (VMs), bare metalkuma.io

Facts

Purpose
Kuma is an open-source control plane for service mesh and microservices management.kuma.io · 2 Oct 2026
Workloads
It supports Kubernetes, virtual machines, and bare-metal environments.kuma.io · 2 Oct 2026
Deployment
Kuma supports single-zone and multi-zone deployments across clouds, regions, and Kubernetes clusters.kuma.io · 2 Oct 2026
Multi-mesh
One control plane can support multiple individual meshes.kuma.io · 2 Oct 2026
Security
Listed security features include multi-mesh, mutual TLS, and mesh traffic permissions.kuma.io · 2 Oct 2026
Observability
Listed observability features include service maps, traces, access logs, metrics, and OpenTelemetry.kuma.io · 2 Oct 2026
Integrations
Kuma's observability documentation describes integrations with Prometheus, Grafana, Jaeger, and Datadog.kuma.io · 2 Oct 2026
Interface
Kuma provides native Kubernetes CRDs, a GUI, a REST API, and a CLI.kuma.io · 2 Oct 2026
Runtime
Kuma bundles Envoy as its data plane proxy.kuma.io · 2 Oct 2026
Install
The installation guide provides Linux and macOS downloads and documents installing the CLI on macOS with Homebrew.kuma.io · 2 Oct 2026
Deployment security
Production guidance covers secrets management, API access control, API server and proxy authentication, proxy membership, certificates, and Kubernetes RBAC.kuma.io · 2 Oct 2026
GUI limitation
The Kubernetes quickstart describes Kuma's GUI as read-only.kuma.io · 2 Oct 2026
Maintainer
The documentation identifies Kong as Kuma's core maintainer.kuma.io · 2 Oct 2026

Best Kuma alternatives

See all 19

Where it ranks on Specifiction

Is Kuma yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources