# Release 3.3.0 (/release-notes/v3-3-0)



**Released September 23, 2026.** This release refuses installation shapes KubeMQ does not support and makes the first minutes of an evaluation easier to follow. It is the first release numbered above the legacy product; see [How KubeMQ versions work](/release-notes/versioning).

## Artifacts [#artifacts]



| Artifact                 | Version                                                                                       |
| ------------------------ | --------------------------------------------------------------------------------------------- |
| Server image             | `europe-docker.pkg.dev/kubemq/images/kubemq-next:v3.3.0`                                      |
| Server image (FIPS)      | `europe-docker.pkg.dev/kubemq/images/kubemq-next-fips:v3.3.0`                                 |
| Operator image           | `europe-docker.pkg.dev/kubemq/images/kubemq-operator-next:v3.3.0`, then `v3.3.1` the same day |
| Helm chart `kubemq-next` | 3.3.0 (operator `v3.3.0`, server `v3.3.0`), then 3.3.1 (operator `v3.3.1`, server `v3.3.0`)   |
| kmq                      | No new release                                                                                |

## Before you upgrade [#before-you-upgrade]

* **Only supported installations start.** The server refuses to start as a native process, under a container runtime other than Docker, as a clustered Docker server, or on Kubernetes without the operator or with fewer than 3 servers. It stops before it reads the license or changes stored data. Move such an installation to a [supported setup](/deploy/install/requirements#supported-setups) before you upgrade. Single-server Podman is supported from [3.5.0](/release-notes/v3-5-0).
* **Kubernetes clusters need at least 3 servers.** The operator refuses to reconcile a cluster with `standalone: true` or fewer than 3 servers, and leaves its running pods and volumes as they are. Move such a cluster before you upgrade. A new cluster also needs a license that covers its server count.
* **Kafka exposed outside a cluster needs per-server addresses.** On a clustered `KubemqCluster`, `spec.kafka.expose` set to `NodePort` or `LoadBalancer` now requires `spec.kafka.peers`. The operator refuses the change before it touches the running cluster.

## Changes [#changes]

* **First administrator on Docker.** On a fresh Docker server, management sign-in is on unless you turn it off, and the first person to open the dashboard chooses the administrator. Until then the dashboard and the management API stay locked; messaging keeps its own security settings. The choice survives restarts and container replacement, and recovering the administrator does not delete messages. Sign-in settings you set yourself are kept.
* **The first minutes say what is happening.** A server started without a license key that cannot reach the license service now logs what it is waiting for and how to proceed. A Kafka connector you enabled by name fails startup when its port is taken, naming the port; the default-on Kafka connector is switched off instead, and the log and the dashboard banner say why.
* **Two licensing terms.** Messages and the dashboard now say "evaluation" for the 14-day run without a key and "trial key" for the 30-day key from the trial form. When an evaluation ends, the message offers both ways forward: add a trial key, or remove the volume, which deletes its messages, and start again.
* **Dashboard.** Empty lists are told apart from failed requests, with a retry. All six dashboard languages are complete.
* **RabbitMQ (AMQP 0-9-1).** Clearing expired messages at the head of a queue no longer loses the live message behind them, and binding destinations are validated.
* **Kubernetes.** On OpenShift, chart 3.3.0 no longer grants the server's service account the `privileged` security context constraint. Operator 3.3.1 changes only the operator's own install manifest, which no longer creates a Role for that constraint; clusters behave as with 3.3.0.

## Known issues [#known-issues]

* Images are published for `linux/amd64` only. Release [3.5.2](/release-notes/v3-5-2) adds `linux/arm64`.
* No default connector image is published. Set `spec.image` on every `KubemqConnector`.
