shouldiuse.io

Report

Should I Use Kestra, Open Source Declarative Orchestration Platform?

kestra.io·Analyzed 19 hours ago··Based on 12 sources

Use declarative language to build simpler, faster, scalable and flexible workflows

Depends

Depends

Buy if your engineering team needs unified scheduled and event-driven orchestration for data or AI pipelines and can self-host and patch fast.

Powerful open-source orchestrator for engineers; recent tenant-isolation CVEs and self-host burden make it overkill for simple automation.

Confidence: Medium

26,000+

GitHub stars

Java-based orchestration engine

$36M

Total funding

Last funded March 2026

24

G2 reviews

Thin independent review base

Yes

Free tier

Open source, self-hosted

Value for money4

Free self-host tier; claims 90% lower legacy tooling cost.

Ease of use4

Declarative YAML plus no-code UI for analysts.

Feature depth5

Scheduled, event-driven, durable execution, multi-tenancy, AI orchestration.

Support quality3

SLA-backed enterprise support offered; quality unverified.

Security posture2

11 CVEs in 90 days, tenant isolation flaws.

Pros

  • Open source; self-host free on Docker or Kubernetes²
  • 26,000+ GitHub stars, strong community traction
  • Declarative YAML with no-code UI for non-engineers11
  • Built-in retries, backfills, and failure handling for production³
  • Unifies scheduled and event-driven automation in one platform²

Cons

  • 11 vulnerabilities in last 90 days; 8 rated high or above
  • Path traversal CVE allowed reading files across tenants
  • Enterprise pricing hidden behind demo calls³
  • Only 24 G2 reviews; thin independent feedback

Gotchas

  • highOne recent CVE flagged known-exploited; run 1.3.24+ or isolate the instance.
  • highMulti-tenancy storage isolation breach; fixed only in 1.0.45 and 1.3.23.
  • mediumNo public enterprise pricing; expect custom quotes and a sales cycle.³
  • mediumSelf-hosting means you own upgrades, backups, and security patching.²

Best for

  • Data platform teams
  • AI/ML pipeline orchestration
  • GitOps-driven engineering orgs
  • Teams replacing legacy schedulers

Not for

  • Small teams wanting Zapier-style simple automation
  • Teams without DevOps or Kubernetes capacity
  • Anyone slow to patch — active tenant-isolation CVEs
  • Buyers needing transparent public pricing

Pricing

Open Source

Free

  • Self-host on Docker or Kubernetes
  • Core orchestration features

Cloud

Not disclosed

  • Managed hosting
  • Pricing not published

Enterprise

Not disclosed

  • SLA-backed support
  • SSO, dedicated customer success

Security

Multiple recent CVEs including tenant isolation flaws; upgrade to 1.3.24+ before production use.

  • CVE-2026-55069 — BasicAuth flawVulnerability in BasicAuth authentication affects versions prior to 1.3.24.
  • CVE-2026-49984 — Path traversalAllows attackers to read sensitive files across tenants.
  • Multi-tenancy isolation breachComplete breach of storage isolation and multi-tenancy boundary; fixed in 1.0.45 and 1.3.23.

What users say

Independent reviews are thin — 24 G2 reviews — but Reddit and GitHub community sentiment is positive.

the existing orchestration tools are either too technical
Reddit, r/opensource

Alternatives

Compare Kestra, Open Source Declarative Orchestration Platform with each alternative.

n8n

Guess: visual automation; better fit for non-engineers.

Full analysis

Based on ~20 public sources; official claims dominate and independent user reviews are thin.

Sources

  1. official
  2. official
  3. official
  4. official
  5. security
  6. security
  7. OpenCVE — Kestra vendor CVEsopencve.alliance.unm.edu
    security
  8. security
  9. review
  10. review
  11. news
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.

    Comments

    One queue. No replies. Give a display name first. Limit: 7 comments per day.

    Save a name to write a comment.

    No comments yet.