Kafdeck v0.4 — Consumers, Schemas & Ecosystem Read Views
Kafdeck v0.4 — Consumers, Schemas & Ecosystem Read Views
Kafdeck v0.4 expands the read-only control plane with consumer-group diagnostics, Schema Registry exploration, and bounded ecosystem read views while preserving the released v0.3 data-access boundary and no-mutation posture.
Included capabilities
- separately authorized
consumer.read,schema.read,connect.read,ksql.read, andcatalog.read, - consumer group state, members and assignments,
- committed offsets, end offsets, per-partition lag and aggregate lag,
- explicit missing/out-of-range/unauthorized/partial lag states,
- evidence-based consumer diagnostics with explicit unavailable metrics/history,
- Schema Registry subjects, versions, references and schema detail,
- bounded local schema diff,
- read-only compatibility-mode inspection,
- Kafka Connect worker, connector and task status,
- fail-closed connector configuration projection,
- bounded/redacted connector task traces,
- GET-only ksqlDB info/health discovery,
- explicit unsupported state where ksqlDB metadata would require statement execution,
- configuration-owned topic catalog metadata foundations,
- REST/OpenAPI/operator UI parity.
Security posture
v0.4 adds no mutation surface:
- no Kafka produce/replay,
- no consumer offset commit/reset/shift/delete,
- no topic/configuration mutation,
- no Schema Registry mutation,
- no Connect create/update/delete/pause/resume/restart,
- no ksqlDB statement/query execution,
- no generic upstream HTTP proxy,
- no arbitrary server-side JavaScript,
- no masking bypass.
All new read permissions remain independent from record.read and record.export.
External ecosystem endpoints are deployment-configured, bounded, cancellable, redirect-restricted and isolated by separate concurrency bulkheads.
Consumer truthfulness rules
- an offset beyond the observed log end is out-of-range, not zero lag,
- missing committed offsets are explicit,
- partial Kafka authorization remains explicit,
- unknown is never represented as zero,
- metrics/history are unavailable unless an explicit provider supplies trustworthy evidence,
- current observation is not labeled historical analysis.
Schema Registry posture
The registry explorer uses read-only GET operations only.
Compatibility provenance is determined by subject-specific configuration first and global fallback only when the subject has no override.
Schema diff executes locally under input-size/line bounds.
Kafka Connect posture
Connector configuration is fail-closed: only a small explicit allowlist of operational fields may expose values; all other plugin-defined values are redacted.
Task traces are bounded and credential-like values are redacted.
ksqlDB posture
v0.4 supports server info/health through genuine read-only endpoints.
Kafdeck does not execute SHOW, DESCRIBE, arbitrary SQL, or metadata statements. When metadata discovery requires statement execution, the capability is reported unsupported.
Compatibility
Kafka consumer-group behavior is validated against the governed matrix:
Tier 1:
- Apache Kafka 4.3.1
- Apache Kafka 4.2.1
- Apache Kafka 4.1.2
Tier 2:
- Apache Kafka 3.9.2
Schema Registry, Connect and ksqlDB claims are capability/profile evidence, not blanket Kafka-provider equivalence.
Known limitations
- no mandatory durable consumer metrics/history provider,
- no historical rebalance analysis without an explicit history provider,
- one optional Connect profile and one optional ksqlDB profile per Kafka cluster,
- ksqlDB stream/table discovery is unsupported when statement execution is required,
- topic catalog metadata is configuration-owned and descriptive only,
- no ecosystem mutation.
Operator documentation
docs/operator/v0.4-read-views-guide.mddocs/operator/v0.4-upgrade-guide.md
Release governance
The exact technical candidate a94b3baa415f32b7b8420c4bc398f405fa674709 passed the required quality, security, compatibility, benchmark, review-thread, supply-chain and CODEOWNER gates and was admitted through PR #118 as protected-main commit b05b61f1835effcee78a7aef4d6eb481faba8915.
Ammar explicitly approved the v0.4 Release Decision on 2026-09-21. Publication is armed only through a separate governed promotion of the approved v0.4 identity into .github/release/release.json; the protected-main publication source must still complete the exact release workflow before tag/image/GitHub Release publication is considered complete.
Immutable OCI image
ghcr.io/araditc/kafdeck@sha256:8183ced585bd6eb73bf280f4ded5751e2ffc9370b1e170e0b9074a3acc9e2ed1
SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA e22426026d4f03f675df703773ca072ed7ea0f03.