KubeMQ
Release notes

Release 3.5.0

KubeMQ 3.5.0 lets kmq install and license KubeMQ, supports single-server Podman and HTTPS management, and splits the Helm operator and cluster releases.

Released September 25, 2026. kmq can now install, license and manage KubeMQ on Docker, Podman and Kubernetes. From this release kmq and the server share one version number. There is no server release 3.4.0.

Artifacts

ArtifactVersion
kmqv3.5.0
Server imageeurope-docker.pkg.dev/kubemq/images/kubemq-next:v3.5.0
Server image (FIPS)europe-docker.pkg.dev/kubemq/images/kubemq-next-fips:v3.5.0
Operator imageeurope-docker.pkg.dev/kubemq/images/kubemq-operator-next:v3.4.0
Helm chart kubemq-next3.4.0 (operator v3.4.0, server v3.5.0)

Before you upgrade

  • A server with a license key must reach the license service once after the upgrade. On its first start on 3.5.0, a server started with a license key contacts the KubeMQ license service (license.kubemq.io), even if its last check-in is still valid. This also applies on Kubernetes. Make sure the server can reach the license service when you upgrade; later restarts behave as before. Servers on the evaluation or on an offline license file are not affected.
  • Helm: the operator and each cluster are separate releases. Chart 3.4.0 refuses to render a release that sets both operator.enabled and cluster.enabled, and cluster.enabled now defaults to false. If one release holds both today, move it first: see Upgrade KubeMQ.
  • helm uninstall keeps the cluster. The chart's pre-delete hook is gone, and setting preDelete.enabled: true is refused. Uninstalling a cluster release leaves the KubemqCluster and its volumes in place.
  • The management API is same-origin by default. Before 3.5.0 a web page on any origin could read from the management API; changes from other sites were already refused. To let a web page on another origin call the management API, list that origin in API_ALLOW_ORIGINS.

Changes

  • kmq installs and manages KubeMQ. kmq onboard starts a server from simple defaults. kmq deploy plans, applies, updates, restarts, diagnoses and removes an installation, and prepares pinned images, the Kubernetes namespace and protected Secrets ahead of an install. See Install with kmq.
  • kmq handles trial keys and licenses. kmq trial requests, verifies and claims a trial key from the command line. kmq license saves, lists, shows and exports licenses in a protected local store. kmq auth sets up and signs in to the management API and saves the credential.
  • kmq migrates from Apache Kafka. kmq migrate adds plan, prepare, target-check, rehearse, verify, report, job and a guarded set of cutover-* commands. See Migrate from Kafka.
  • Single-server Podman. The server runs as one container on Podman as well as Docker.
  • HTTPS for the management API. Set both API_TLS_CERT_FILE and API_TLS_KEY_FILE; see Security. On Kubernetes, operator 3.4.0 reads the management certificate from the TLS Secret named in spec.api.tlsSecret.
  • Replacing a license keeps the server. A new license key or offline license file keeps the server's identity and stored messages. The server never falls back to a cached license that belongs to a different key.
  • Kubernetes cluster identity. The operator identifies a cluster by its Kubernetes object, not its name: a cluster deleted and re-created under the same name is a new cluster. The operator reports a cluster ready only when the rollout it observed is complete.

Known issues

  • Images are published for linux/amd64 only. Release 3.5.2 adds linux/arm64.
  • No default connector image is published. Set spec.image on every KubemqConnector.

Was this page helpful?

On this page