Kafdeck v0.3 — Safe Data Explorer + Server-Side Masking
Kafdeck v0.3 — Safe Data Explorer + Server-Side Masking
Kafdeck v0.3 introduces bounded Kafka record inspection under the v0.2 Operator Identity/RBAC boundary while preserving Kafdeck's no-mutation posture.
Included capabilities
- separately authorized
record.readandrecord.export, - explicit topic/partition record browsing,
- earliest/latest/offset/timestamp navigation,
- bounded previous-page reconstruction,
- bounded live tail,
- key/value/header inspection,
- UTF-8 text, structured JSON and safe binary/hex projection,
- read-only Schema Registry-assisted Avro, Protobuf and JSON Schema decoding,
- bounded key/header/range/regex/CEL/jq-style filtering,
- authoritative server-side masking/redaction before browser/API/export,
- fail-closed behavior when mandatory structured masking cannot be safely applied,
- bounded JSON, NDJSON and CSV export,
- explicit record/byte/time/rate/concurrency budgets,
- cancellation and per-cluster/global record-read isolation,
- record-read/export security audit events,
- REST/OpenAPI and operator UI parity,
- benchmark/readiness evidence.
Security posture
- metadata permissions do not imply record access,
- export requires a separate permission,
- no masking bypass permission exists in v0.3,
- payloads are not persisted/indexed by default,
- clear record values are excluded from logs, traces, audit records and safe errors,
- Schema Registry access is read-only and used only for decoding,
- no arbitrary server-side JavaScript is executed,
- no general-purpose SQL stream engine is introduced.
Kafka safety posture
v0.3 remains non-mutating toward Kafka:
- no record production or replay,
- no topic/configuration mutation,
- no consumer-group offset mutation,
- no offset commit,
- no durable consumer subscription,
- no unbounded whole-topic scan.
Record reads use bounded explicit partition/range semantics with cancellation, deadlines and isolated bulkheads.
Compatibility
The governed release workflow validates the accepted compatibility matrix on the exact release source:
Tier 1:
- Apache Kafka 4.3.1
- Apache Kafka 4.2.1
- Apache Kafka 4.1.2
Tier 2:
- Apache Kafka 3.9.2
Performance evidence
The final W24 technical candidate recorded bounded in-process release microbenchmarks:
- structured filter: 20,000 operations / 83.371 ms / 239,890.99 ops/s,
- structured masking: 20,000 operations / 399.056 ms / 50,118.28 ops/s.
These measurements are implementation-level release evidence only. They are not Kafka end-to-end throughput figures or a public SLA.
Known limitations
- payload search is bounded scan, not persistent indexing,
- Schema Registry support in v0.3 is decode-only rather than a full subjects/versions explorer,
- live tail is bounded and non-durable,
- record payloads are not retained by Kafdeck,
- full Consumer Group/Lag read views remain deferred,
- Kafka mutations remain deferred.
Operator documentation
Record access, masking and export guidance is in docs/operator/v0.3-record-access-masking-guide.md.
Upgrade guidance from v0.2 is in docs/operator/v0.3-upgrade-guide.md.
Release evidence
Publication requires protected-main admission of the cumulative v0.3 source, exact-revision quality and Kafka compatibility gates, supply-chain evidence, High/Critical vulnerability scanning, keyless signing, immutable OCI digest promotion, and publication of tag v0.3 on the exact governed release SHA.
Immutable OCI image
ghcr.io/araditc/kafdeck@sha256:ac5178a7d6f1a08cb303979f4c6de66aa711b220468c193f3d16d1a91483628e
SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA fb2eb253dfa2b51d28c45e15f7d29ea1100fef85.