Confluent for Kubernetes Release Notes
Confluent for Kubernetes is continuously updated with new features and enhancements. This topic highlights significant new and updated features, bug fixes, and known limitations in each release.
For Confluent Platform and CFK compatibility information, see Confluent Platform.
For CFK image tags by version, see Confluent for Kubernetes image tags.
To learn how to install CFK and Confluent Platform, see Deploy Confluent for Kubernetes and Deploy Confluent Platform using Confluent for Kubernetes.
Note
For the list of security and vulnerability issues fixed in any release, see Security Advisories and Security Release Notes.
[25 September, 2026] Confluent for Kubernetes 3.2.4 Release Notes
Compatibility and container images
CFK 3.2.4 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).
The images released in CFK 3.2.4 are:
confluentinc/confluent-operator:0.1514.158confluentinc/confluent-init-container:3.2.4confluentinc/confluent-observer-container:3.2.4
Breaking changes
There are no breaking changes in this release.
New features
Adds
kubectl confluent block-reconcileandkubectl confluent enable-reconcileplugin commands. See kubectl confluent block-reconcile and kubectl confluent enable-reconcile.
Enhancements
Removes hard-coded
ParallelGCThreads=1orConcGCThreads=1JVM defaults. See Default JVM settings.Enables FIPS on the Kafka broker and applies FIPS JVM settings through
jvm.config.Adds
InternalClientConfigoverride support for the operator’s internal Kafka client. See Disable TLS hostname verification for the Kafka internal client.Checks Schema Registry status directly instead of trusting a cached configuration hash.
Makes the Kafka-to-LDAP TLS client FIPS-aware using a Bouncy Castle FIPS Keystore (BCFKS).
Removes stale multi-region cluster (MRC) bypass-prechecks guidance, a follow-up to the ZooKeeper
chrootfix below.
Bug fixes
Fixed Jolokia configuration options not rendering as a single comma-separated line.
Fixed the default ZooKeeper
chrootto root during KRaft migration for MRC endpoints.Fixed the
KafkaTopiccontroller so it keeps retrying replication factor (RF) fetches after a transient failure, instead of giving up permanently. The bug leftstatus.replicasempty for topics created withspec.replicasunset, and was most noticeable when creating many topics at once through Helm. Broker-side RF was always correct. Only theKafkaTopicstatus was affected.Fixed the Metadata Service (MDS) client
keystorerendering for themtlstype withoutsslClientAuthentication.Fixed the Schema Registry
restConfigbootstrap URL.Fixed
spec.tls.fips.enabled: truenot being applied to the embedded Kafka REST proxy’s Metadata Service (MDS) client TLS configuration, which was always generated asJKSinstead ofBCFKS. Manualkafka.rest.client.ssl.*configuration overrides are no longer needed to run FIPS and RBAC deployments together.Fixed Kafka-to-ZooKeeper TLS connections crash-looping under FIPS mode due to a missing
BCFKSkeystore or truststore configuration.Fixed a
java.security.propertiespath typo that silently prevented FIPS enforcement from taking effect.Fixed reconcile errors and a stale cluster phase being hidden in
Kafkastatus. Status, Kubernetes events, and broker logs now surface the actual failure reason and cluster phase instead of generic or missing messages. This helps diagnose and recover from issues faster.Fixed an unnecessary full cluster roll caused by a stale cached read of tracked secret versions.
Fixed a per-role Kafka discovery override issue in Connect, ksqlDB, and
KafkaRestProxy.Fixed the Replicator
mTLSconnector plugin version.Fixed an RBAC name collision between External-DNS and Ingress-Nginx.
Fixed FIPS-prefixed Kafka clients missing
security.providers.Fixed excessive LDAP load caused by each mirror topic independently triggering an OAuth token request. Tokens are now batched and cached, preventing LDAP overload at scale.
Fixed Cluster Linking remote-auth secrets not mounting on Kafka brokers.
Fixed observer certificate rotation triggering an unnecessary cluster roll.
Fixed CFK triggering unnecessary Kafka or KRaftController rolling restarts on metadata-only writes to a tracked secret. CFK now detects secret changes by content instead of
resourceVersion.Fixed a
Schemaresource that could reportstatus.appState: Createdwithout the schema actually being registered in Schema Registry, following a reconcile interrupted at a specific point. Affected resources now self-heal on the next reconcile.Fixed Kafka custom resource (CR) reconciliation failures caused by TLS secrets (for example,
services.kafkaRestmTLS) that contained onlyJKSorPKCS12material. Only PEM-style secrets were supported.Fixed an operator memory leak caused by idle outbound HTTP connections that were never closed, which could cause gradual memory growth and potential
OOMKilledrestarts. Idle connections now close after a configurable timeout set byCONFLUENT_OPERATOR_HTTP_IDLE_CONN_TIMEOUT, which defaults to 90 seconds. See Deploy CFK with custom environment variables.Fixed the default OpenID Connect (OIDC) session token expiry, increasing it from 90 seconds to 15 minutes.
