Axual 2026.3 Release Notes
Helm Charts Release Notes
Axual Governance Charts
1.6.0 - 2026-09-30
-
Update
Chart.yamlto use platform-manager16.0.0dependency chart -
Update
Chart.yamlto use platform-ui14.0.0dependency chart -
Update
Chart.yamlto use topic-browse0.9.0dependency chart -
Update
Chart.yamlto use api-gateway0.11.0dependency chart -
Update
Chart.yamlto use metrics-exposer1.7.0dependency chart
Axual Governance Charts Component Versions
| Component | Version |
|---|---|
0.11.0 |
|
Keycloak |
26.6.4 |
1.7.0 |
|
16.0.0 |
|
14.0.0 |
|
0.9.0 |
|
Vault |
2.0.4 |
Axual Kafka Connect Charts
0.7.0 - 2026-09-29
-
Deliver plugins as per-plugin OCI image volumes (
imageVolumes, default) or as one prebuilt image per profile (prebuiltImage) -
Bundle plugin specs for the Apicurio converter, Axual HTTP sink, Axual Kafka sync, Camel SFTP sink and source, Stream Reactor FTP, Debezium (MongoDB, MySQL, Oracle, PostgreSQL, SQL Server), FileStream and
kafka-topic-name-transforms -
Authenticate workers with mTLS or SASL/SCRAM-SHA-512, with
bootstrapServersper listener -
Derive the group id and internal topic names from the required
tenant,instanceandclusterNamevalues, and fail an upgrade that would change them -
Create the internal topics and worker ACLs in a pre-install and pre-upgrade hook Job (
aclBootstrap) -
Resolve
${vault:…}placeholders in connector configs through Vault AppRole credentials (vault) -
Expose the REST API through an
IngressorHTTPRoutewith basic auth and aNetworkPolicythat restricts port 8083 to the route (restApi) -
Write worker logs as ECS JSON, with configurable levels per logger (
logging) -
Run pods with a restricted security context by default, with optional
runtimeClassName,affinity,tolerationsandpodAnnotations -
Reject unknown keys anywhere in the values file through a strict schema
Axual Runtime Provisioner Charts
0.8.0 - 2026-09-29
-
ksml-provisioner is renamed to runtime-provisioner
-
The alert name, the service, job, container and app.kubernetes.io/name labels and the OpenTelemetry service.name and scope all follow the rename, so dashboards, alert routes and silences stop matching
-
Fix the OpenShift Route, which carried no traffic: it asked for a targetPort the Service does not have, and route.path defaulted to /api, which reaches no handler. route.path and the Ingress path now default to /
-
A working Route or Ingress publishes an unauthenticated service, so set BASIC_AUTH_ENABLED=true with a username and password before you enable either
-
Docker mode containers are labelled axual.io/managed-by=runtime-provisioner, and the bulk /status matches that label on its key, so containers left by 0.7.x stay listed and none has to be recreated
-
Add GET /kafkaconnect/logs/download, which streams every worker’s current log file as one plain-text attachment in labelled sections, capped by CONNECT_DOWNLOAD_CAP_BYTES, 64 MiB by default
-
Breaking for trace queries: the log download reports its spans under the shared scope axual.io/otel/runtime-provisioner instead of kafkaconnect-download, matching every other handler. The span name is unchanged
-
The connector filter matches a log entry on its connector.context field instead of searching the line text, ending false positives such as a filter for sink matching orders-sink
-
GET /kafkaconnect/logs accepts minLevel, keeping only lines at that severity or above in both modes, with stack trace lines kept alongside the line they belong to
-
The connector filter no longer matches a connector whose name is a hyphen-separated suffix of another, so sink stops matching connector-producer-orders-sink-0
-
A log stream reports when its history reached the start of what the workers still hold, so a short window is told apart from a log that has ended
-
A Kafka Connect log stream sends the history a batch request answers with and then follows the log, from one read per worker, so tailLines means the same in both modes
-
Breaking for API clients: GET /kafkaconnect/logs answers with entries, one time-ordered list carrying origin and timestamp per line, plus linesRead, linesReturned and degraded. The per-worker logs field is gone
-
A filtered request reads a wider raw window, so tailLines bounds the answer and not the read. Adds CONNECT_FILTER_WINDOW_PERCENT (default 2000) and CONNECT_FILTER_WINDOW_MAX_LINES (default 50000), and the matching chart values
-
Breaking for dashboards: the metric kafkaconnect.log.stream.errors is renamed to kafkaconnect.log.read.errors and gains a mode attribute of batch or stream
-
Log streaming sends Waiting for output from the application… after 2 seconds of silence, and KSML reports a not-started container as starting instead of failing with a 500
-
Add GET /kafkaconnect/logs, merging one Kafka Connect cluster’s worker pod logs into a single JSON or NDJSON answer, with the CONNECT_NAMESPACES, CONNECT_CONTAINER_NAME and MAX_CONCURRENT_LOG_STREAMS settings
-
Add /healthz and /readyz, serve the KSML endpoints under /ksml/ beside the flat paths, and add KSML_ENABLED to switch KSML support off
-
Breaking for the chart: liveness and readiness now use /healthz and /readyz instead of a port check, so do not pin image.tag below this chart version or the container restarts in a loop
-
KSML log streaming can answer 503 when MAX_CONCURRENT_LOG_STREAMS is reached, because the cap is shared with Kafka Connect log streaming
-
Add DOCKER_KSML_RUNNER_DEFAULTS_FILE to Docker mode, a ksml-runner.yaml-shaped defaults file deep-merged under every generated runner config, giving Docker Compose what CUSTOM_VALUES_FILE gives Kubernetes mode
-
Update dependencies (Helm 3.22.0, golang.org/x/crypto 0.57.0 with a security fix, OpenTelemetry OTLP gRPC exporter 1.46.0, and related modules)
-
Update default KSML CHART_VERSION to 1.3.2
Axual Distributor Charts
5.7.0 - 2026-10-01
-
Add self stall-detection for message distributor tasks: the task reports when it is RUNNING but not making progress while work is pending, through new config stall.detection.enabled / stall.detection.threshold.ms / stall.detection.check.interval.ms, new metrics message_distributor_batch_processor_stalled, message_distributor_batch_processor_no_progress_ms and message_distributor_batch_processor_assigned_partitions, and a new DistributorTaskStalled alert. Detection only reports (metric plus log line); it never fails or restarts the task.
-
Count every stop-progress failure per partition: a batch-level failure now increments message_distributor_batch_processor_partition_exception_count_total (previously only per-record produce failures were counted), so the exceptions view is trustworthy.
-
Dashboard: add stall, progress (copy rate vs arrival), per-partition lag and topic-partitioning panels to the Message Distributor dashboard.
-
Dashboard: add a "Time without progress (ms) per task" panel that plots message_distributor_batch_processor_no_progress_ms against the stall threshold, so the gauge now has a consumer.
-
Dashboard: empty-result health stats (Running/Failed Tasks, exception counts, "Distributing?") now fall back to 0/OK instead of showing an ambiguous "No data" when nothing has happened yet. The "Distributing?" panel also groups by connector so it matches the DistributorTaskStalled alert.
-
Integration tests: run out of the box on macOS Docker Desktop (Docker Engine 29+, API >= 1.40) with no manual ~/.docker-java.properties / ~/.testcontainers.properties. A macOS-only Maven profile in distributor-integrationtest points Testcontainers at the real engine socket, sets a supported Docker API version, and fixes Ryuk startup so it cleans up the test containers. Linux CI is unaffected (the profile activates only on macOS).
-
Unit tests: pass on newer JDKs (JDK 25 / latest LTS) with mvn test, no JDK switch and no extra flags. Byte Buddy is pinned to 1.17.8 (overriding the 1.17.5 that Mockito 5.18.0 bundles), which could not instrument mocks under JDK 25 ("Could not modify all classes", e.g. RemoteProducerTest). Still builds and tests on JDK 17/21.
-
Dependency updates: Kafka connect-api/connect-runtime to 4.3.1, Avro to 1.12.2, Lombok to 1.18.48, slf4j to 2.0.19, Guava to 33.7.1-jre, Commons Lang3 to 3.20.0, Commons Text to 1.15.0, Dropwizard Metrics JMX to 4.2.40, Jackson Databind to 2.22.2, and several Maven plugin/CI tooling versions. JUnit is upgraded to the JUnit 6 major line (6.1.3). CI: gitlab-pipeline-tools to 2.22.1, which runs the Helm lint jobs on GitLab-hosted arm64 runners and fixes the alpine/helm entrypoint for them.
-
Fix two tests that broke under the newer Kafka connect-api (it now requires bootstrap.servers with no default): OffsetDistributorTest.metrics and OffsetDistributorTaskTest.cacheTimeoutIsConfigurable now set local.bootstrap.servers / target.bootstrap.servers in their test configs.
-
Pin jackson-annotations to 2.22 alongside jackson-databind in distributor-common, so it matches everywhere. Without this, distributor-integrationtest’s test-scope connect-runtime pulled in an older jackson-annotations that did not match the newer jackson-databind, and Kafka Connect’s plugin scanner failed to load JsonConverter with a NoClassDefFoundError.
-
Update kafka-synchronisation-connectors to 2.0.0. Fixes a data race in the upstream KafkaSinkRunner (an unsynchronized offsets map shared between the runner thread and the Kafka Connect commit thread, which could throw ConcurrentModificationException or lose an offset commit) and a thread leak in KafkaSinkTask.stop(). Both apply to schema-distributor, which uses this library’s sink runner. No config or code changes needed here: schema-distributor never used the removed deprecated topic.selector string config, and its connector class does not go through the library’s own connector-level validation where the new default-on remote-connectivity check lives.
-
Fix MessageDistributionChaosIT flaking on a loaded machine: its initial pre-chaos sanity check used a fixed 20s window expecting an exact record count, the same pattern that used to make the post-chaos check flaky. It now waits until every produced record is seen remotely, with early exit, like the post-chaos check already did.
-
Run the CI coverage-gitlab job on the arm64 image jacoco2cobertura:1.0.11-arm64, so it works on the arm64 runners. The amd64-only tags (1.0.10 / 1.0.11) hang during the runner’s shell detection (detect_shell_script: applet not found) and only fail after the 1-hour job timeout. Also added a short job timeout as a safety net so any future hang fails fast; the job stays allow_failure.
Axual Streaming Charts
3.0.0 - 2026-09-30
-
Update
Chart.yamlto use rest-proxy1.18.0dependency chart -
Update
Chart.yamlto use apicurio-registry-v3 0.2.0 dependency chart -
Enable apicurio-registry-v3 by default (global.apicurio-registry-v3.enabled)
-
Remove the apicurio-registry (v2) dependency chart and its global.apicurio.enabled toggle, apicurio-registry-v3 is now the only Schema Registry
Axual MCP Server Charts
0.2.2 - 2026-06-26
MCP Tools
-
Add search_access_grants tool for searching grant connections between applications and topics; filters by environment_uid (required), application_uid, topic_uid, and statuses (PENDING, APPROVED, REJECTED, CANCELLED); returns grant uid, status, access type, topic, environment, and application info
-
Add operate_access_grants tool for approving, rejecting, or cancelling a PENDING access grant; REJECT requires a reason; revoking APPROVED grants is explicitly blocked
-
Add update_application tool for updating an application’s metadata (name, description, type, properties, applicationId) and/or its deployment configuration in a specific environment; deployment config updates automatically stop and restart the deployment if it was running
-
Add register_application tool for registering self-managed CUSTOM applications with auto-generated applicationId and shortName, smart owner group resolution, and duplicate field error reporting
-
Add search_applications tool for searching applications by name, applicationId, shortName, group, applicationType (CUSTOM, KSML, CONNECTOR), or visibility with pagination support
-
Add get_application_details tool providing a comprehensive view of an application including per-environment credentials, principals, access grants, deployment state, and cluster connectivity info (bootstrap servers, Schema Registry listeners); includes deployment state and configs for KSML and Connector types
-
Add create_application_authentication tool for provisioning SASL/SCRAM credentials for an application in a specific environment
MCP Resources
-
Add environment resource exposing Axual environment information to MCP clients
-
Add KSML data generator resource with documentation and examples for producing messages
-
Add KSML definition resource providing the KSML guide to MCP clients
Authentication & Security
-
Enforce redirect URI whitelist on OAuth authorization requests (AXPD-11489). The new MCP_OAUTH_ALLOWED_REDIRECT_URIS env var (default: http://localhost:*) prevents open-redirect phishing attacks where an attacker could harvest authorization codes via a crafted authorize URL containing a malicious redirect_uri. Production deployments should set this to their server domain plus http://localhost:* (e.g., https://mcp.axual.se/,http://localhost:)