Skip to content

Kafdeck v0.2 — Operator Identity/RBAC

Choose a tag to compare

@github-actions github-actions released this 20 Sep 19:33
9fef573

Kafdeck v0.2 — Operator Identity/RBAC Release Notes

Kafdeck v0.2 adds governed operator identity and authorization while preserving the read-only Kafka boundary established in v0.1.

Included capabilities

  • OIDC Authorization Code + PKCE operator sign-in with server-side sessions,
  • explicit Local, Token, and OIDC access modes with no OIDC-to-token fallback,
  • immutable, default-deny RBAC policy evaluation,
  • subject and external-group role bindings,
  • action-, cluster-, and resource-scoped authorization,
  • backend-authoritative API enforcement with corresponding operator UI behavior,
  • structured security audit events for authentication, authorization denials, sensitive configuration reads, and legacy deployment-token boundary events,
  • upgrade and rollback guidance for existing v0.1 deployments.

Security posture

  • no Kafka mutation endpoint or UI control,
  • no record production/consumption or payload browser,
  • deployment tokens are not treated as operator identity,
  • unbound identities and ungranted actions fail closed,
  • OIDC tokens, session cookies, deployment tokens, and Kafka credentials are excluded from API/log/audit output,
  • Kafka ACL denial remains distinct from Kafdeck RBAC denial,
  • non-loopback OIDC deployments require HTTPS and normal platform trust validation; TLS verification cannot be disabled.

Compatibility

v0.2 preserves the v0.1 Local and Token deployment modes. Kafka access remains metadata/configuration read-only. The governed release workflow re-runs the accepted Kafka compatibility matrix against the exact release source revision.

Known limitations

  • application sessions are intentionally invalidated by restart,
  • durable shared session state is not part of v0.2,
  • durable audit-history storage is not part of v0.2,
  • identity-provider reachability and private-CA trust remain deployment responsibilities,
  • v0.2 does not introduce Kafka mutation or payload access.

Operator documentation

OIDC/RBAC deployment guidance is in docs/operator/v0.2-oidc-rbac-guide.md. Upgrade and rollback guidance is in docs/operator/v0.2-upgrade-guide.md.

Release evidence

Publication requires the approved release delta on protected main, exact-revision quality and Kafka compatibility gates, independent review, supply-chain evidence, immutable OCI digest promotion, keyless signing, and publication of tag v0.2 on the exact release SHA.

Immutable OCI image

ghcr.io/araditc/kafdeck@sha256:759ca8e8b3d5491941dcfb1de8b76b7aeffd01a275204238e541d09e5de186f5

SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA 9fef5736ddd5c40854d12ad89afd9489987e808f.