Confluent for Kubernetes Release Notes

Confluent for Kubernetes is continuously updated with new features and enhancements. This topic highlights significant new and updated features, bug fixes, and known limitations in each release.

Note

For the list of security and vulnerability issues fixed in any release, see Security Advisories and Security Release Notes.

[25 September, 2026] Confluent for Kubernetes 3.2.4 Release Notes

Compatibility and container images

CFK 3.2.4 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).

The images released in CFK 3.2.4 are:

  • confluentinc/confluent-operator:0.1514.158

  • confluentinc/confluent-init-container:3.2.4

  • confluentinc/confluent-observer-container:3.2.4

Breaking changes

There are no breaking changes in this release.

New features

Enhancements

  • Removes hard-coded ParallelGCThreads=1 or ConcGCThreads=1 JVM defaults. See Default JVM settings.

  • Enables FIPS on the Kafka broker and applies FIPS JVM settings through jvm.config.

  • Adds InternalClientConfig override support for the operator’s internal Kafka client. See Disable TLS hostname verification for the Kafka internal client.

  • Checks Schema Registry status directly instead of trusting a cached configuration hash.

  • Makes the Kafka-to-LDAP TLS client FIPS-aware using a Bouncy Castle FIPS Keystore (BCFKS).

  • Removes stale multi-region cluster (MRC) bypass-prechecks guidance, a follow-up to the ZooKeeper chroot fix below.

Bug fixes

  • Fixed Jolokia configuration options not rendering as a single comma-separated line.

  • Fixed the default ZooKeeper chroot to root during KRaft migration for MRC endpoints.

  • Fixed the KafkaTopic controller so it keeps retrying replication factor (RF) fetches after a transient failure, instead of giving up permanently. The bug left status.replicas empty for topics created with spec.replicas unset, and was most noticeable when creating many topics at once through Helm. Broker-side RF was always correct. Only the KafkaTopic status was affected.

  • Fixed the Metadata Service (MDS) client keystore rendering for the mtls type without sslClientAuthentication.

  • Fixed the Schema Registry restConfig bootstrap URL.

  • Fixed spec.tls.fips.enabled: true not being applied to the embedded Kafka REST proxy’s Metadata Service (MDS) client TLS configuration, which was always generated as JKS instead of BCFKS. Manual kafka.rest.client.ssl.* configuration overrides are no longer needed to run FIPS and RBAC deployments together.

  • Fixed Kafka-to-ZooKeeper TLS connections crash-looping under FIPS mode due to a missing BCFKS keystore or truststore configuration.

  • Fixed a java.security.properties path typo that silently prevented FIPS enforcement from taking effect.

  • Fixed reconcile errors and a stale cluster phase being hidden in Kafka status. Status, Kubernetes events, and broker logs now surface the actual failure reason and cluster phase instead of generic or missing messages. This helps diagnose and recover from issues faster.

  • Fixed an unnecessary full cluster roll caused by a stale cached read of tracked secret versions.

  • Fixed a per-role Kafka discovery override issue in Connect, ksqlDB, and KafkaRestProxy.

  • Fixed the Replicator mTLS connector plugin version.

  • Fixed an RBAC name collision between External-DNS and Ingress-Nginx.

  • Fixed FIPS-prefixed Kafka clients missing security.providers.

  • Fixed excessive LDAP load caused by each mirror topic independently triggering an OAuth token request. Tokens are now batched and cached, preventing LDAP overload at scale.

  • Fixed Cluster Linking remote-auth secrets not mounting on Kafka brokers.

  • Fixed observer certificate rotation triggering an unnecessary cluster roll.

  • Fixed CFK triggering unnecessary Kafka or KRaftController rolling restarts on metadata-only writes to a tracked secret. CFK now detects secret changes by content instead of resourceVersion.

  • Fixed a Schema resource that could report status.appState: Created without the schema actually being registered in Schema Registry, following a reconcile interrupted at a specific point. Affected resources now self-heal on the next reconcile.

  • Fixed Kafka custom resource (CR) reconciliation failures caused by TLS secrets (for example, services.kafkaRest mTLS) that contained only JKS or PKCS12 material. Only PEM-style secrets were supported.

  • Fixed an operator memory leak caused by idle outbound HTTP connections that were never closed, which could cause gradual memory growth and potential OOMKilled restarts. Idle connections now close after a configurable timeout set by CONFLUENT_OPERATOR_HTTP_IDLE_CONN_TIMEOUT, which defaults to 90 seconds. See Deploy CFK with custom environment variables.

