Skip to content

Kafdeck v0.1 — Cluster Explorer

Choose a tag to compare

@github-actions github-actions released this 19 Sep 18:59
137142b

Kafdeck v0.1 — Cluster Explorer Release Notes

Kafdeck v0.1 is the first release candidate of the read-only, multi-cluster Cluster Explorer.

Included capabilities

  • configured multi-cluster discovery with isolated Kafka clients and caches,
  • cluster, controller and broker visibility with explainable health,
  • searchable topic exploration with bounded pagination,
  • partition leader/replica/ISR and anomaly visibility,
  • on-demand broker/topic configuration reads subject to Kafka authorization,
  • explicit fresh/stale/partial/denied/unavailable observation states,
  • React operator UI and versioned /api/v1 HTTP surface,
  • single non-root OCI image for UI + API,
  • local-first deployment with token-gated non-loopback access,
  • TLS, mTLS, SASL PLAIN and SCRAM connection support within the accepted matrix.

Kafka compatibility baseline

Tier 1:

  • Apache Kafka 4.3.1
  • Apache Kafka 4.2.1
  • Apache Kafka 4.1.2

Tier 2:

  • Apache Kafka 3.9.2

The release gate re-runs the compatibility/security matrix against the exact release source revision.

Security and supply chain

  • no Kafka mutation endpoint or UI control,
  • no Kafka payload browsing,
  • no durable persistence of Kafka passwords/private-key passwords,
  • secret references for deployment and Kafka credentials,
  • non-loopback access fails closed without the deployment token,
  • exact-digest SBOM and High/Critical vulnerability scan,
  • locked dependency restore,
  • keyless Sigstore/cosign signing of the published OCI digest,
  • SHA-pinned third-party GitHub Actions.

The release-specific threat-model delta is documented in docs/security/v0.1-release-threat-model-delta.md.

Known limitations

  • the deployment token is a deployment boundary, not human identity/RBAC,
  • v0.1 is intentionally read-only,
  • no topic/group/ACL/broker mutation is supported,
  • no record production/consumption or payload browser is included,
  • operational health reflects bounded Kafka admin-read observations, not end-to-end application health,
  • supported Kafka versions are limited to the documented release matrix.

Operator documentation

Deployment, configuration, air-gapped operation, authentication bootstrap, troubleshooting and security guidance are in docs/operator/v0.1-operator-guide.md.

Release evidence

Publication requires the accepted release commit on main, all applicable exact-revision gates green, independent review of this final release delta, active Phase 0 repository controls, and successful tagged release supply-chain evidence.

Immutable OCI image

ghcr.io/araditc/kafdeck@sha256:ef82b45c5b74e2a0346c9226f9aae6c19d898f1acc231620088b04e2b74ab3ae

SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA 137142bc3733fe3354e2941b8c09ce7d63326741.