Hi Hongshun, Thanks for the good questions. I've added the detailed design of Fluss act-as to FIP-49, including how act-user-id maps to ACLs on the server side. The related issue is tracked in [1].
[1] https://github.com/apache/fluss/issues/3837 Best regards, Junbo Wang > On 7 Aug 2026, at 16:57, Hongshun Wang <[email protected]> wrote: > > Could we clarify this boundary in the FIP, for example: > > - service mode is intended for trusted or single-identity deployments, and > all authenticated Gateway users share the service account's permissions; > - user mode provides per-user Fluss authorization and requires act-as support > from the Fluss cluster. > > This would also make the compatibility statement more precise: service mode > works with existing clusters, while user mode requires the corresponding > server capability.
