Release 3.5.3
KubeMQ 3.5.3 fixes a Kafka client-handshake regression and OffsetFetch v1 support, and kmq deploy now publishes the Kafka and AMQP ports by default.
Released September 27, 2026. A Kafka connection from a current client library no longer drops, OffsetFetch works with clients that only speak version 1, and kmq deploy publishes the Kafka and AMQP ports by default. The operator and the Helm chart are unchanged from 3.5.2.
Artifacts
| Artifact | Version |
|---|---|
| kmq | v3.5.3 |
| Server image | europe-docker.pkg.dev/kubemq/images/kubemq-next:v3.5.3, for linux/amd64 and linux/arm64 |
| Server image (FIPS) | europe-docker.pkg.dev/kubemq/images/kubemq-next-fips:v3.5.3, for linux/amd64 and linux/arm64 |
| Operator image | europe-docker.pkg.dev/kubemq/images/kubemq-operator-next:v3.4.0 (unchanged) |
Helm chart kubemq-next | 3.4.0 (unchanged; it installs server v3.5.0) |
Before you upgrade
- Nothing new to prepare. The operator and the Helm chart are the same as in 3.5.2. Coming from a release before 3.5.1, also read Before you upgrade in 3.5.1.
Changes
- A Kafka connection from a current client no longer drops on the first request.
ApiVersionsrequests above the server's supported version (3) were decoded with the older request layout before the version check ran, so the decode failed and the connection was torn down. The body is now left undecoded until after the check, so the client gets the existingUNSUPPORTED_VERSIONreply and renegotiates, as real Apache Kafka 4.3.1 does. This fixed every connection failing against franz-go 1.22.0. OffsetFetchworks with clients that only request version 1, such as segmentio/kafka-go. Version 1 has no top-level error field, so a request-wide error — no coordinator, not ready, an invalid group, authorization denied, or a proxy drop — is now repeated on every requested partition instead of the client seeing a silent success.- A topic is visible right after
CreateTopicsorDeleteTopics. A successful call now drops the cached all-topics list, so a client that discovers topics that way no longer fails a write issued right after the topic is created. kmq deploypublishes the Kafka and AMQP connectors by default, on ports 9092 and 5672, and both connectors are enabled by default in the server. New--amqp-portflag alongside the existing--kafka-port; set either to0to leave that port unpublished.
Known issues
- No default connector image is published. Set
spec.imageon everyKubemqConnector.
Was this page helpful?
How KubeMQ versions work
The numbering history of KubeMQ releases, why the current product jumped from 1.3 to 3.3, and how the legacy kubemq image and charts differ.
Release 3.5.2
KubeMQ 3.5.2 publishes server images for arm64 as well as amd64, lowers the management password minimum to 6 characters, and clarifies kmq sign-in.