Kuma
Universal service mesh platform supporting Kubernetes and VMs with multi-zone deployment capabilities
- Vendor
- Kong
- Also known as
- kuma
Available worldwide
What is Kuma?
Open-source control plane for service mesh delivering security, observability, routing and more. Built on Envoy with support for Kubernetes, VMs, and multi-cluster deployments.
Kuma pricing
We don't have Kuma's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
What Kuma does
The capabilities that matter for service mesh, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Data plane
- Sidecar
- Proxy
- Envoy
- Automatic mutual TLS
- ✓
- SPIFFE / SPIRE identity
- -
- Traffic splitting / canary
- ✓
- Fault injection / resilience
- ✓
- Multi-cluster federation
- ✓
- VM support (beyond Kubernetes)
- ✓
- Built-in observability
- ✓
- Gateway API / GAMMA support
- ✓
- WASM extensibility
- -
- FIPS mode
- -
- CNCF maturity
- Sandbox
- Commercial support / enterprise edition
- ✓
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
- Hybrid
- On-premise
Integrations (4)
Independently observed- Prometheus
- Grafana
- Datadog
- OpenTelemetry
Security & compliance
Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality
Kuma FAQ
Common questions about Kuma, answered from independent, dated evidence.
What is Kuma?
Open-source control plane for service mesh delivering security, observability, routing and more. Built on Envoy with support for Kubernetes, VMs, and multi-cluster deployments. It is indexed under Service Mesh.
Source: https://kuma.io
Is Kuma free to use?
Kuma is open source, so it can be self-hosted and used at no licence cost. It is released under the Apache-2.0 licence. Pricing changes often, so verify at source before relying on it.
Source: https://kuma.io
What platforms does Kuma support?
Kuma supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.
Source: https://kuma.io
Can Kuma be self-hosted?
Yes. Kuma can be deployed cloud / SaaS, hybrid, on-premise and self-hosted, so it does not have to run on the vendor's infrastructure.
Source: https://kuma.io
What does Kuma integrate with?
We have confirmed 4 integrations for Kuma, including Prometheus, Grafana, Datadog and OpenTelemetry. This is what we could verify from public sources, so the vendor may support others we have not indexed.
Source: https://kuma.io
What security certifications does Kuma have?
We have independently confirmed GDPR for Kuma. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Kuma not holding them. Always confirm compliance directly before you rely on it.
Source: https://kuma.io/privacy/
Is Kuma open source?
Yes. Kuma is published under the Apache-2.0 licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.
Source: https://github.com/kumahq/kuma
Where is Kuma available?
Kuma is available worldwide. The vendor is headquartered in the United States.
Source: https://kuma.io
Kuma alternatives
Other service mesh we track, ranked by the same independent score.
- AWS App Meshmedium · 63%
- Google Cloud Service MeshA fully managed service mesh platform built on Envoy and Istiolow · 40%
- ConsulA distributed service connectivity and configuration platform for multi-datacenter environmentsmedium · 51%
- Kong MeshA service mesh for connecting, managing, and securing workloads across any environmentlow · 38%
- LinkerdA minimal service mesh designed with security as a core priority for Kubernetes environmentsmedium · 54%
- IstioA service mesh platform for managing cloud-native application traffic, security, and observabilitymedium · 54%
Compare Kuma
Side by side against other service mesh, attribute by attribute, with a source on every value.
The vioscaleAI score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Kuma, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Development activity | 63 | 0.09 | 5.9 | ✓ |
| Capabilities | 92 | 0.06 | 5.8 | ✓ |
| Security score | 80 | 0.04 | 3.4 | ✓ |
| Stars | 68 | 0.03 | 1.8 | ✓ |
| Integrations | 14 | 0.07 | 1.0 | ✓ |
| Dependent projects | 16 | 0.06 | 1.0 | ✓ |
| Release cadence | 0 | 0.05 | 0.0 | - |
| Security posture | 10 | 0.12 | 0.0 | - |
| Package downloads | 0 | 0.14 | 0.0 | - |
| Developer Q&A activity | 0 | 0.06 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 100 | mediumsource · 2026-09-10 · 65% |
Adoption
Content
| Attribute | Value | Evidence |
|---|---|---|
| Faq | 8 items | mediumsource · 2026-09-10 · 68% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Proxy: envoy · Data plane: sidecar · Vm support: Yes · Multicluster: Yes · Cncf maturity: sandbox · Automatic mtls: Yes | mediumsource · 2026-09-10 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 2 | mediumsource · 2026-09-10 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Go | highsource · 2026-09-10 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | Apache-2.0 | highsource · 2026-09-10 · 95% |
Market
| Attribute | Value | Evidence |
|---|---|---|
| Availability | HqCountry: US · PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: … | highsource · 2026-08-13 · 75% |
Pricing
Release
| Attribute | Value | Evidence |
|---|---|---|
| History | 20 items | mediumsource · 2026-09-10 · 70% |
Security
| Attribute | Value | Evidence |
|---|---|---|
| Disclosure policy | Yes | mediumsource · 2026-08-13 · 60% |
| Gdpr | Yes | highsource · 2026-08-13 · 75% |
| Scorecard | 8 | highsource · 2026-09-10 · 90% |
| Vulnerabilities | Count: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fkumahq%2Fkuma%2Fpkg%2Ftransparentproxy%2Fistio&per_page=100 · Last 12m: 0 | highsource · 2026-09-10 · 90% |
Is Kuma the right choice for you?
Tell us the job, the constraints and what you weigh most, and we will rank Kuma against the rest of the service mesh we index, using the same dated evidence weighted your way.
Free to run, no account needed to start. How the evaluation works
Is this your product?
This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Kuma up or down: nobody can buy rank here, including you.
Take the badge
Live, always current, and free to use on your own site. It shows Kuma's independent score and links back to this profile.
<a href="https://www.vioscale.ai/software/kuma" target="_blank" rel="noopener">
<img src="https://www.vioscale.ai/badge/software/kuma.svg" alt="Kuma, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>Markdown, for a README →
[](https://www.vioscale.ai/software/kuma)Claim the profile
Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Kuma. Free, and it does not change the score.
- Correct anything wrong, with evidence
- Point our crawler at the pages that matter
- See which AI systems are reading this profile
Not the owner? How vendor profiles work