Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
84 changes: 84 additions & 0 deletions _posts/2026-10-08-release-0_25_0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
---
layout: post
title: "Kroxylicious release 0.25.0"
date: 2026-10-08 12:00:00 +0100
author: "Keith Wall"
author_url: "https://github.com/k-wall"
# noinspection YAMLSchemaValidation
categories: blog kroxylicious-proxy releases
tags: [ "releases", "kroxylicious-proxy" ]
---

Kroxylicious 0.25.0 has surfaced upstream! 🐊

0.25.0 brings Kubernetes-based authentication for HashiCorp Vault, improved control of the Kubernetes Service resources created for Load Balancer-based ingress, the ability to configure the Service Account used to run the proxy pods, and OpenRewrite recipes to aid configuration migrations. Take a look at [all the changes](https://github.com/kroxylicious/kroxylicious/blob/v0.25.0/CHANGELOG.md).

---

### Kubernetes Authentication for HashiCorp Vault KMS

Kroxylicious 0.25.0 adds Kubernetes authentication support to the HashiCorp Vault KMS provider. Running proxy instances in Kubernetes no longer requires managing Vault authentication tokens manually. You can now leverage HashiCorp Vault's [Kubernetes auth method](https://developer.hashicorp.com/vault/docs/auth/kubernetes) so that the Record Encryption filter authenticates to Vault using an annotated service account, giving you an improved security posture.

---

### Kubernetes Load Balancer Service Improvements

Several enhancements improve load balancer service integration support in the operator:

* annotations specified in the `KafkaProxyIngress` CR now flow to the load balancer `Services`. This is useful if you need to
have precise control of the type of load balancer deployed by your cloud provider.
* there's now the ability to control `externalTrafficPolicy` and `allocateLoadBalancerNodePorts` giving you fine-grained control over load balancer behaviour.
* if a single `KafkaProxyIngress` is shared by many `VirtualKafkaClusters`, the load balancer service remains shared. If you
use multiple `KafkaProxyIngress` resources of type `loadBalancer`, these will now result in distinct `Service` instances.

### Kubernetes Service Account Support

The `KafkaProxy` CR now allows you to refer to a Kubernetes `ServiceAccount` resource. If this is done, the proxy pods will use the
service account rather than the `default` service account.

### OpenRewrite Recipes for automated Configuration Upgrade

You may remember we dipped our toes into the world of OpenRewrite in 0.24.0, where we used it to automate code changes following an API change.

We've extended the migration to support some upgrades of the Kroxylicious configuration file. The scope is limited to the `clusterDefinitions` configuration refactor, but we intend to teach it new things in upcoming releases.

It is as easy as:

```shell
# dry-run
jbang io.kroxylicious:kroxylicious-migrations:0.25.0 convert-config --dry-run /path/to/kroxylicious-config.yaml
# or apply them
jbang io.kroxylicious:kroxylicious-migrations:0.25.0 convert-config /path/to/kroxylicious-config.yaml
```

---

### Community Contributions

This release included commits from:
- [Abdullah](https://github.com/search?q=Abdullah)
- [Aditya Thakur](https://github.com/AdityaThakur1998)
- [DragonFSKY](https://github.com/DragonFSKY)
- [Francisco Vila](https://github.com/search?q=Francisco+Vila)
- [henryZrncik](https://github.com/search?q=henryZrncik)
- [Hiroaki KAWAI](https://github.com/search?q=Hiroaki+KAWAI)
- [Jabrail](https://github.com/search?q=Jabrail)
- [jjj-n](https://github.com/jjj-n)
- [Keith Wall](https://github.com/k-wall)
- [Matheus André](https://github.com/matheusandre1)
- [Peter Mendis](https://github.com/search?q=Peter+Mendis)
- [Rafael Reia](https://github.com/RafaelReia)
- [Robert Young](https://github.com/search?q=Robert+Young)
- [Sam Barker](https://github.com/SamBarker)
- [Thomas Cooper](https://github.com/search?q=Thomas+Cooper)
- [Tom Bentley](https://github.com/tombentley)

Thank you all, your hard work is massively appreciated!

### Artefacts

Download binary distributions and container images from the [download](https://kroxylicious.io/download/0.25.0/) page.

### Feedback

Drop by and say hello on [Slack](https://kroxylicious.slack.com), [GitHub](https://github.com/kroxylicious/kroxylicious/issues), or [bsky](https://bsky.app/profile/kroxylicious.io). You can also join us in person at a [community call]({% link join-us/community-call/index.md %}).
Loading