Kafdeck v0.2 — Operator Identity/RBAC
Kafdeck v0.2 — Operator Identity/RBAC Release Notes
Kafdeck v0.2 adds governed operator identity and authorization while preserving the read-only Kafka boundary established in v0.1.
Included capabilities
- OIDC Authorization Code + PKCE operator sign-in with server-side sessions,
- explicit Local, Token, and OIDC access modes with no OIDC-to-token fallback,
- immutable, default-deny RBAC policy evaluation,
- subject and external-group role bindings,
- action-, cluster-, and resource-scoped authorization,
- backend-authoritative API enforcement with corresponding operator UI behavior,
- structured security audit events for authentication, authorization denials, sensitive configuration reads, and legacy deployment-token boundary events,
- upgrade and rollback guidance for existing v0.1 deployments.
Security posture
- no Kafka mutation endpoint or UI control,
- no record production/consumption or payload browser,
- deployment tokens are not treated as operator identity,
- unbound identities and ungranted actions fail closed,
- OIDC tokens, session cookies, deployment tokens, and Kafka credentials are excluded from API/log/audit output,
- Kafka ACL denial remains distinct from Kafdeck RBAC denial,
- non-loopback OIDC deployments require HTTPS and normal platform trust validation; TLS verification cannot be disabled.
Compatibility
v0.2 preserves the v0.1 Local and Token deployment modes. Kafka access remains metadata/configuration read-only. The governed release workflow re-runs the accepted Kafka compatibility matrix against the exact release source revision.
Known limitations
- application sessions are intentionally invalidated by restart,
- durable shared session state is not part of v0.2,
- durable audit-history storage is not part of v0.2,
- identity-provider reachability and private-CA trust remain deployment responsibilities,
- v0.2 does not introduce Kafka mutation or payload access.
Operator documentation
OIDC/RBAC deployment guidance is in docs/operator/v0.2-oidc-rbac-guide.md. Upgrade and rollback guidance is in docs/operator/v0.2-upgrade-guide.md.
Release evidence
Publication requires the approved release delta on protected main, exact-revision quality and Kafka compatibility gates, independent review, supply-chain evidence, immutable OCI digest promotion, keyless signing, and publication of tag v0.2 on the exact release SHA.
Immutable OCI image
ghcr.io/araditc/kafdeck@sha256:759ca8e8b3d5491941dcfb1de8b76b7aeffd01a275204238e541d09e5de186f5
SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA 9fef5736ddd5c40854d12ad89afd9489987e808f.