Skip to content

Kafdeck v0.3 — Safe Data Explorer + Server-Side Masking

Choose a tag to compare

@github-actions github-actions released this 21 Sep 07:56
fb2eb25

Kafdeck v0.3 — Safe Data Explorer + Server-Side Masking

Kafdeck v0.3 introduces bounded Kafka record inspection under the v0.2 Operator Identity/RBAC boundary while preserving Kafdeck's no-mutation posture.

Included capabilities

  • separately authorized record.read and record.export,
  • explicit topic/partition record browsing,
  • earliest/latest/offset/timestamp navigation,
  • bounded previous-page reconstruction,
  • bounded live tail,
  • key/value/header inspection,
  • UTF-8 text, structured JSON and safe binary/hex projection,
  • read-only Schema Registry-assisted Avro, Protobuf and JSON Schema decoding,
  • bounded key/header/range/regex/CEL/jq-style filtering,
  • authoritative server-side masking/redaction before browser/API/export,
  • fail-closed behavior when mandatory structured masking cannot be safely applied,
  • bounded JSON, NDJSON and CSV export,
  • explicit record/byte/time/rate/concurrency budgets,
  • cancellation and per-cluster/global record-read isolation,
  • record-read/export security audit events,
  • REST/OpenAPI and operator UI parity,
  • benchmark/readiness evidence.

Security posture

  • metadata permissions do not imply record access,
  • export requires a separate permission,
  • no masking bypass permission exists in v0.3,
  • payloads are not persisted/indexed by default,
  • clear record values are excluded from logs, traces, audit records and safe errors,
  • Schema Registry access is read-only and used only for decoding,
  • no arbitrary server-side JavaScript is executed,
  • no general-purpose SQL stream engine is introduced.

Kafka safety posture

v0.3 remains non-mutating toward Kafka:

  • no record production or replay,
  • no topic/configuration mutation,
  • no consumer-group offset mutation,
  • no offset commit,
  • no durable consumer subscription,
  • no unbounded whole-topic scan.

Record reads use bounded explicit partition/range semantics with cancellation, deadlines and isolated bulkheads.

Compatibility

The governed release workflow validates the accepted compatibility matrix on the exact release source:

Tier 1:

  • Apache Kafka 4.3.1
  • Apache Kafka 4.2.1
  • Apache Kafka 4.1.2

Tier 2:

  • Apache Kafka 3.9.2

Performance evidence

The final W24 technical candidate recorded bounded in-process release microbenchmarks:

  • structured filter: 20,000 operations / 83.371 ms / 239,890.99 ops/s,
  • structured masking: 20,000 operations / 399.056 ms / 50,118.28 ops/s.

These measurements are implementation-level release evidence only. They are not Kafka end-to-end throughput figures or a public SLA.

Known limitations

  • payload search is bounded scan, not persistent indexing,
  • Schema Registry support in v0.3 is decode-only rather than a full subjects/versions explorer,
  • live tail is bounded and non-durable,
  • record payloads are not retained by Kafdeck,
  • full Consumer Group/Lag read views remain deferred,
  • Kafka mutations remain deferred.

Operator documentation

Record access, masking and export guidance is in docs/operator/v0.3-record-access-masking-guide.md.

Upgrade guidance from v0.2 is in docs/operator/v0.3-upgrade-guide.md.

Release evidence

Publication requires protected-main admission of the cumulative v0.3 source, exact-revision quality and Kafka compatibility gates, supply-chain evidence, High/Critical vulnerability scanning, keyless signing, immutable OCI digest promotion, and publication of tag v0.3 on the exact governed release SHA.

Immutable OCI image

ghcr.io/araditc/kafdeck@sha256:ac5178a7d6f1a08cb303979f4c6de66aa711b220468c193f3d16d1a91483628e

SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA fb2eb253dfa2b51d28c45e15f7d29ea1100fef85.