Kafka Connect 0.7.0 Changelog

[0.7.0] - 2026-09-29

Initial release. The chart renders a Strimzi KafkaConnect resource and its supporting manifests; the Strimzi operator owns the workers.

Added

  • Plugin delivery in two modes: per-plugin OCI images mounted as image volumes (imageVolumes, default) or one prebuilt image per profile (prebuiltImage, with prebuiltImageRegistry for mirrors). Plugin specs live in plugins/; release bundles (.zip, .tar) are unpacked and their jars flattened, keeping LICENSE/NOTICE.

  • Plugins: Apicurio converter, Axual HTTP sink, Axual Kafka sync, Camel SFTP sink/source, Stream Reactor FTP, Debezium (MongoDB, MySQL, Oracle, PostgreSQL, SQL Server), FileStream and kafka-topic-name-transforms.

  • Worker authentication with mTLS or SASL/SCRAM-SHA-512, and bootstrapServers per listener.

  • Cluster identity (tenant, instance, clusterName), required and validated as label values. They label the worker pods for the log viewer and derive the group id and internal topic names (_<tenant>-<instance>-<clusterName>-connect[-configs|-offsets|-status]), so two clusters on one Kafka never merge. An upgrade that would change these names fails before applying anything.

  • ACL bootstrap Job (aclBootstrap): a pre-install/pre-upgrade hook that creates the internal topics and grants the worker ACLs, as an mTLS or SCRAM superuser.

  • Vault integration (vault) for ${vault:...} placeholders in connector configs, with the AppRole credentials in a Secret (vault.credentialsSecret).

  • REST API route with basic auth (restApi): an Ingress or HTTPRoute, an htpasswd Secret, extraObjects for implementation-specific auth, and a NetworkPolicy that leaves the route as the only way to port 8083. Examples for ingress-nginx, F5 NIC and NGINX Gateway Fabric.

  • ECS JSON worker logs with logging.level, logging.loggers and logging.monitorInterval.

  • Pod hardening: restricted podSecurityContext/securityContext by default, plus runtimeClassName (via a Kyverno policy), affinity, tolerations and podAnnotations.

  • Strict values schema: unknown keys are rejected everywhere.