The v1 API: What Changed and What Was Removed
The v1 API, introduced in Strimzi 0.49, removes all ZooKeeper-related configuration and deprecated stateful set options. Keycloak authorization and Open Policy Agent authorization APIs were removed, not the features themselves. Those now use Strimzi’s typed custom APIs, which accept any authentication or authorization mechanism and require less maintenance per release. The 1.0 release drops the old APIs entirely, making the cleanup final after three transitional releases.
Upgrading to 1.0: The Conversion Tool and Flexible Paths
Users on Strimzi 0.46 through 0.48 must migrate from ZooKeeper to KRaft before upgrading. From there, they can jump directly to 0.49, 0.50, or 0.51 without going through all three. Versions 0.49-0.51 support both old and new APIs, giving teams time to convert custom resources. Once ready for 1.0, the conversion tool handles the CRD upgrade: it removes old API versions from the CRD status subresource so the new CRDs can go in clean.
Why Strimzi Took Eight Years to Reach 1.0
Strimzi merged nearly 7,000 PRs across 51 minor releases before reaching 1.0. The delay had nothing to do with production readiness. Cloudera, Red Hat, and IBM all shipped products built on Strimzi while it sat at 0.x. The actual cause: maintainers decided to wait for ZooKeeper removal from Kafka before cutting 1.0, expecting it within a year. That year stretched to four. Sunk-cost thinking kept the wait going. The time wasted was mostly spent explaining why a production-grade project had no 1.0.
Automated KRaft Dynamic Quorum Management
With static quorum, controller membership is fixed at startup, making scale-up and scale-down risky without downtime. Dynamic quorum uses a voters record exchanged through the metadata topic. New controllers join as observers, replicate metadata, then register into the quorum. A Strimzi proposal, open for feedback, automates this entirely. The operator registers and unregisters controllers as replica counts change, handles role transitions between combined and dedicated nodes, and migrates clusters from static to dynamic quorum on upgrade.
Cert Manager Integration and the Gateway API Shift
Cert manager integration, already accepted and in progress, removes certificate lifecycle from the Strimzi operator. The operator still handles Kafka configuration but hands certificate operations to cert manager. Auto-rebalancing gains anomaly detection through Cruise Control: when goal violations appear, the operator triggers a KafkaRebalance resource rather than letting Cruise Control act on its own. Gateway API integration replaces NGINX ingress, archived at KubeCon. Users bring their own gateway and configure a TLS route listener. Strimzi creates the TLSRoute resource and supports both TLS passthrough and TLS termination.
Notable Quotes
almost 7,000 uh PRs that were merged Jakub Scholz · ▶ 09:02
release and yet we are production ready. Jakub Scholz · ▶ 12:03
retired. It happened yet uh yesterday. Paolo Patierno · ▶ 21:39
Key Takeaways
- The v1 API removes all ZooKeeper configuration; 1.0 drops the old APIs entirely, completing the cleanup.
- Versions 0.49-0.51 support both old and new APIs, giving teams time to convert custom resources before upgrading.
- The 8-year gap between founding and 1.0 came from waiting on ZooKeeper removal, not from production immaturity.
- Upcoming work includes automated KRaft dynamic quorum management, cert manager integration, and Gateway API support.
About the Speakers
Jakub Scholz is an engineer at Cloudera and a CNCF Ambassador. He is one of the founders and maintainers of the Strimzi project, with long-term experience in Kubernetes, streaming, and messaging, focused primarily on Apache Kafka and its integration with Kubernetes.
Paolo Patierno is a Senior Principal Software Engineer at IBM working on the messaging and data streaming team. He is a maintainer of Strimzi, a CNCF incubating project for running Apache Kafka on Kubernetes using operators.