@Asaf Mesika We have a manifest importer service that is exposed to our customers. They can make changes to their manifest there and a successful merge/pull request will enable a pipeline to deploy those changes to pulsar.
The question that our security team is asking, is how will we know if manifest changes in Pulsar. If an actor were to change the permissions on a topic say, how would the pulsar admin team know?
I’m wondering if the community has thought through any of these issues.