Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
PR v1.5 roadmap: Auth, ACL coverage, and proxy protocol hardening
Summary
This PR implements the v1.5 auth groundwork: broker-side ACL enforcement improvements, connection-level principal plumbing with PROXY protocol support, expanded ACL test coverage, and documentation updates. It also adds rate-limited auth denial logs and tightens proxy protocol parsing behavior.
Key Changes
client_id(default),remote_addr,proxy_addr; with fail‑closed behavior when PROXY protocol is enabled.notes/directory in.gitignore.Details
KAFSCALE_PROXY_PROTOCOL=trueand header missing/invalid.TestACLsE2E).Tests
make testmake test-aclNotes for Reviewers
client_idremain spoofable unless trusted edge auth is enforced; warnings are logged on startup.