Skip to content

Feat: Protected Principals for ACLs via RBAC#1728

Open
RotemCDos wants to merge 27 commits intokafbat:mainfrom
RotemCDos:issue/288
Open

Feat: Protected Principals for ACLs via RBAC#1728
RotemCDos wants to merge 27 commits intokafbat:mainfrom
RotemCDos:issue/288

Conversation

@RotemCDos
Copy link
Contributor

@RotemCDos RotemCDos commented Mar 17, 2026

  • Breaking change? (if so, please describe the impact and migration path for existing application instances)

Currently, when working in an admin-client environment type, the client is able to edit all or none of the ACLs.
This might cause an issue where the client will remove the Kafbat UI ACLs and softlock themselves until the cluster admin inserts them back via code.

What changes did you make? (Give an overview)
These changes were inspired by #288 with less capabilites, however I still believe this is enough.
Added an option for protectedPrincipals (non wildcard) under a specific role in the RBAC file. Any ACL binding whose principal matches one of these strings will be blocked from modification by that role.

Is there anything you'd like reviewers to focus on?

How Has This Been Tested? (put an "x" (case-sensitive!) next to an item)

  • No need to
  • Manually (please, describe, if necessary)
  • Unit checks
  • Integration checks
  • Covered by existing automation

Checklist (put an "x" (case-sensitive!) next to all the items, otherwise the build will fail)

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation (e.g. ENVIRONMENT VARIABLES)
  • My changes generate no new warnings (e.g. Sonar is happy)
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged

Check out Contributing and Code of Conduct

A picture of a cute animal (not mandatory but encouraged)

@RotemCDos RotemCDos requested a review from a team as a code owner March 17, 2026 12:55
@kapybro kapybro bot added status/triage Issues pending maintainers triage area/rbac Related to Role Based Access Control feature status/triage/manual Manual triage in progress labels Mar 17, 2026
@kapybro kapybro bot added status/triage/completed Automatic triage completed and removed status/triage Issues pending maintainers triage labels Mar 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/rbac Related to Role Based Access Control feature status/triage/completed Automatic triage completed status/triage/manual Manual triage in progress

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant