Kafka Connect 0.7.0 Changelog
[0.7.0] - 2026-09-29
Initial release. The chart renders a Strimzi KafkaConnect resource
and its supporting manifests; the Strimzi operator owns the workers.
Added
-
Plugin delivery in two modes: per-plugin OCI images mounted as image volumes (
imageVolumes, default) or one prebuilt image per profile (prebuiltImage, withprebuiltImageRegistryfor mirrors). Plugin specs live inplugins/; release bundles (.zip,.tar) are unpacked and their jars flattened, keepingLICENSE/NOTICE. -
Plugins: Apicurio converter, Axual HTTP sink, Axual Kafka sync, Camel SFTP sink/source, Stream Reactor FTP, Debezium (MongoDB, MySQL, Oracle, PostgreSQL, SQL Server), FileStream and
kafka-topic-name-transforms. -
Worker authentication with mTLS or SASL/SCRAM-SHA-512, and
bootstrapServersper listener. -
Cluster identity (
tenant,instance,clusterName), required and validated as label values. They label the worker pods for the log viewer and derive the group id and internal topic names (_<tenant>-<instance>-<clusterName>-connect[-configs|-offsets|-status]), so two clusters on one Kafka never merge. An upgrade that would change these names fails before applying anything. -
ACL bootstrap Job (
aclBootstrap): a pre-install/pre-upgrade hook that creates the internal topics and grants the worker ACLs, as an mTLS or SCRAM superuser. -
Vault integration (
vault) for${vault:...}placeholders in connector configs, with the AppRole credentials in a Secret (vault.credentialsSecret). -
REST API route with basic auth (
restApi): anIngressorHTTPRoute, an htpasswd Secret,extraObjectsfor implementation-specific auth, and aNetworkPolicythat leaves the route as the only way to port 8083. Examples for ingress-nginx, F5 NIC and NGINX Gateway Fabric. -
ECS JSON worker logs with
logging.level,logging.loggersandlogging.monitorInterval. -
Pod hardening: restricted
podSecurityContext/securityContextby default, plusruntimeClassName(via a Kyverno policy),affinity,tolerationsandpodAnnotations. -
Strict values schema: unknown keys are rejected everywhere.