Confluent for Kubernetes Release Notes

Confluent for Kubernetes is continuously updated with new features and enhancements. This topic highlights significant new and updated features, bug fixes, and known limitations in each release.

Note

For the list of security and vulnerability issues fixed in any release, see Security Advisories and Security Release Notes.

[25 September, 2026] Confluent for Kubernetes 3.3.1 Release Notes

Compatibility and container images

CFK 3.3.1 allows you to deploy and manage Confluent Platform versions from 7.5.x to 8.3.x on Kubernetes versions 1.28 - 1.36 (OpenShift 4.15 - 4.22).

The images released in CFK 3.3.1 are:

  • confluentinc/confluent-operator:0.1718.99

  • confluentinc/confluent-init-container:3.3.1

  • confluentinc/confluent-observer-container:3.3.1

Breaking changes

There are no breaking changes in this release.

New features

Enhancements

  • Removes hard-coded ParallelGCThreads=1 or ConcGCThreads=1 JVM defaults. See Default JVM settings.

  • Adds spec.configId to the Confluent Gateway custom resource (CR) for tracking hot-reload configuration revisions.

  • Adds a pod annotation that triggers a kubelet sync for faster Confluent Gateway hot-reload.

  • Adds InternalClientConfig override support for the operator’s internal Kafka client. See Disable TLS hostname verification for the Kafka internal client.

  • Unifies Flink Day-2 status refresh on skipApply to pull through reconcile.

Bug fixes

  • Fixed Jolokia configuration options not rendering as a single comma-separated line.

  • Fixed the default ZooKeeper chroot to root during KRaft migration for MRC endpoints.

  • Fixed a Cluster Linking issue where non-OAuth secrets were finalized prematurely while the operator was still resolving the authentication type.

  • Fixed Cluster Linking remote-auth secrets not mounting on Kafka brokers.

  • Fixed RBAC drift in the Operator Lifecycle Manager (OLM) bundle.

  • Fixed component startup failures on Confluent Platform 8.3.x for components that authenticate using OAuth client assertions, by allow-listing the client-assertion private-key file.

  • Fixed Kafka-to-ZooKeeper TLS connections crash-looping under Federal Information Processing Standards (FIPS) mode due to a missing BCFKS keystore/truststore configuration.

  • Fixed the Metadata Service (MDS) client keystore rendering for the mtls type without sslClientAuthentication.

  • Fixed spec.tls.fips.enabled: true not being applied to the embedded Kafka REST proxy’s Metadata Service (MDS) client TLS configuration, which was always generated as JKS instead of BCFKS. Manual kafka.rest.client.ssl.* configuration overrides are no longer needed to run FIPS and RBAC deployments together.

  • Fixed a java.security.properties path typo that silently prevented FIPS enforcement from taking effect.

  • Fixed the KafkaTopic controller so it keeps retrying replication factor (RF) fetches after a transient failure, instead of giving up permanently. The bug left status.replicas empty for topics created with spec.replicas unset, and was most noticeable when creating many topics at once through Helm. Broker-side RF was always correct. Only the KafkaTopic status was affected.

  • Fixed reconcile errors and a stale cluster phase being hidden in Kafka status. Status, Kubernetes events, and broker logs now surface the actual failure reason and cluster phase instead of generic or missing messages. This helps diagnose and recover from issues faster.

  • Fixed an unnecessary full cluster roll caused by a stale cached read of tracked secret versions.

  • Fixed observer certificate rotation triggering an unnecessary cluster roll.

  • Fixed CFK triggering unnecessary Kafka or KRaftController rolling restarts on metadata-only writes to a tracked secret. CFK now detects secret changes by content instead of resourceVersion.

  • Fixed the Replicator mTLS connector plugin version.

  • Fixed excessive LDAP load caused by each mirror topic independently triggering an OAuth token request. Tokens are now batched and cached, preventing LDAP overload at scale.

  • Fixed FlinkEnvironment creation being rejected by CMF due to a name collision between metadata.name and the top-level name field.

  • Fixed Common Expression Language (CEL) validation for passthroughConfig on the Confluent Gateway CR.

