Kafdeck v0.1 — Cluster Explorer
Kafdeck v0.1 — Cluster Explorer Release Notes
Kafdeck v0.1 is the first release candidate of the read-only, multi-cluster Cluster Explorer.
Included capabilities
- configured multi-cluster discovery with isolated Kafka clients and caches,
- cluster, controller and broker visibility with explainable health,
- searchable topic exploration with bounded pagination,
- partition leader/replica/ISR and anomaly visibility,
- on-demand broker/topic configuration reads subject to Kafka authorization,
- explicit fresh/stale/partial/denied/unavailable observation states,
- React operator UI and versioned
/api/v1HTTP surface, - single non-root OCI image for UI + API,
- local-first deployment with token-gated non-loopback access,
- TLS, mTLS, SASL PLAIN and SCRAM connection support within the accepted matrix.
Kafka compatibility baseline
Tier 1:
- Apache Kafka 4.3.1
- Apache Kafka 4.2.1
- Apache Kafka 4.1.2
Tier 2:
- Apache Kafka 3.9.2
The release gate re-runs the compatibility/security matrix against the exact release source revision.
Security and supply chain
- no Kafka mutation endpoint or UI control,
- no Kafka payload browsing,
- no durable persistence of Kafka passwords/private-key passwords,
- secret references for deployment and Kafka credentials,
- non-loopback access fails closed without the deployment token,
- exact-digest SBOM and High/Critical vulnerability scan,
- locked dependency restore,
- keyless Sigstore/cosign signing of the published OCI digest,
- SHA-pinned third-party GitHub Actions.
The release-specific threat-model delta is documented in docs/security/v0.1-release-threat-model-delta.md.
Known limitations
- the deployment token is a deployment boundary, not human identity/RBAC,
- v0.1 is intentionally read-only,
- no topic/group/ACL/broker mutation is supported,
- no record production/consumption or payload browser is included,
- operational health reflects bounded Kafka admin-read observations, not end-to-end application health,
- supported Kafka versions are limited to the documented release matrix.
Operator documentation
Deployment, configuration, air-gapped operation, authentication bootstrap, troubleshooting and security guidance are in docs/operator/v0.1-operator-guide.md.
Release evidence
Publication requires the accepted release commit on main, all applicable exact-revision gates green, independent review of this final release delta, active Phase 0 repository controls, and successful tagged release supply-chain evidence.
Immutable OCI image
ghcr.io/araditc/kafdeck@sha256:ef82b45c5b74e2a0346c9226f9aae6c19d898f1acc231620088b04e2b74ab3ae
SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA 137142bc3733fe3354e2941b8c09ce7d63326741.