Kafka Broker and Streams Enhancements
Confluent Platform 8.0: Client-side field level encryption (GA),  and More

Confluent Platform 8.0: Client-side field level encryption (GA), and More

6/24/2025 · Olivia Greene

What this post added

Confluent Platform 8.0 introduces KRaft as the default metadata management system, replacing ZooKeeper, which simplifies Kafka architecture, improves scalability (millions of partitions), and enables near-instant controller failover. The next-generation Confluent Control Center is now Prometheus-based, offering significant performance improvements: 2x faster metrics, support for up to 400K partitions, metrics freshness within 2-3 minutes, and 15x faster startup times (1 minute). It also integrates Confluent Manager for Apache Flink (CMF) for centralized management of Flink environments and applications. Client-Side Field Level Encryption (CSFLE) is now Generally Available, providing granular encryption of individual message fields for enhanced data protection and compliance. FlinkSQL is available in Open Preview via REST and CLI. Kafka Queues (Share Groups) are in Early Access, offering a native, cooperative consumption model for queue-style workloads. Confluent Community software will now align more closely with the Kafka release cycle. Passwordless authentication is now supported for Confluent Server and Schema Registry using OAuth client credentials grant type with pre-signed assertions. CFK 2.11.1 and Confluent Ansible 8.0.0 have been released to support these updates, with CFK allowing side-by-side deployment of new and legacy Control Center.

Read the original post ↗