  • Fixed Confluent Gateway authentication-swapping validation so oauthSettings.jwksEndpointUri is required only when swapping to OAuth authentication, and oauthSettings.audience is no longer always required.

  • Fixed the CMF ownership annotation for FlinkStatement.

  • Fixed a Schema resource that could report status.appState: Created without the schema actually being registered in Schema Registry, following a reconcile interrupted at a specific point. Affected resources now self-heal on the next reconcile.

  • Fixed Kafka CR reconciliation failures caused by TLS secrets (for example, services.kafkaRest mTLS) that contained only JKS or PKCS12 material. Previously, only PEM-style secrets were supported.

  • Fixed an operator memory leak caused by idle outbound HTTP connections that were never closed, which could cause gradual memory growth and potential OOMKilled restarts. Idle connections now close after a configurable timeout set by CONFLUENT_OPERATOR_HTTP_IDLE_CONN_TIMEOUT, which defaults to 90 seconds. See Deploy CFK with custom environment variables.

  • Fixed the default OpenID Connect (OIDC) session token expiry, increasing it from 90 seconds to 15 minutes.

  • Fixed TLS handshake errors flooding Control Center Prometheus and Alertmanager logs, caused by Kubernetes health checks against TLS-enabled endpoints. Set useProcNetPortCheck: true under spec.podTemplate.probe.readiness or spec.podTemplate.probe.liveness on the ControlCenter CR to switch these health checks to a TLS-free method.

  • Fixed an issue that prevented installing or pinning to a specific, non-latest, CFK version through the OpenShift OperatorHub. Each release now retains a direct upgrade link to its predecessor in the Red Hat operator catalog.

Known limitations

There are no new known limitations in this release.

Known issues

  • On a new KRaft controller deployment, CFK doesn’t automatically set inter.broker.listener.name on the KRaftController, regardless of CFK version. If this property is unset, it defaults to null and Self-Balancing fails to start. As a workaround, set inter.broker.listener.name=REPLICATION through configOverrides on the KRaftController CR. In CFK 3.3 and later, you can instead set spec.listeners.replication.enabled: true on the KRaftController CR to have CFK set the property automatically. For details, see Configure KRaft controllers.

Deprecations

There are no new deprecations in this release.

[23 June, 2026] Confluent for Kubernetes 3.3.0 Release Notes

Compatibility and container images

CFK 3.3.0 allows you to deploy and manage Confluent Platform versions from 7.5.x to 8.3.x on Kubernetes versions 1.28 - 1.36 (OpenShift 4.15 - 4.22).

The images released in CFK 3.3.0 are:

  • confluentinc/confluent-operator:0.1718.10

  • confluentinc/confluent-init-container:3.3.0

  • confluentinc/confluent-observer-container:3.3.0

Breaking changes

There are no breaking changes in this release.

Upgrade considerations

Flink custom resources (CRs) now require co-location with their FlinkEnvironment. A FlinkApplication, and the preview Flink SQL CRs, must be created in the same namespace as the FlinkEnvironment it references through spec.flinkEnvironment. CFK stamps an environment-rooted owner reference on these CRs so that deleting the FlinkEnvironment cascades to them, and Kubernetes owner references cannot cross namespaces.

If you deployed the FlinkEnvironment and FlinkApplication in different namespaces on an earlier release, the application reports status.cmfSync: Failed after the upgrade until you remediate it. You can remediate without disrupting running Flink jobs. For the complete step-by-step procedure, including how to restore the application and safely remove the now-redundant FlinkEnvironment, see Migrate cross-namespace Flink resources.

New features

Enhancements

  • Masks sensitive credentials in CFK log output through a centralized redaction wrapper, so plaintext credentials are sanitized before reaching any log sink.

  • Generates the KRaft admin-client properties file for dynamic quorum deployments.

  • Revokes the corresponding Metadata Service (MDS) role binding when you remove an entry from spec.resourcePatterns on the ConfluentRolebinding CR, preventing orphaned bindings from persisting. See Update a rolebinding.

  • Supports a new useProcNetPortCheck liveness and readiness probe method that reports liveness from the /proc/net/tcp file instead of performing an actual handshake. This helps avoid TLS-related errors.

