Kafdeck v0.5 — Safe Administration & Controlled Mutations
Kafdeck v0.5 — Safe Administration & Controlled Mutations
Kafdeck v0.5 adds governed administrative mutation workflows on top of the read-only foundations from v0.4. Mutation execution is explicit, bounded, durable, authorization-aware, risk-classified, previewed before execution, independently approved where required, and designed to preserve truthful outcomes when provider effects are ambiguous.
Included capabilities
- durable mutation operation state, idempotency, resource claims and recovery semantics,
- server-owned risk floors with independent approval for CRITICAL operations,
- stale-preview and current-state precondition revalidation,
- governed topic administration,
- bounded single/batch/template-assisted Kafka record production,
- consumer group and offset administration,
- Schema Registry register/config/delete workflows,
- Kafka Connect create/update/delete/pause/resume/restart workflows,
- controlled DeleteRecords purge with explicit partition/offset targets,
- REST/OpenAPI and operator UI workflows for preview, confirm, approve, reject, cancel and status,
- explicit ExecutionUnknown handling for potentially-applied ambiguous outcomes,
- SQLite standalone and PostgreSQL HA persistence paths,
- upgrade, backup/restore, rollback and operator guidance.
Safety invariants
v0.5 deliberately does not introduce a broad admin bypass or generic provider command surface.
- read permissions do not imply mutation permissions,
- raw Kafka payloads and secrets are not durably staged by default,
- record-production execution material is ephemeral and digest-bound to preview,
- no blind retry occurs after a potentially applied dispatch,
- ambiguous provider outcomes remain ExecutionUnknown unless bounded verification supports a stronger state,
- no arbitrary Kafka producer configuration passthrough,
- no generic Kafka CLI/AdminClient or provider REST proxy,
- no arbitrary JavaScript, SQL, shell or serializer/runtime execution,
- destructive purge requires explicit bounded targets and CRITICAL governance where applicable.
Governed mutation areas
Topics
Create topic, allowlisted configuration changes, partition increases and topic deletion use typed provider ports, finite materialized targets, current-state fingerprints and verification readback.
Record production
Single, batch and template-assisted production enforce record/byte/header ceilings, exact-topic record.produce authorization, optional schema validation, HMAC-bound ephemeral execution material, broker acknowledgement evidence and payload-leakage protections.
Consumer groups and offsets
Offset resolution, reset/alter/delete operations preserve group-state preconditions, explicit target previews and post-operation verification.
Schema Registry
Typed fixed-route mutations cover schema registration/new versions, compatibility configuration and governed deletion semantics without exposing a generic registry write proxy.
Kafka Connect
Connector lifecycle mutations use a fixed-route adapter, secret-safe diffs, bounded request/response handling, redirect/origin restrictions and typed operations.
Controlled purge
DeleteRecords is restricted to explicit partition/offset targets or bounded timestamp resolution into frozen offsets. Whole-topic wildcard purge is not provided.
Compatibility and readiness
Kafka behavior is validated against the governed matrix:
Tier 1:
- Apache Kafka 4.3.1
- Apache Kafka 4.2.1
- Apache Kafka 4.1.2
Tier 2:
- Apache Kafka 3.9.2
W40 readiness also reconciled security/threat-model coverage, Schema Registry and Kafka Connect mutation fixtures, SQLite/PostgreSQL persistence and recovery, ambiguous-outcome fault handling, boundedness evidence, regression benchmarks and operator documentation.
Upgrade and operation
Review the v0.5 operator and upgrade guidance before enabling mutation features. Mutation runtime activation remains fail-closed unless deployment prerequisites, persistence and authorization integration requirements are satisfied.
Release governance
Implementation W32-W40 was governed-admitted through protected main, culminating in PR #141 and protected-main commit 9441697248a09694b54d84b390725511f138dcfd.
Ammar explicitly approved the v0.5 release decision on 2026-09-23. Publication is armed only by promotion of the v0.5 identity through .github/release/release.json. The protected-main publication workflow must complete its exact-revision quality, Kafka compatibility, SBOM, High/Critical vulnerability scan, keyless signing, immutable OCI promotion and GitHub Release steps before publication is considered complete.
Immutable OCI image
ghcr.io/araditc/kafdeck@sha256:37196487ae5869144bdde312c92aafdd300c7f411473077b901ca368fabcfcab
SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA 0901b6b7c4c8c580268e05d1b7c04ec591d2e5cf.