  • Fixed the default OpenID Connect (OIDC) session token expiry, increasing it from 90 seconds to 15 minutes.

  • Fixed TLS handshake errors flooding Control Center Prometheus and Alertmanager logs, caused by Kubernetes health checks against TLS-enabled endpoints. Set useProcNetPortCheck: true under spec.podTemplate.probe.readiness or spec.podTemplate.probe.liveness on the ControlCenter CR to switch these health checks to a TLS-free method.

  • Fixed an issue that prevented installing or pinning to a specific, non-latest, CFK version through the OpenShift OperatorHub. Each release now retains a direct upgrade link to its predecessor in the Red Hat operator catalog.

Known limitations

There are no new known limitations in this release.

Known issues

  • On a new KRaft controller deployment, CFK doesn’t automatically set inter.broker.listener.name on the KRaftController, regardless of CFK version. If this property is unset, it defaults to null and Self-Balancing can fail to start. As a workaround, set inter.broker.listener.name=REPLICATION through configOverrides on the KRaftController CR. In CFK 3.3 and later, you can instead set spec.listeners.replication.enabled: true on the KRaftController CR to have CFK set the property automatically. For details, see Configure KRaft controllers.

Deprecations

There are no new deprecations in this release.

[23 June, 2026] Confluent for Kubernetes 3.2.3 Release Notes

Compatibility and container images

CFK 3.2.3 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).

The images released in CFK 3.2.3 are:

  • confluentinc/confluent-operator:0.1514.76

  • confluentinc/confluent-init-container:3.2.3

  • confluentinc/confluent-observer-container:3.2.3

New features

Enhancements

  • Improves Kafka and KRaft readiness probing to avoid probe-generated connection churn and false mTLS authentication failures from polluting operational metrics.

  • Masks sensitive credentials in CFK log output through a centralized redaction wrapper, so plain-text credentials are sanitized before reaching any log sink.

Bug fixes

  • Fixed dynamic per-listener TLS certificate rotation triggering unnecessary Kafka broker rolling restarts. CFK now correctly classifies derived PKCS12 secrets as dynamic-config secrets.

  • Fixed the zk-node-removal plugin for RBAC and multi-region cluster (MRC) deployments.

  • Fixed a multi-region KRaft migration issue where the KRaft controller required a manual override for the zookeeper.connect configuration.

  • Fixed Schema Registry cluster discovery for external-access and multi-region deployments by handling multi-URL endpoints correctly when schemaRegistryClusterRef is used.

  • Fixed a connector cleanup issue to ensure that CFK deletes connectors even if their creation previously returned an HTTP 500 error, preventing orphaned connectors from accumulating on the Connect cluster.

  • Fixed incorrect advertised.listeners ports when multiple user-defined listeners share the same static or nodePort offset.

Known limitations

  • The operator can leak memory and goroutines over time from idle outbound HTTP connections (to Kafka REST, Metadata Service (MDS), Schema Registry, or an OAuth identity provider) that are never closed. This can affect any deployment. Upgrade to CFK 3.2.4 or later, which adds a configurable idle-connection timeout to fix this. See [25 September, 2026] Confluent for Kubernetes 3.2.4 Release Notes.

Deprecations

There are no new deprecations in this release.

[30 April, 2026] Confluent for Kubernetes 3.2.2 Release Notes

Compatibility and container images

CFK 3.2.2 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).

The images released in CFK 3.2.2 are:

  • confluentinc/confluent-operator:0.1514.40

  • confluentinc/confluent-init-container:3.2.2

  • confluentinc/confluent-observer-container:3.2.2

New features

  • Locks Kafka, ZooKeeper, and KRaftController CRs during KRaft migration to prevent accidental modifications or deletions. See CR lock enforcement.

  • Supports KRaft migration rollback from the SETUP and MIGRATE phases (previously DUAL-WRITE only). See Roll Back to ZooKeeper.

  • Adds kubectl confluent cluster kraft-migration plugin for managing KRaft migration lifecycle operations: status, finalize, rollback, and CR lock release. See KRaft Migration Plugin Commands.

  • Adds mTLS authentication support between ksqlDB and MDS.

