# Release 3.5.2 (/release-notes/v3-5-2)



**Released September 27, 2026.** Server images are published for `arm64` as well as `amd64`, the management password minimum is 6 characters, and kmq explains sign-in failures. The operator and the Helm chart are unchanged from [3.5.0](/release-notes/v3-5-0).

## Artifacts [#artifacts]



| Artifact                 | Version                                                                                            |
| ------------------------ | -------------------------------------------------------------------------------------------------- |
| kmq                      | `v3.5.2`                                                                                           |
| Server image             | `europe-docker.pkg.dev/kubemq/images/kubemq-next:v3.5.2`, for `linux/amd64` and `linux/arm64`      |
| Server image (FIPS)      | `europe-docker.pkg.dev/kubemq/images/kubemq-next-fips:v3.5.2`, for `linux/amd64` and `linux/arm64` |
| Operator image           | `europe-docker.pkg.dev/kubemq/images/kubemq-operator-next:v3.4.0` (unchanged)                      |
| Helm chart `kubemq-next` | 3.4.0 (unchanged; it installs server `v3.5.0`)                                                     |

## Before you upgrade [#before-you-upgrade]

* **Nothing new to prepare.** The operator and the Helm chart are the same as in 3.5.0, and the Helm chart still installs server 3.5.0. Coming from a release before 3.5.1, also read [Before you upgrade in 3.5.1](/release-notes/v3-5-1#before-you-upgrade); coming from 3.3.x, also read [Before you upgrade in 3.5.0](/release-notes/v3-5-0#before-you-upgrade).

## Changes [#changes]

* **Server images for `arm64`.** The server image and the FIPS image are published for `linux/arm64` as well as `linux/amd64`, under one tag, so a container runtime pulls the image for its own architecture.
* **Management password minimum is 6 characters**, down from 12, for the dashboard and the management API. Every refusal states the minimum.
* **kmq sign-in.** `kmq auth setup` states the password minimum in its prompt, checks it before sending anything, asks you to confirm the password on a terminal, and uses `admin` as the administrator name unless you give another. `kmq auth login` asks for the administrator name on a terminal when you omit `--username`.
* **kmq reports the server's reason.** When the management server refuses a request, kmq now shows the reason the server gave, such as a password below the minimum, instead of a general failure.
* **kmq runs an `amd64`-only image on an `arm64` host.** `kmq deploy` on Docker or Podman now selects `linux/amd64` emulation for such an image, and says so in its plan and result, instead of refusing.

## Known issues [#known-issues]

* No default connector image is published. Set `spec.image` on every `KubemqConnector`.