  • Supports adding a sidecar container to a Pod Overlay for in-pod debugging and connectivity checks. This has always been possible, but it becomes more important starting with Confluent Platform 8.3, because images now use the ubi9-micro base image instead of ubi9-minimal and no longer include curl and other command-line tools. See Customize Confluent Platform pods with Pod Overlay.

  • Adds a disaster recovery procedure for recovering a multi-region dynamic KRaft cluster after a controller quorum loss. See Disaster Recovery for Multi-Region KRaft Clusters.

Bug fixes

  • Fixed incorrect advertised.listeners ports when multiple user-defined listeners share the same static or nodePort offset.

  • Fixed dynamic per-listener TLS certificate rotation triggering unnecessary Kafka broker rolling restarts. CFK now correctly classifies derived PKCS12 secrets as dynamic-config secrets.

  • Fixed the zk-node-removal plugin for RBAC and MRC deployments.

  • Fixed MRC KRaft migration requiring a manual zookeeper.connect override on the KRaftController. For 2.5DC topologies, the manual ZooKeeper endpoint on the 0.5DC KRaftController is still required. See Configure the IBP version.

  • Fixed an orphaned connector when a Connector CR is deleted after a failed create or update. CFK now issues the REST DELETE instead of skipping it.

  • Fixed Jolokia file-reference password resolution to trim whitespace so passwords read from mounted secret files no longer fail.

  • Fixed client-side OAUTHBEARER authentication failing through the Gateway.

Known limitations

  • Components that authenticate to Kafka using OAuth client assertions, such as Schema Registry, Connect, ksqlDB, Control Center, and REST Proxy, fail to start on Confluent Platform 8.3.x. Kafka 4.3 enforces an empty, deny-by-default allowlist for the files used in the OAuth client-assertion flow, so the configured private-key file is rejected. As a workaround, set the -Dorg.apache.kafka.sasl.oauthbearer.allowed.files JVM system property on the affected component through its *_OPTS environment variable or podTemplate. If you configure issuer or JSON Web Key Set (JWKS) endpoint URLs, also set -Dorg.apache.kafka.sasl.oauthbearer.allowed.urls.

  • In Multi-Region Cluster (MRC) deployments, the co-ownership check only considers ConfluentRolebinding resources visible to the operator managing that cluster. A co-owning ConfluentRolebinding on another region’s cluster is not visible, so removing a pattern from (or deleting) a ConfluentRolebinding might revoke a binding that a ConfluentRolebinding in another region still declares. Use caution when removing patterns or deleting ConfluentRolebinding resources in MRC if the same (principal, role, scope, resourcePattern) might be declared on another region’s cluster. For details, see Update a rolebinding.

  • A Confluent Gateway passthrough route that configures cluster.extensionHeaders fails admission validation. Injecting extension headers requires setting client.authentication.type to oauth, which triggers a CRD validation rule that mandates oauthSettings.jwksEndpointUri and oauthSettings.audience. Although Confluent Gateway ignores these fields at runtime on passthrough routes and forwards tokens unmodified, the validation rule still rejects the resource. As a workaround, you must provide placeholder values for the required OAuth fields. For details, see OAUTHBEARER passthrough limitation.

  • If you manage the CFK ServiceAccount permissions manually instead of letting Helm create them, CFK 3.3.0 requires additional RBAC permissions that earlier versions did not. Without these permissions, the CFK pod repeatedly crashes with a jobs.batch is forbidden error. For details on the required permissions, see Add RBAC permissions for custom roles before upgrading to 3.3.

  • CFK 3.3.x can trigger unnecessary Kafka or KRaftController rolling restarts when a metadata-only update changes a tracked secret’s resourceVersion. As a workaround, set platform.confluent.io/secret-change-roll-cluster="false" on the affected resources. Note that after applying this workaround, intentional secret rotations then require a manual roll.

  • The operator can leak memory and goroutines over time from idle outbound HTTP connections (to Kafka REST, Metadata Service (MDS), Schema Registry, or an OAuth identity provider) that are never closed. This can affect any deployment. Upgrade to CFK 3.3.1 or later, which adds a configurable idle-connection timeout to fix this. See [25 September, 2026] Confluent for Kubernetes 3.3.1 Release Notes.

Deprecations

There are no new deprecations in this release.