Release date 2026/09/15
Feature
Added
schema_registry.confluent.authentication.logical_cluster_idand.identity_pool_idconfiguration options, sent as thetarget-sr-clusterandConfluent-Identity-Pool-Idrequest headers when authenticating to Confluent Cloud Schema Registry withoauth2mode.
Bugfix
Fixed the confluent schema registry client caching fetched schemas and subjects under keys that did not account for the registry URL or authentication. Instances configured with different credentials could be served each other’s cached lookups, letting an unauthorized instance bypass schema-registry authentication once any authorized instance had warmed the cache. Cache entries are now scoped to the registry identity, and the configured
schema_registry.confluent.ttlis now applied to these cache entries.Fixed a crash that occurred when a plugin set
schema_registry.confluent.authentication.modetooauth2but omitted theoauth2_clientrecord. Previously this returned a 500 from the Admin API during validation, and once saved it also crashed at runtime while fetching the schema registry OAuth2 token. The absentoauth2_clientis now handled and falls back to the default authentication method, so a configuration withoutoauth2_clientworks end-to-end.Fixed a permanent failure that started when a broker answered an
ApiVersionsrequest with an error code, an empty API key set, or a malformed frame. The client cached that result and every later request failed withProduceRequest API version not negotiated; broker may be unreachableuntil the node restarted, even after the broker recovered. The client now refuses an unusableApiVersionsresponse, keeps the previous negotiation, and retries the negotiation for a topic whose metadata is already cached.
Performance
Added an improved asynchronous Kafka producer, opt-in via the new
new_kafka_async_producerconfig option (defaultfalse). When enabled, it batches and sends messages more efficiently under high load. Messages without a key are packed into larger per-partition batches; because Kafka does not guarantee ordering across partitions, their relative order may change. Set a message key if ordering matters — keyed messages are unaffected. The legacy producer remains the default.