Kafdeck v0.7 — Developer & Streaming Ecosystem Platform
Status: OWNER-AUTHORIZED v0.7 RELEASE NOTES
v0.7 is the owner-authorized release identity assembled by W51–W60 and selected by the governed release manifest. Publication is performed only by the protected-main release workflow after exact-head quality, compatibility, security and supply-chain gates succeed.
Highlights
Schema Registry lifecycle and developer tooling
- Confluent-compatible lifecycle capability truth;
- explicit Karapace-compatible profile;
- explicit Apicurio Unsupported state until a typed adapter is admitted;
- Avro, Protobuf and JSON Schema;
- references, bounded reference graph, deterministic diff and compatibility explanation;
- bounded deterministic mock examples;
- governed registration/compatibility/delete paths.
Multi-profile Kafka Connect
- multiple stable Connect profiles per Kafka cluster;
- legacy
defaultprofile compatibility; - typed read/mutation routes;
- plugin discovery and validation;
- secret-safe configuration handling;
- bounded optional auto-restart with durable attempts/backoff/lifetime/circuit state;
- shared MM2/replication guard.
Controlled data tooling
- CBOR, XML and MessagePack controlled SerDe;
- XML external entity/DTD/resource resolution prohibited;
- governed replay/reprocess/DLQ/cross-topic/cross-cluster forwarding jobs;
- finite budgets, durable checkpoints and no-blind-replay ambiguity semantics;
- deterministic Smart Mock / Data Generator with explicit destination policy and hard volume/rate/time caps.
Streaming ecosystem
- bounded single-statement read-only ksqlDB SELECT tooling;
- no DDL/DML/persistent query creation;
- registered Kafka Streams application/topology/state-store evidence;
- lineage with Observed/Inferred edge kinds, provenance, confidence and stale truth;
- inferred lineage never satisfies authorization.
Developer/operator UX
- keyboard-first Command Palette with Ctrl/Cmd+K;
- registered typed navigation only;
- integrated topic/catalog/schema/Connect/data-job/generator/ksql/Streams/lineage surfaces;
- unified explicit states for Denied, Unsupported, Blocked, Partial, Stale, Unavailable, Unknown, approval and unresolved external effects;
- focus containment/restoration and reduced-motion support.
Browser and air-gap security
- deployment access token is memory-only after URL-fragment bootstrap and immediate URL scrub;
- no secret/payload local/session storage;
- no runtime CDN;
- locally bundled Tabler/frontend assets;
- local OpenAPI contract.
Compatibility posture
Kafka broker validation retains Kafka 4.3.1, 4.2.1 and 4.1.2 as Tier 1 and Kafka 3.9.2 as Tier 2.
Ecosystem compatibility is capability- and evidence-driven. Kafdeck does not claim blanket vendor-version support merely because an endpoint is protocol compatible. See docs/architecture/v0.7-provider-capabilities.md.
Publication integrity
Owner publication authorization was granted under Issue #203 on 2026-09-27. The release is still fail-closed: the protected-main workflow must validate the exact source revision, full Kafka compatibility matrix, SBOM and High/Critical vulnerability gate before it may create the immutable v0.7 tag, GitHub Release, signed/provenanced OCI digest and final GHCR tags.
Immutable OCI image
ghcr.io/araditc/kafdeck@sha256:2e089bfe4788d93e7f9b5d03fac117001daccd06c244f1017648d5ccf57535c8
SBOM and vulnerability-scan evidence are retained by the release workflow for source SHA 23b3777461649f53f602ebf49c1ffd3607b546f7.