Dependency review: franz-go
- Decision: approved for the standalone
github.com/spice-framework/starter-kafkamodule. - Version:
github.com/twmb/franz-gov1.21.0. - Upstream: https://github.com/twmb/franz-go.
- License: BSD-3-Clause; retained in the vendored module license.
- Maintenance: the active v1 line is pure Go and documents Kafka-compatible broker support through Kafka 4.2+, consumer groups, idempotent and transactional producers, administration, and current protocol KIPs.
- Security: verified TLS 1.2 or newer and authentication are independent
defaults. Plaintext and unauthenticated local development each require an
explicit opt-out. Broker addresses are exact bounded
host:portvalues; credentials and payloads never enter starter-produced errors or interaction metadata. PLAIN and SCRAM mechanisms are explicit. - Cancellation: ping, synchronous publish, and shutdown flush use caller-owned contexts. Spice sets finite dial and request-overhead defaults and bounds every configured timeout.
- Observability: franz-go has neutral hooks. Spice exposes payload-free synchronous publication and consumer-delivery observations and leaves broader OpenTelemetry hook installation caller-owned.
- Configuration:
Openperforms no network I/O, fixes all-ISR acknowledgement, retains franz-go’s idempotent producer, disables linger for synchronous behavior, bounds batches, and returns exact lifecycle cleanup. - Integration: unit tests use narrow client seams to prove records, cancellation, observation, flush, idempotent close, bounded group polling, and acknowledge/retry/reject commit behavior. A pinned Redpanda real-broker workflow proves SCRAM authentication, publish/consume ordering, commits, restart behavior, and cleanup. Target production broker/TLS configurations still require their own acceptance.
Primary references:
- https://github.com/twmb/franz-go/releases/tag/v1.21.0
- https://github.com/twmb/franz-go#features
- https://github.com/twmb/franz-go/blob/master/docs/producing-and-consuming.md
- https://github.com/twmb/franz-go/blob/master/LICENSE
Build-only dependencies: Spice release tools
- Decision: approved as the repository-authorized release signer, renderer, and independent verifier.
- Signer version:
github.com/spice-framework/developmentv0.0.0-20260806132124-4c308d1b9fda. - Signer tool:
github.com/spice-framework/development/cmd/spice-devthrough the standard Gotooldirective; invocations always use the full package path. - Verifier version:
github.com/spice-framework/toolchainv0.0.0-20260806133530-71211498297c. - Verifier tool:
github.com/spice-framework/toolchain/cmd/spice-library-release-verify. - License: Apache-2.0, with its notice retained in
vendor. - Runtime scope: none. Product packages do not import the development module, and released applications acquire no runtime dependency on it.
- Dependency graph: the tool participates in normal Go minimal-version
selection. That build-time coupling is accepted and visible in
go.mod,go.sum, andvendor/modules.txt; no parallel tool registry is introduced. - Integrity and network behavior: the exact pseudo-version is pinned and
checksummed. Release rehearsal runs with
GOWORK=off,GOPROXY=off,GOTOOLCHAIN=local, andGOFLAGS=-mod=vendor, so it cannot select an ambient checkout, upgrade itself, or download dependencies. - Security: the trusted native renderer reads the exact committed Git graph and writes only to caller-supplied temporary output directories. The independent verifier authenticates release artifacts against an external trust anchor and exact Git objects. Neither tool generates private material.
- Maintenance: the protected central workflow is the sole production builder.
The caller maps only the repository
SPICE_LIBRARY_RELEASE_SIGNING_KEYsecret; secret inheritance and additional mappings are rejected by repository verification. The protected signing and publishing environments remain approval boundaries. The former repository-local builder was removed after the protected, independently verified central path was established.