Fixed TLS handshake errors flooding Control Center Prometheus and Alertmanager logs, caused by Kubernetes health checks against TLS-enabled endpoints. Set
useProcNetPortCheck: trueunderspec.podTemplate.probe.readinessorspec.podTemplate.probe.livenesson theControlCenterCR to switch these health checks to a TLS-free method.Fixed an issue that prevented installing or pinning to a specific, non-latest, CFK version through the OpenShift OperatorHub. Each release now retains a direct upgrade link to its predecessor in the Red Hat operator catalog.
Known limitations
There are no new known limitations in this release.
Known issues
On a new KRaft controller deployment, CFK doesn’t automatically set
inter.broker.listener.nameon the KRaftController, regardless of CFK version. If this property is unset, it defaults tonulland Self-Balancing can fail to start. As a workaround, setinter.broker.listener.name=REPLICATIONthroughconfigOverrideson the KRaftController CR. In CFK 3.3 and later, you can instead setspec.listeners.replication.enabled: trueon the KRaftController CR to have CFK set the property automatically. For details, see Configure KRaft controllers.
Deprecations
There are no new deprecations in this release.
[23 June, 2026] Confluent for Kubernetes 3.2.3 Release Notes
Compatibility and container images
CFK 3.2.3 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).
The images released in CFK 3.2.3 are:
confluentinc/confluent-operator:0.1514.76confluentinc/confluent-init-container:3.2.3confluentinc/confluent-observer-container:3.2.3
New features
Adds support for the migration pre-check utility for single-cluster KRaft migrations. See Step 3.2: Enable the ZooKeeper metadata preflight check.
Enhancements
Improves Kafka and KRaft readiness probing to avoid probe-generated connection churn and false mTLS authentication failures from polluting operational metrics.
Masks sensitive credentials in CFK log output through a centralized redaction wrapper, so plain-text credentials are sanitized before reaching any log sink.
Bug fixes
Fixed dynamic per-listener TLS certificate rotation triggering unnecessary Kafka broker rolling restarts. CFK now correctly classifies derived
PKCS12secrets asdynamic-configsecrets.Fixed the
zk-node-removalplugin for RBAC and multi-region cluster (MRC) deployments.Fixed a multi-region KRaft migration issue where the KRaft controller required a manual override for the
zookeeper.connectconfiguration.Fixed Schema Registry cluster discovery for external-access and multi-region deployments by handling multi-URL endpoints correctly when
schemaRegistryClusterRefis used.Fixed a connector cleanup issue to ensure that CFK deletes connectors even if their creation previously returned an HTTP 500 error, preventing orphaned connectors from accumulating on the Connect cluster.
Fixed incorrect
advertised.listenersports when multiple user-defined listeners share the same static ornodePortoffset.
Known limitations
The operator can leak memory and
goroutinesover time from idle outbound HTTP connections (to Kafka REST, Metadata Service (MDS), Schema Registry, or an OAuth identity provider) that are never closed. This can affect any deployment. Upgrade to CFK 3.2.4 or later, which adds a configurable idle-connection timeout to fix this. See [25 September, 2026] Confluent for Kubernetes 3.2.4 Release Notes.
Deprecations
There are no new deprecations in this release.
[30 April, 2026] Confluent for Kubernetes 3.2.2 Release Notes
Compatibility and container images
CFK 3.2.2 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).
The images released in CFK 3.2.2 are:
confluentinc/confluent-operator:0.1514.40confluentinc/confluent-init-container:3.2.2confluentinc/confluent-observer-container:3.2.2
New features
Locks Kafka, ZooKeeper, and KRaftController CRs during KRaft migration to prevent accidental modifications or deletions. See CR lock enforcement.
Supports KRaft migration rollback from the
SETUPandMIGRATEphases (previouslyDUAL-WRITEonly). See Roll Back to ZooKeeper.Adds
kubectl confluent cluster kraft-migrationplugin for managing KRaft migration lifecycle operations: status, finalize, rollback, and CR lock release. See KRaft Migration Plugin Commands.Adds mTLS authentication support between ksqlDB and MDS.
Enhancements
Validates
configOverrides.serverfor blocklisted keys (for example,zookeeper.connect) before starting KRaft migration; blocks migration with an actionable error on conflicts. See Step 3: Start migration.
Bug fixes
Fixed duplicate OpenShift Route hostname between
TOKEN_SASLandREPLICATIONlisteners when MDS mTLS is enabled.Fixed propagation of
podTemplate.affinityto Confluent Gateway deployments so CR-defined affinity rules apply correctly to pods.
Known limitations
There are no new known limitations in this release.
Deprecations
There are no new deprecations in this release.
[27 March, 2026] Confluent for Kubernetes 3.2.1 Release Notes
Compatibility and container images
CFK 3.2.1 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).