Enhancements

  • Validates configOverrides.server for blocklisted keys (for example, zookeeper.connect) before starting KRaft migration; blocks migration with an actionable error on conflicts. See Step 3: Start migration.

Bug fixes

  • Fixed duplicate OpenShift Route hostname between TOKEN_SASL and REPLICATION listeners when MDS mTLS is enabled.

  • Fixed propagation of podTemplate.affinity to Confluent Gateway deployments so CR-defined affinity rules apply correctly to pods.

Known limitations

There are no new known limitations in this release.

Deprecations

There are no new deprecations in this release.

[27 March, 2026] Confluent for Kubernetes 3.2.1 Release Notes

Compatibility and container images

CFK 3.2.1 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).

The images released in CFK 3.2.1 are:

  • confluentinc/confluent-operator:0.1514.19

  • confluentinc/confluent-init-container:3.2.1

  • confluentinc/confluent-observer-container:3.2.1

New features

  • Adds JMX authentication and access control configuration using CR specifications to secure exposed JMX ports for all Confluent Platform components. This is a breaking change for existing deployments that access the JMX port remotely for metrics queries. See JMX Metrics.

  • Supports dynamic quorum configuration for KRaft deployments, including multi-region cluster (MRC) deployments. MRC requires Confluent Platform 7.9.6 or later (7.9.x) and 8.1.2 or later (8.1.x). Migrating existing MRC deployments from static to dynamic quorum requires Confluent Platform 8.0 or later. See Configure Dynamic KRaft Quorum for Confluent Platform Using Confluent for Kubernetes.

Enhancements

There are no new enhancements in this release.

Bug fixes

  • Fixed custom OAuth listener validation failure when JAAS configurations were omitted.

  • Fixed metrics TLS configuration to correctly resolve keystore passwords from vault-injected files when DirectoryPathInContainer is used.

Known limitations

There are no new known limitations in this release.

Deprecations

There are no new deprecations in this release.

[11 March, 2026] Confluent for Kubernetes 3.2.0 Release Notes

Compatibility and container images

CFK 3.2.0 allows you to deploy and manage Confluent Platform versions from 7.4.x to 8.2.x on Kubernetes versions 1.27 - 1.35 (OpenShift 4.14 - 4.21).

The images released in CFK 3.2.0 are:

  • confluentinc/confluent-operator:0.1514.1

  • confluentinc/confluent-init-container:3.2.0

  • confluentinc/confluent-observer-container:3.2.0

Breaking changes

There are no breaking changes in this release.

New features

Enhancements

  • Derives the inter-broker protocol (IBP) version automatically for standard Confluent Platform images during ZooKeeper to KRaft migration. Custom images still require the platform.confluent.io/kraft-migration-ibp-version annotation. See Step 1: Configure IBP version.

  • Triggers operator-controlled rolling restarts on secret updates with under-replicated partition (URP) safety checks for Kafka and KRaft components, preventing cluster instability during certificate rotation. See Secret updates and safe rolling restarts.

  • Validates required init-container environment variables and supports appending custom environment variables to init containers using the common podTemplate spec.

  • Optimizes the Unified Stream Manager Schema Registry automation workflow for improved performance.

Bug fixes

  • Fixed an issue where CFK ignored the platform.confluent.io/roll-delay-interval-seconds annotation during upgrades, causing pods to roll immediately instead of waiting for the configured delay.

  • Fixed connector reconciliation to properly handle Connect’s credential masking in the REST API, preventing unnecessary connector updates or restarts when sensitive configuration fields are masked.

  • Fixed an issue where CFK did not add the Unified Stream Manager (USM) extension class when RBAC authorization was enabled.

  • Fixed an issue where CFK issued DELETE_TOPICS requests for auto-mirrored topics during reconciliation. This causes brokers to repeatedly log TopicDeletionDisabledException errors and the destination cluster link to enter a ClusterLinkUpdateFailed condition. However, the data flow and mirroring were not affected. This is tracked in CFK-3888. For details on the symptoms in earlier versions, see Troubleshoot Confluent for Kubernetes.

Known limitations

  • CFK 3.2.x can trigger unnecessary Kafka or KRaftController rolling restarts when a metadata-only update changes a tracked secret’s resourceVersion. As a workaround, set platform.confluent.io/secret-change-roll-cluster="false" on the affected resources. Note that after applying this workaround, intentional secret rotations then require a manual roll.

Deprecations

There are no new deprecations in this release.