Release notes
Release 3.5.0
KubeMQ 3.5.0 lets kmq install and license KubeMQ, supports single-server Podman and HTTPS management, and splits the Helm operator and cluster releases.
Released September 25, 2026. kmq can now install, license and manage KubeMQ on Docker, Podman and Kubernetes. From this release kmq and the server share one version number. There is no server release 3.4.0.
Artifacts
| Artifact | Version |
|---|---|
| kmq | v3.5.0 |
| Server image | europe-docker.pkg.dev/kubemq/images/kubemq-next:v3.5.0 |
| Server image (FIPS) | europe-docker.pkg.dev/kubemq/images/kubemq-next-fips:v3.5.0 |
| Operator image | europe-docker.pkg.dev/kubemq/images/kubemq-operator-next:v3.4.0 |
Helm chart kubemq-next | 3.4.0 (operator v3.4.0, server v3.5.0) |
Before you upgrade
- A server with a license key must reach the license service once after the upgrade. On its first start on 3.5.0, a server started with a license key contacts the KubeMQ license service (
license.kubemq.io), even if its last check-in is still valid. This also applies on Kubernetes. Make sure the server can reach the license service when you upgrade; later restarts behave as before. Servers on the evaluation or on an offline license file are not affected. - Helm: the operator and each cluster are separate releases. Chart 3.4.0 refuses to render a release that sets both
operator.enabledandcluster.enabled, andcluster.enablednow defaults tofalse. If one release holds both today, move it first: see Upgrade KubeMQ. helm uninstallkeeps the cluster. The chart's pre-delete hook is gone, and settingpreDelete.enabled: trueis refused. Uninstalling a cluster release leaves theKubemqClusterand its volumes in place.- The management API is same-origin by default. Before 3.5.0 a web page on any origin could read from the management API; changes from other sites were already refused. To let a web page on another origin call the management API, list that origin in
API_ALLOW_ORIGINS.
Changes
- kmq installs and manages KubeMQ.
kmq onboardstarts a server from simple defaults.kmq deployplans, applies, updates, restarts, diagnoses and removes an installation, and prepares pinned images, the Kubernetes namespace and protected Secrets ahead of an install. See Install with kmq. - kmq handles trial keys and licenses.
kmq trialrequests, verifies and claims a trial key from the command line.kmq licensesaves, lists, shows and exports licenses in a protected local store.kmq authsets up and signs in to the management API and saves the credential. - kmq migrates from Apache Kafka.
kmq migrateaddsplan,prepare,target-check,rehearse,verify,report,joband a guarded set ofcutover-*commands. See Migrate from Kafka. - Single-server Podman. The server runs as one container on Podman as well as Docker.
- HTTPS for the management API. Set both
API_TLS_CERT_FILEandAPI_TLS_KEY_FILE; see Security. On Kubernetes, operator 3.4.0 reads the management certificate from the TLS Secret named inspec.api.tlsSecret. - Replacing a license keeps the server. A new license key or offline license file keeps the server's identity and stored messages. The server never falls back to a cached license that belongs to a different key.
- Kubernetes cluster identity. The operator identifies a cluster by its Kubernetes object, not its name: a cluster deleted and re-created under the same name is a new cluster. The operator reports a cluster ready only when the rollout it observed is complete.
Known issues
- Images are published for
linux/amd64only. Release 3.5.2 addslinux/arm64. - No default connector image is published. Set
spec.imageon everyKubemqConnector.
Was this page helpful?
Release 3.5.1
KubeMQ 3.5.1 makes Kafka share groups generally available with Kafka 4.3 parity and adds kmq update and kmq version --check.
Release 3.3.0
KubeMQ 3.3.0 starts only on supported installations, lets you choose the first dashboard administrator on Docker, and needs at least 3 servers on Kubernetes.