The images released in CFK 3.2.1 are:
confluentinc/confluent-operator:0.1514.19confluentinc/confluent-init-container:3.2.1confluentinc/confluent-observer-container:3.2.1
New features
Adds JMX authentication and access control configuration using CR specifications to secure exposed JMX ports for all Confluent Platform components. This is a breaking change for existing deployments that access the JMX port remotely for metrics queries. See JMX Metrics.
Supports dynamic quorum configuration for KRaft deployments, including multi-region cluster (MRC) deployments. MRC requires Confluent Platform 7.9.6 or later (7.9.x) and 8.1.2 or later (8.1.x). Migrating existing MRC deployments from static to dynamic quorum requires Confluent Platform 8.0 or later. See Configure Dynamic KRaft Quorum for Confluent Platform Using Confluent for Kubernetes.
Enhancements
There are no new enhancements in this release.
Bug fixes
Fixed custom OAuth listener validation failure when JAAS configurations were omitted.
Fixed metrics TLS configuration to correctly resolve keystore passwords from vault-injected files when
DirectoryPathInContaineris used.
Known limitations
There are no new known limitations in this release.
Deprecations
There are no new deprecations in this release.
[11 March, 2026] Confluent for Kubernetes 3.2.0 Release Notes
Compatibility and container images
CFK 3.2.0 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).
The images released in CFK 3.2.0 are:
confluentinc/confluent-operator:0.1514.1confluentinc/confluent-init-container:3.2.0confluentinc/confluent-observer-container:3.2.0
Breaking changes
There are no breaking changes in this release.
New features
Adds an Observer container for self-contained readiness monitoring of Kafka and KRaft controller pods. See Configure Observer container for Confluent Platform.
Supports dynamic quorum configuration for KRaft deployments, including MRC deployments. MRC requires Confluent Platform 7.9.6 or later (7.9.x) and 8.1.2 or later (8.1.x). See Configure Dynamic KRaft Quorum for Confluent Platform Using Confluent for Kubernetes.
Supports bidirectional cluster linking for data replication in both directions between two Kafka clusters. See Bidirectional cluster linking.
Supports deploying FIPS 140-3 compliant Confluent Platform components. See Security Compliance in Confluent for Kubernetes.
Supports increasing the partition count for existing Kafka topics by editing
spec.partitionCounton the KafkaTopic CR (decreasing is not supported). Before upgrading brownfield deployments, verifyspec.partitionCountmatches the live cluster to avoid an unintended partition increase on first reconcile. See Update Kafka topic.Supports adding or rotating external SASL/PLAIN client credentials without broker restarts. CFK hot-reloads credential changes when
jaasConfiguses the defaultFileBasedLoginModule. Enabled by default. See Update Kafka or KRaft SASL/PLAIN external client users.Adds
spec.listeners.advertisedListenersEnabledto the KRaftController CR; set totruefor MRC deployments to prevent controller endpoint registration issues. See Configure KRaft in MRC.
Enhancements
Derives the inter-broker protocol (IBP) version automatically for standard Confluent Platform images during ZooKeeper to KRaft migration. Custom images still require the
platform.confluent.io/kraft-migration-ibp-versionannotation. See Step 1: Configure IBP version.Triggers operator-controlled rolling restarts on secret updates with under-replicated partition (URP) safety checks for Kafka and KRaft components, preventing cluster instability during certificate rotation. See Secret updates and safe rolling restarts.
Validates required init-container environment variables and supports appending custom environment variables to init containers using the common
podTemplatespec.Optimizes the Unified Stream Manager Schema Registry automation workflow for improved performance.
Bug fixes
Fixed an issue where CFK ignored the
platform.confluent.io/roll-delay-interval-secondsannotation during upgrades, causing pods to roll immediately instead of waiting for the configured delay.Fixed connector reconciliation to properly handle Connect’s credential masking in the REST API, preventing unnecessary connector updates or restarts when sensitive configuration fields are masked.
Fixed an issue where CFK did not add the Unified Stream Manager (USM) extension class when RBAC authorization was enabled.
Fixed an issue where CFK issued
DELETE_TOPICSrequests for auto-mirrored topics during reconciliation. This causes brokers to repeatedly logTopicDeletionDisabledExceptionerrors and the destination cluster link to enter aClusterLinkUpdateFailedcondition. However, the data flow and mirroring were not affected. This is tracked in CFK-3888. For details on the symptoms in earlier versions, see Troubleshoot Confluent for Kubernetes.
Known limitations
CFK 3.2.x can trigger unnecessary Kafka or KRaftController rolling restarts when a metadata-only update changes a tracked secret’s
resourceVersion. As a workaround, setplatform.confluent.io/secret-change-roll-cluster="false"on the affected resources. Note that after applying this workaround, intentional secret rotations then require a manual roll.
Deprecations
There are no new deprecations in this release.