Ansible Playbooks for Confluent Platform Release Notes

Ansible Playbooks for Confluent Platform (Confluent Ansible) is continuously updated with new features and enhancements. This topic highlights the significant new and updated features, enhancements, bug fixes, and known limitations in each release.

Note

For the list of security and vulnerability issues fixed in any release, see Security Advisories and Security Release Notes.

[21 September, 2026] Confluent Ansible 8.3.2 Release Notes

Ansible Playbooks for Confluent Platform (Confluent Ansible) 8.3.2 allows you to deploy Confluent Platform version 8.3.2.

Breaking changes

confluent_package_version is now required. Confluent Ansible no longer ships a hard-coded default Confluent Platform version. Before you upgrade, add confluent_package_version to your inventory and set it to the Confluent Platform version you want to install. See the Confluent Ansible and Confluent Platform compatibility matrix in Prerequisites for Installing Confluent Platform with Ansible Playbooks. If confluent_package_version is not set, the playbook fails early.

New features

Adds end-to-end support for installing Confluent Platform as a non-root user. See Install Confluent Platform without root access.

Enhancements

Control Center Next Gen (2.7.0 and later) and USM Agent (1.3.0 and later) packages are now fetched from version-numbered repository paths, for example .../rpm/2.7/ instead of .../rpm/. Earlier versions and standard installations are unaffected. For air-gapped or mirrored environments, you can adjust the path using the new confluent_control_center_next_gen_versioned_from_minor_version and confluent_usm_agent_versioned_from_minor_version variables.

Bug fixes

  • Fixed distinguished name (DN) extraction from keystores truncating on certificate fields that contain a colon.

  • Fixed the security.properties copy task failing when using a static or bring-your-own master key with nothing to copy. The fix checks whether the file exists on the controller before attempting to copy it.

  • Scoped the archive-ownership chown task to binary_base_path instead of the shared archive_destination_path.

  • Fixed Control Center Next Gen Basic Authentication by generating the JAAS configuration with the correct Jetty login module.

  • Fixed kafka_controller_quorum_voters to honor hostname_aliasing_enabled and use resolved controller hostnames instead of raw inventory hostnames, ensuring consistent and routable controller endpoints.

Known limitations

This release has no known limitations.

Deprecations

This release has no deprecations.

[13 August, 2026] Confluent Ansible 8.3.1 Release Notes

Ansible Playbooks for Confluent Platform (Confluent Ansible) 8.3.1 allows you to deploy Confluent Platform version 8.3.1.

Breaking changes

There are no breaking changes in this release.

New features

There are no new features in this release.

Enhancements

This release adds protection against Common Vulnerabilities and Exposures (CVEs) found in Confluent Platform. For more information, see the Confluent Platform 8.3.1 release notes.

Bug fixes

There are no bug fixes in this release.

Known limitations

There are no known limitations in this release.

Deprecations

There are no deprecations in this release.

[23 June, 2026] Confluent Ansible 8.3.0 Release Notes

Ansible Playbooks for Confluent Platform (Confluent Ansible) 8.3.0 allows you to deploy Confluent Platform version 8.3.0.

Breaking changes

There are no breaking changes in this release.

New features

Adds the capability to generate a support bundle for Confluent Ansible playbook runs. See Support bundle.

Enhancements

  • Introduces a Confluent CLI v3.0.0 preflight assertion.

  • Adds support for Java 25.

Bug fixes

  • Fixed an issue that caused the Kafka broker and Kafka controller to restart twice.

  • Fixed the issue with the security.properties copy task that failed to copy the file to the Ansible host.

  • Fixed kafka-storage format failures on KRaft clusters with secrets protection enabled. The master key is now passed to the format step using the CONFLUENT_SECURITY_MASTER_KEY environment variable. See Generate and regenerate the master key with Ansible.

  • Fixed custom certificate chain building for multi-tier and partial-chain PKIs. Chains now assemble correctly for root and intermediate bundles, and for DoD-style partial chains.

  • Fixed an issue where OAuth client-assertion components failed to start on Confluent Platform 8.3. The new -Dorg.apache.kafka.sasl.oauthbearer.allowed.files JVM property is now passed to these components.

Known limitations

There are no known limitations in this release.

Deprecations

There are no deprecations in this release.