Skip to content

Kafdeck v0.4 — Consumers, Schemas & Ecosystem Read Views

Choose a tag to compare

@github-actions github-actions released this 21 Sep 13:51
e224260

Kafdeck v0.4 — Consumers, Schemas & Ecosystem Read Views

Kafdeck v0.4 expands the read-only control plane with consumer-group diagnostics, Schema Registry exploration, and bounded ecosystem read views while preserving the released v0.3 data-access boundary and no-mutation posture.

Included capabilities

  • separately authorized consumer.read, schema.read, connect.read, ksql.read, and catalog.read,
  • consumer group state, members and assignments,
  • committed offsets, end offsets, per-partition lag and aggregate lag,
  • explicit missing/out-of-range/unauthorized/partial lag states,
  • evidence-based consumer diagnostics with explicit unavailable metrics/history,
  • Schema Registry subjects, versions, references and schema detail,
  • bounded local schema diff,
  • read-only compatibility-mode inspection,
  • Kafka Connect worker, connector and task status,
  • fail-closed connector configuration projection,
  • bounded/redacted connector task traces,
  • GET-only ksqlDB info/health discovery,
  • explicit unsupported state where ksqlDB metadata would require statement execution,
  • configuration-owned topic catalog metadata foundations,
  • REST/OpenAPI/operator UI parity.

Security posture

v0.4 adds no mutation surface:

  • no Kafka produce/replay,
  • no consumer offset commit/reset/shift/delete,
  • no topic/configuration mutation,
  • no Schema Registry mutation,
  • no Connect create/update/delete/pause/resume/restart,
  • no ksqlDB statement/query execution,
  • no generic upstream HTTP proxy,
  • no arbitrary server-side JavaScript,
  • no masking bypass.

All new read permissions remain independent from record.read and record.export.

External ecosystem endpoints are deployment-configured, bounded, cancellable, redirect-restricted and isolated by separate concurrency bulkheads.

Consumer truthfulness rules

  • an offset beyond the observed log end is out-of-range, not zero lag,
  • missing committed offsets are explicit,
  • partial Kafka authorization remains explicit,
  • unknown is never represented as zero,
  • metrics/history are unavailable unless an explicit provider supplies trustworthy evidence,
  • current observation is not labeled historical analysis.

Schema Registry posture

The registry explorer uses read-only GET operations only.

Compatibility provenance is determined by subject-specific configuration first and global fallback only when the subject has no override.

Schema diff executes locally under input-size/line bounds.

Kafka Connect posture

Connector configuration is fail-closed: only a small explicit allowlist of operational fields may expose values; all other plugin-defined values are redacted.

Task traces are bounded and credential-like values are redacted.

ksqlDB posture

v0.4 supports server info/health through genuine read-only endpoints.

Kafdeck does not execute SHOW, DESCRIBE, arbitrary SQL, or metadata statements. When metadata discovery requires statement execution, the capability is reported unsupported.

Compatibility

Kafka consumer-group behavior is validated against the governed matrix:

Tier 1:

  • Apache Kafka 4.3.1
  • Apache Kafka 4.2.1
  • Apache Kafka 4.1.2

Tier 2:

  • Apache Kafka 3.9.2

Schema Registry, Connect and ksqlDB claims are capability/profile evidence, not blanket Kafka-provider equivalence.

Known limitations

  • no mandatory durable consumer metrics/history provider,
  • no historical rebalance analysis without an explicit history provider,
  • one optional Connect profile and one optional ksqlDB profile per Kafka cluster,
  • ksqlDB stream/table discovery is unsupported when statement execution is required,
  • topic catalog metadata is configuration-owned and descriptive only,
  • no ecosystem mutation.

Operator documentation

  • docs/operator/v0.4-read-views-guide.md
  • docs/operator/v0.4-upgrade-guide.md

Release governance

The exact technical candidate a94b3baa415f32b7b8420c4bc398f405fa674709 passed the required quality, security, compatibility, benchmark, review-thread, supply-chain and CODEOWNER gates and was admitted through PR #118 as protected-main commit b05b61f1835effcee78a7aef4d6eb481faba8915.

Ammar explicitly approved the v0.4 Release Decision on 2026-09-21. Publication is armed only through a separate governed promotion of the approved v0.4 identity into .github/release/release.json; the protected-main publication source must still complete the exact release workflow before tag/image/GitHub Release publication is considered complete.

Immutable OCI image

ghcr.io/araditc/kafdeck@sha256:8183ced585bd6eb73bf280f4ded5751e2ffc9370b1e170e0b9074a3acc9e2ed1

SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA e22426026d4f03f675df703773ca072ed7ea0f03.