Skip to content

Enable share groups by default and enhance protocol gates - #51

Merged
hupe1980 merged 2 commits into
mainfrom
feat/share-groups-default-and-evidence-gates
Sep 13, 2026
Merged

hupe1980 merged 2 commits into
mainfrom
feat/share-groups-default-and-evidence-gates

Conversation

@hupe1980

Copy link
Copy Markdown
Owner

Share groups stopped being experimental in Apache Kafka 4.2, and krafka kept hiding them behind unstable-protocol for two more releases. The gate contradicted its own data: every share API is marked stable in the vendored 4.3 snapshot and the version table negotiated all of them unconditionally, so only the API that could reach the protocol was hidden.

BREAKING CHANGE: the KIP-932 share consumer moved to a share-groups feature, on by default. unstable-protocol now means only what Kafka marks latestVersionUnstable — ApiVersions v5 and InitProducerId v6.

Gates added:

  • protocol-parity check 5 fails when a row is gated on unstable-protocol but Kafka ships that version as stable, so this class cannot recur.
  • ci-job-parity asserts every just ci recipe has a CI job, that the new ci-success aggregator needs every job, and that it carries if: always() (GitHub reads a skipped required check as success).
  • bench-check gates the producer send path against a stored baseline. An end-to-end fake-broker benchmark was built and removed once before because it could not rank compression codecs; that is a within-run comparison, where the harness constant swamps the signal. A regression gate is an across-run comparison, where the same constant sits on both sides and cancels.
  • semver-check classifies API changes against the last published release.
  • docs-test and a publish-time verify job now actually run.

Documentation is current state only, not history:

  • The README's 536-line upgrade section is gone; CHANGELOG.md already covered every version of it.
  • The protocol reference no longer flags the four share APIs as unstable, the share-consumer guide no longer recounts Kafka's own release history, and the configuration guide describes behaviour rather than what it used to be.
  • The performance guide and landing page reflect the regression gate while keeping the standard that no absolute figure is published.
  • fuzz/README.md documented three of six targets.

…nest

Share groups stopped being experimental in Apache Kafka 4.2, and krafka kept
hiding them behind `unstable-protocol` for two more releases. The gate
contradicted its own data: every share API is marked stable in the vendored
4.3 snapshot and the version table negotiated all of them unconditionally, so
only the API that could reach the protocol was hidden.

BREAKING CHANGE: the KIP-932 share consumer moved to a `share-groups` feature,
on by default. `unstable-protocol` now means only what Kafka marks
`latestVersionUnstable` — ApiVersions v5 and InitProducerId v6.

Gates added:

- protocol-parity check 5 fails when a row is gated on `unstable-protocol`
  but Kafka ships that version as stable, so this class cannot recur.
- ci-job-parity asserts every `just ci` recipe has a CI job, that the new
  ci-success aggregator needs every job, and that it carries `if: always()`
  (GitHub reads a skipped required check as success).
- bench-check gates the producer send path against a stored baseline. An
  end-to-end fake-broker benchmark was built and removed once before because
  it could not rank compression codecs; that is a within-run comparison, where
  the harness constant swamps the signal. A regression gate is an across-run
  comparison, where the same constant sits on both sides and cancels.
- semver-check classifies API changes against the last published release.
- docs-test and a publish-time verify job now actually run.

Documentation is current state only, not history:

- The README's 536-line upgrade section is gone; CHANGELOG.md already covered
  every version of it.
- The protocol reference no longer flags the four share APIs as unstable, the
  share-consumer guide no longer recounts Kafka's own release history, and the
  configuration guide describes behaviour rather than what it used to be.
- The performance guide and landing page reflect the regression gate while
  keeping the standard that no absolute figure is published.
- fuzz/README.md documented three of six targets.
NOT_COORDINATOR, COORDINATOR_NOT_AVAILABLE and COORDINATOR_LOAD_IN_PROGRESS
all mean "re-run FindCoordinator and try again". A freshly started or
rebalancing cluster answers this way routinely, and the Java client retries
transparently.

krafka dropped the cached coordinator and then returned the error anyway.
`invalidate_coordinator_on_error` returns a bool documented as "retriable
after re-discovery" and both call sites discarded it, so nothing ever made the
next attempt — a routine coordinator election surfaced to the application as
`Failed to subscribe: Broker { code: NotCoordinator }`.

Both join paths now re-discover and retry with jittered backoff, bounded at
five attempts. The KIP-848 path had the same defect in a worse form: it
returned the error without invalidating the cached coordinator at all, so
nothing downstream could recover either.

Found by the Redpanda integration suite, which is where a real coordinator
election actually happens. Each fix carries a fake-broker regression test,
both verified against the defect they cover.
@hupe1980
hupe1980 merged commit 5160141 into main Sep 13, 2026
30 checks passed
@hupe1980
hupe1980 deleted the feat/share-groups-default-and-evidence-gates branch September 13, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant