Confluent for Kubernetes Release Notes
Confluent for Kubernetes is continuously updated with new features and enhancements. This topic highlights significant new and updated features, bug fixes, and known limitations in each release.
For Confluent Platform and CFK compatibility information, see Confluent Platform.
For CFK image tags by version, see Confluent for Kubernetes image tags.
To learn how to install CFK and Confluent Platform, see Deploy Confluent for Kubernetes and Deploy Confluent Platform using Confluent for Kubernetes.
Note
For the list of security and vulnerability issues fixed in any release, see Security Advisories and Security Release Notes.
[25 September, 2026] Confluent for Kubernetes 3.3.1 Release Notes
Compatibility and container images
CFK 3.3.1 allows you to deploy and manage Confluent Platform versions from 7.5.x to 8.3.x on Kubernetes versions 1.28 - 1.36 (OpenShift 4.15 - 4.22).
The images released in CFK 3.3.1 are:
confluentinc/confluent-operator:0.1718.99confluentinc/confluent-init-container:3.3.1confluentinc/confluent-observer-container:3.3.1
Breaking changes
There are no breaking changes in this release.
New features
Adds
kubectl confluent block-reconcileandkubectl confluent enable-reconcileplugin commands. See kubectl confluent block-reconcile and kubectl confluent enable-reconcile.
Enhancements
Removes hard-coded
ParallelGCThreads=1orConcGCThreads=1JVM defaults. See Default JVM settings.Adds
spec.configIdto the Confluent Gateway custom resource (CR) for tracking hot-reload configuration revisions.Adds a pod annotation that triggers a
kubeletsync for faster Confluent Gateway hot-reload.Adds
InternalClientConfigoverride support for the operator’s internal Kafka client. See Disable TLS hostname verification for the Kafka internal client.Unifies Flink Day-2 status refresh on
skipApplyto pull through reconcile.
Bug fixes
Fixed Jolokia configuration options not rendering as a single comma-separated line.
Fixed the default ZooKeeper
chrootto root during KRaft migration for MRC endpoints.Fixed a Cluster Linking issue where non-OAuth secrets were finalized prematurely while the operator was still resolving the authentication type.
Fixed Cluster Linking remote-auth secrets not mounting on Kafka brokers.
Fixed RBAC drift in the Operator Lifecycle Manager (OLM) bundle.
Fixed component startup failures on Confluent Platform 8.3.x for components that authenticate using OAuth client assertions, by allow-listing the client-assertion private-key file.
Fixed Kafka-to-ZooKeeper TLS connections crash-looping under Federal Information Processing Standards (FIPS) mode due to a missing
BCFKSkeystore/truststore configuration.Fixed the Metadata Service (MDS) client
keystorerendering for themtlstype withoutsslClientAuthentication.Fixed
spec.tls.fips.enabled: truenot being applied to the embedded Kafka REST proxy’s Metadata Service (MDS) client TLS configuration, which was always generated asJKSinstead ofBCFKS. Manualkafka.rest.client.ssl.*configuration overrides are no longer needed to run FIPS and RBAC deployments together.Fixed a
java.security.propertiespath typo that silently prevented FIPS enforcement from taking effect.Fixed the
KafkaTopiccontroller so it keeps retrying replication factor (RF) fetches after a transient failure, instead of giving up permanently. The bug leftstatus.replicasempty for topics created withspec.replicasunset, and was most noticeable when creating many topics at once through Helm. Broker-side RF was always correct. Only theKafkaTopicstatus was affected.Fixed reconcile errors and a stale cluster phase being hidden in
Kafkastatus. Status, Kubernetes events, and broker logs now surface the actual failure reason and cluster phase instead of generic or missing messages. This helps diagnose and recover from issues faster.Fixed an unnecessary full cluster roll caused by a stale cached read of tracked secret versions.
Fixed observer certificate rotation triggering an unnecessary cluster roll.
Fixed CFK triggering unnecessary Kafka or KRaftController rolling restarts on metadata-only writes to a tracked secret. CFK now detects secret changes by content instead of
resourceVersion.Fixed the Replicator
mTLSconnector plugin version.Fixed excessive LDAP load caused by each mirror topic independently triggering an OAuth token request. Tokens are now batched and cached, preventing LDAP overload at scale.
Fixed
FlinkEnvironmentcreation being rejected by CMF due to a name collision betweenmetadata.nameand the top-levelnamefield.Fixed Common Expression Language (CEL) validation for
passthroughConfigon the Confluent Gateway CR.Fixed Confluent Gateway authentication-swapping validation so
oauthSettings.jwksEndpointUriis required only when swapping to OAuth authentication, andoauthSettings.audienceis no longer always required.Fixed the CMF ownership annotation for
FlinkStatement.Fixed a Schema resource that could report
status.appState: Createdwithout the schema actually being registered in Schema Registry, following a reconcile interrupted at a specific point. Affected resources now self-heal on the next reconcile.Fixed Kafka CR reconciliation failures caused by TLS secrets (for example,
services.kafkaRestmTLS) that contained onlyJKSorPKCS12material. Previously, only PEM-style secrets were supported.Fixed an operator memory leak caused by idle outbound HTTP connections that were never closed, which could cause gradual memory growth and potential
OOMKilledrestarts. Idle connections now close after a configurable timeout set byCONFLUENT_OPERATOR_HTTP_IDLE_CONN_TIMEOUT, which defaults to 90 seconds. See Deploy CFK with custom environment variables.Fixed the default OpenID Connect (OIDC) session token expiry, increasing it from 90 seconds to 15 minutes.
Fixed TLS handshake errors flooding Control Center Prometheus and Alertmanager logs, caused by Kubernetes health checks against TLS-enabled endpoints. Set
useProcNetPortCheck: trueunderspec.podTemplate.probe.readinessorspec.podTemplate.probe.livenesson theControlCenterCR to switch these health checks to a TLS-free method.Fixed an issue that prevented installing or pinning to a specific, non-latest, CFK version through the OpenShift OperatorHub. Each release now retains a direct upgrade link to its predecessor in the Red Hat operator catalog.
Known limitations
There are no new known limitations in this release.
Known issues
On a new KRaft controller deployment, CFK doesn’t automatically set
inter.broker.listener.nameon the KRaftController, regardless of CFK version. If this property is unset, it defaults tonulland Self-Balancing fails to start. As a workaround, setinter.broker.listener.name=REPLICATIONthroughconfigOverrideson the KRaftController CR. In CFK 3.3 and later, you can instead setspec.listeners.replication.enabled: trueon the KRaftController CR to have CFK set the property automatically. For details, see Configure KRaft controllers.
Deprecations
There are no new deprecations in this release.
[23 June, 2026] Confluent for Kubernetes 3.3.0 Release Notes
Compatibility and container images
CFK 3.3.0 allows you to deploy and manage Confluent Platform versions from 7.5.x to 8.3.x on Kubernetes versions 1.28 - 1.36 (OpenShift 4.15 - 4.22).
The images released in CFK 3.3.0 are:
confluentinc/confluent-operator:0.1718.10confluentinc/confluent-init-container:3.3.0confluentinc/confluent-observer-container:3.3.0
Breaking changes
There are no breaking changes in this release.
Upgrade considerations
Flink custom resources (CRs) now require co-location with their
FlinkEnvironment. A FlinkApplication, and the preview Flink SQL CRs, must be
created in the same namespace as the FlinkEnvironment it references through
spec.flinkEnvironment. CFK stamps an environment-rooted owner reference on
these CRs so that deleting the FlinkEnvironment cascades to them, and
Kubernetes owner references cannot cross namespaces.
If you deployed the FlinkEnvironment and FlinkApplication in different
namespaces on an earlier release, the application reports
status.cmfSync: Failed after the upgrade until you remediate it. You can
remediate without disrupting running Flink jobs. For the complete step-by-step
procedure, including how to restore the application and safely remove the
now-redundant FlinkEnvironment, see Migrate cross-namespace Flink resources.
New features
Adds preview support for managing Confluent Platform Flink SQL objects through CFK with six new custom resources. See Manage Flink SQL Statements Using Confluent for Kubernetes.
Expands the FlinkEnvironment and FlinkApplication schemas with new configuration and status fields. See Create a Flink environment.
Adds support for the migration pre-check utility for single-cluster KRaft migrations. See Step 3.2: Enable the ZooKeeper metadata preflight check.
Supports ZooKeeper to KRaft migration for 2.5 datacenter (2.5DC) deployments. See Two-and-a-half datacenter (2.5DC) considerations.
Supports scaling up KRaftController replicas on dynamic quorum clusters without rolling existing controllers or co-located Kafka brokers. See Scale up the controller quorum.
Adds opt-in hot-reload for eligible Gateway configuration changes.
Adds
mountedSecretsandmountedVolumesto the Gateway CR for mounting custom secrets and volumes.Supports running the Gateway with
readOnlyRootFilesystem: trueby provisioning writableemptyDirvolumes for the log and temporary file paths.Supports OAuth-to-OAuth authentication swap through the Gateway. See Configure authentication swapping.
Runs the liveness probe as an
execprobe backed by thecfkproberbinary. See Liveness probe change to exec in CFK 3.3.0.Pauses a maintenance-mode pod inside its main container instead of the init container, giving direct access to the component’s command-line tools. See Configure maintenance mode.
Enhancements
Masks sensitive credentials in CFK log output through a centralized redaction wrapper, so plaintext credentials are sanitized before reaching any log sink.
Generates the KRaft admin-client properties file for dynamic quorum deployments.
Revokes the corresponding Metadata Service (MDS) role binding when you remove an entry from
spec.resourcePatternson the ConfluentRolebinding CR, preventing orphaned bindings from persisting. See Update a rolebinding.Supports a new
useProcNetPortCheckliveness and readiness probe method that reports liveness from the/proc/net/tcpfile instead of performing an actual handshake. This helps avoid TLS-related errors.Supports adding a sidecar container to a Pod Overlay for in-pod debugging and connectivity checks. This has always been possible, but it becomes more important starting with Confluent Platform 8.3, because images now use the
ubi9-microbase image instead ofubi9-minimaland no longer includecurland other command-line tools. See Customize Confluent Platform pods with Pod Overlay.Adds a disaster recovery procedure for recovering a multi-region dynamic KRaft cluster after a controller quorum loss. See Disaster Recovery for Multi-Region KRaft Clusters.
Bug fixes
Fixed incorrect
advertised.listenersports when multiple user-defined listeners share the same static or nodePort offset.Fixed dynamic per-listener TLS certificate rotation triggering unnecessary Kafka broker rolling restarts. CFK now correctly classifies derived
PKCS12secrets as dynamic-config secrets.Fixed the
zk-node-removalplugin for RBAC and MRC deployments.Fixed MRC KRaft migration requiring a manual
zookeeper.connectoverride on the KRaftController. For 2.5DC topologies, the manual ZooKeeper endpoint on the 0.5DCKRaftControlleris still required. See Configure the IBP version.Fixed an orphaned connector when a Connector CR is deleted after a failed create or update. CFK now issues the
REST DELETEinstead of skipping it.Fixed Jolokia file-reference password resolution to trim whitespace so passwords read from mounted secret files no longer fail.
Fixed client-side
OAUTHBEARERauthentication failing through the Gateway.
Known limitations
Components that authenticate to Kafka using OAuth client assertions, such as Schema Registry, Connect, ksqlDB, Control Center, and REST Proxy, fail to start on Confluent Platform 8.3.x. Kafka 4.3 enforces an empty, deny-by-default allowlist for the files used in the OAuth client-assertion flow, so the configured private-key file is rejected. As a workaround, set the
-Dorg.apache.kafka.sasl.oauthbearer.allowed.filesJVM system property on the affected component through its*_OPTSenvironment variable orpodTemplate. If you configure issuer or JSON Web Key Set (JWKS) endpoint URLs, also set-Dorg.apache.kafka.sasl.oauthbearer.allowed.urls.
In Multi-Region Cluster (MRC) deployments, the co-ownership check only considers
ConfluentRolebindingresources visible to the operator managing that cluster. A co-owningConfluentRolebindingon another region’s cluster is not visible, so removing a pattern from (or deleting) aConfluentRolebindingmight revoke a binding that aConfluentRolebindingin another region still declares. Use caution when removing patterns or deletingConfluentRolebindingresources in MRC if the same(principal, role, scope, resourcePattern)might be declared on another region’s cluster. For details, see Update a rolebinding.A Confluent Gateway passthrough route that configures
cluster.extensionHeadersfails admission validation. Injecting extension headers requires settingclient.authentication.typetooauth, which triggers a CRD validation rule that mandatesoauthSettings.jwksEndpointUriandoauthSettings.audience. Although Confluent Gateway ignores these fields at runtime on passthrough routes and forwards tokens unmodified, the validation rule still rejects the resource. As a workaround, you must provide placeholder values for the required OAuth fields. For details, see OAUTHBEARER passthrough limitation.If you manage the CFK
ServiceAccountpermissions manually instead of letting Helm create them, CFK 3.3.0 requires additional RBAC permissions that earlier versions did not. Without these permissions, the CFK pod repeatedly crashes with ajobs.batch is forbiddenerror. For details on the required permissions, see Add RBAC permissions for custom roles before upgrading to 3.3.CFK 3.3.x can trigger unnecessary Kafka or KRaftController rolling restarts when a metadata-only update changes a tracked secret’s
resourceVersion. As a workaround, setplatform.confluent.io/secret-change-roll-cluster="false"on the affected resources. Note that after applying this workaround, intentional secret rotations then require a manual roll.The operator can leak memory and
goroutinesover time from idle outbound HTTP connections (to Kafka REST, Metadata Service (MDS), Schema Registry, or an OAuth identity provider) that are never closed. This can affect any deployment. Upgrade to CFK 3.3.1 or later, which adds a configurable idle-connection timeout to fix this. See [25 September, 2026] Confluent for Kubernetes 3.3.1 Release Notes.
Deprecations
There are no new deprecations in this release.