Skip to content
Spice Framework on GitHub

Dependency review: franz-go

kafkaMaturity: previewSource: starter-kafka@c603a03Exact reviewed source
  • Decision: approved for the standalone github.com/spice-framework/starter-kafka module.
  • Version: github.com/twmb/franz-go v1.21.0.
  • Upstream: https://github.com/twmb/franz-go.
  • License: BSD-3-Clause; retained in the vendored module license.
  • Maintenance: the active v1 line is pure Go and documents Kafka-compatible broker support through Kafka 4.2+, consumer groups, idempotent and transactional producers, administration, and current protocol KIPs.
  • Security: verified TLS 1.2 or newer and authentication are independent defaults. Plaintext and unauthenticated local development each require an explicit opt-out. Broker addresses are exact bounded host:port values; credentials and payloads never enter starter-produced errors or interaction metadata. PLAIN and SCRAM mechanisms are explicit.
  • Cancellation: ping, synchronous publish, and shutdown flush use caller-owned contexts. Spice sets finite dial and request-overhead defaults and bounds every configured timeout.
  • Observability: franz-go has neutral hooks. Spice exposes payload-free synchronous publication and consumer-delivery observations and leaves broader OpenTelemetry hook installation caller-owned.
  • Configuration: Open performs no network I/O, fixes all-ISR acknowledgement, retains franz-go’s idempotent producer, disables linger for synchronous behavior, bounds batches, and returns exact lifecycle cleanup.
  • Integration: unit tests use narrow client seams to prove records, cancellation, observation, flush, idempotent close, bounded group polling, and acknowledge/retry/reject commit behavior. A pinned Redpanda real-broker workflow proves SCRAM authentication, publish/consume ordering, commits, restart behavior, and cleanup. Target production broker/TLS configurations still require their own acceptance.

Primary references:

Build-only dependencies: Spice release tools

  • Decision: approved as the repository-authorized release signer, renderer, and independent verifier.
  • Signer version: github.com/spice-framework/development v0.0.0-20260806132124-4c308d1b9fda.
  • Signer tool: github.com/spice-framework/development/cmd/spice-dev through the standard Go tool directive; invocations always use the full package path.
  • Verifier version: github.com/spice-framework/toolchain v0.0.0-20260806133530-71211498297c.
  • Verifier tool: github.com/spice-framework/toolchain/cmd/spice-library-release-verify.
  • License: Apache-2.0, with its notice retained in vendor.
  • Runtime scope: none. Product packages do not import the development module, and released applications acquire no runtime dependency on it.
  • Dependency graph: the tool participates in normal Go minimal-version selection. That build-time coupling is accepted and visible in go.mod, go.sum, and vendor/modules.txt; no parallel tool registry is introduced.
  • Integrity and network behavior: the exact pseudo-version is pinned and checksummed. Release rehearsal runs with GOWORK=off, GOPROXY=off, GOTOOLCHAIN=local, and GOFLAGS=-mod=vendor, so it cannot select an ambient checkout, upgrade itself, or download dependencies.
  • Security: the trusted native renderer reads the exact committed Git graph and writes only to caller-supplied temporary output directories. The independent verifier authenticates release artifacts against an external trust anchor and exact Git objects. Neither tool generates private material.
  • Maintenance: the protected central workflow is the sole production builder. The caller maps only the repository SPICE_LIBRARY_RELEASE_SIGNING_KEY secret; secret inheritance and additional mappings are rejected by repository verification. The protected signing and publishing environments remain approval boundaries. The former repository-local builder was removed after the protected, independently verified central path was established.