# Release 3.5.0 (/release-notes/v3-5-0)



**Released September 25, 2026.** kmq can now install, license and manage KubeMQ on Docker, Podman and Kubernetes. From this release kmq and the server share one version number. There is no server release 3.4.0.

## Artifacts [#artifacts]



| Artifact                 | Version                                                           |
| ------------------------ | ----------------------------------------------------------------- |
| kmq                      | `v3.5.0`                                                          |
| Server image             | `europe-docker.pkg.dev/kubemq/images/kubemq-next:v3.5.0`          |
| Server image (FIPS)      | `europe-docker.pkg.dev/kubemq/images/kubemq-next-fips:v3.5.0`     |
| Operator image           | `europe-docker.pkg.dev/kubemq/images/kubemq-operator-next:v3.4.0` |
| Helm chart `kubemq-next` | 3.4.0 (operator `v3.4.0`, server `v3.5.0`)                        |

## Before you upgrade [#before-you-upgrade]

* **A server with a license key must reach the license service once after the upgrade.** On its first start on 3.5.0, a server started with a license key contacts the KubeMQ license service (`license.kubemq.io`), even if its last check-in is still valid. This also applies on Kubernetes. Make sure the server can reach the license service when you upgrade; later restarts behave as before. Servers on the evaluation or on an offline license file are not affected.
* **Helm: the operator and each cluster are separate releases.** Chart 3.4.0 refuses to render a release that sets both `operator.enabled` and `cluster.enabled`, and `cluster.enabled` now defaults to `false`. If one release holds both today, move it first: see [Upgrade KubeMQ](/deploy/upgrade#combined-release).
* **`helm uninstall` keeps the cluster.** The chart's pre-delete hook is gone, and setting `preDelete.enabled: true` is refused. Uninstalling a cluster release leaves the `KubemqCluster` and its volumes in place.
* **The management API is same-origin by default.** Before 3.5.0 a web page on any origin could read from the management API; changes from other sites were already refused. To let a web page on another origin call the management API, list that origin in `API_ALLOW_ORIGINS`.

## Changes [#changes]

* **kmq installs and manages KubeMQ.** `kmq onboard` starts a server from simple defaults. `kmq deploy` plans, applies, updates, restarts, diagnoses and removes an installation, and prepares pinned images, the Kubernetes namespace and protected Secrets ahead of an install. See [Install with kmq](/deploy/install/kmq).
* **kmq handles trial keys and licenses.** `kmq trial` requests, verifies and claims a trial key from the command line. `kmq license` saves, lists, shows and exports licenses in a protected local store. `kmq auth` sets up and signs in to the management API and saves the credential.
* **kmq migrates from Apache Kafka.** `kmq migrate` adds `plan`, `prepare`, `target-check`, `rehearse`, `verify`, `report`, `job` and a guarded set of `cutover-*` commands. See [Migrate from Kafka](/connectors/kafka/how-to/migrate-from-kafka).
* **Single-server Podman.** The server runs as one container on Podman as well as Docker.
* **HTTPS for the management API.** Set both `API_TLS_CERT_FILE` and `API_TLS_KEY_FILE`; see [Security](/configure/reference/security). On Kubernetes, operator 3.4.0 reads the management certificate from the TLS Secret named in `spec.api.tlsSecret`.
* **Replacing a license keeps the server.** A new license key or offline license file keeps the server's identity and stored messages. The server never falls back to a cached license that belongs to a different key.
* **Kubernetes cluster identity.** The operator identifies a cluster by its Kubernetes object, not its name: a cluster deleted and re-created under the same name is a new cluster. The operator reports a cluster ready only when the rollout it observed is complete.

## Known issues [#known-issues]

* Images are published for `linux/amd64` only. Release [3.5.2](/release-notes/v3-5-2) adds `linux/arm64`.
* No default connector image is published. Set `spec.image` on every `KubemqConnector`.
