Releases: camunda/camunda-platform-helm
camunda-platform-8.8-13.1.1
The changelog is automatically generated and it follows Conventional Commits format.
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/camunda:8.8.2
- docker.io/camunda/connectors-bundle:8.8.1
- docker.io/camunda/console:8.8.17
- docker.io/camunda/identity:8.8.0
- docker.io/camunda/keycloak:26.3.3
- docker.io/camunda/optimize:8.8.0
- docker.io/camunda/web-modeler-restapi:8.8.1
- docker.io/camunda/web-modeler-webapp:8.8.1
- docker.io/camunda/web-modeler-websockets:8.8.1
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.18.0
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-13.1.1.tgz \
--bundle "camunda-platform-13.1.1-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-13.1.1-cosign-verify.sh file.
camunda-platform-8.8-13.1.0
The changelog is automatically generated and it follows Conventional Commits format.
camunda-platform-13.1.0 (2025-10-27)
Features
- Data injection during testing (#4423)
Fixes
- Consistent naming for migrations and importer (#4477)
- Changing pod anti-affinity rules for migration jobs and importer (#4481)
- Allows cpu to be set as either string or number (#4491)
- Delete the migrator from 8.9 (#4503)
- The oidc scenario was always running the upgrade. Removing here … (#4523)
- Use joinPath helper to fix double slash issues in console configmap (#4562)
- Apply dual-region exclusion logic to opensearch exporter as well (#4352)
- Add back mapping rules in the orchestration cluster (#4545)
Revert
- Update camunda-platform-8.8 major (#4461)
- Install-tool-action part of feat - data injection during testing (#4467)
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/camunda:8.8.1
- docker.io/camunda/connectors-bundle:8.8.1
- docker.io/camunda/console:8.8.17
- docker.io/camunda/identity:8.8.0
- docker.io/camunda/keycloak:26.3.3
- docker.io/camunda/optimize:8.8.0
- docker.io/camunda/web-modeler-restapi:8.8.1
- docker.io/camunda/web-modeler-webapp:8.8.1
- docker.io/camunda/web-modeler-websockets:8.8.1
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.18.0
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-13.1.0.tgz \
--bundle "camunda-platform-13.1.0-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-13.1.0-cosign-verify.sh file.
camunda-platform-8.7-12.6.3
The changelog is automatically generated and it follows Conventional Commits format.
camunda-platform-12.6.3 (2025-10-21)
Fixes
- Fix link to upgrade instructions (#4450)
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/connectors-bundle:8.7.10
- docker.io/camunda/console:8.7.90
- docker.io/camunda/identity:8.7.7
- docker.io/camunda/keycloak:26.3.3
- docker.io/camunda/operate:8.7.15
- docker.io/camunda/optimize:8.7.11
- docker.io/camunda/tasklist:8.7.15
- docker.io/camunda/web-modeler-restapi:8.7.11
- docker.io/camunda/web-modeler-webapp:8.7.11
- docker.io/camunda/web-modeler-websockets:8.7.11
- docker.io/camunda/zeebe:8.7.15
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.17.4
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-12.6.3.tgz \
--bundle "camunda-platform-12.6.3-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-12.6.3-cosign-verify.sh file.
camunda-platform-8.6-11.10.2
The changelog is automatically generated and it follows Conventional Commits format.
camunda-platform-11.10.2 (2025-10-21)
Fixes
- Fix link to upgrade instructions (#4450)
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/connectors-bundle:8.6.20
- docker.io/camunda/console:8.6.90
- docker.io/camunda/identity:8.6.20
- docker.io/camunda/keycloak:25.0.6
- docker.io/camunda/operate:8.6.29
- docker.io/camunda/optimize:8.6.18
- docker.io/camunda/tasklist:8.6.29
- docker.io/camunda/web-modeler-restapi:8.6.20
- docker.io/camunda/web-modeler-webapp:8.6.20
- docker.io/camunda/web-modeler-websockets:8.6.20
- docker.io/camunda/zeebe:8.6.29
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.15.4
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-11.10.2.tgz \
--bundle "camunda-platform-11.10.2-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-11.10.2-cosign-verify.sh file.
camunda-platform-8.8-13.0.0
The changelog is automatically generated and it follows Conventional Commits format.
camunda-platform-13.0.0 (2025-10-13)
Refactor
- Upgrade keycloak image from 26.3.1 to 26.3.3 (#4386)
- Streamline OIDC and Microsoft Entra auth (#4416)
- Rename zeebe/orchestration labels (#4430)
Fixes
- No default backwardsCompatibleAudiences (#4421)
- Remove duplicate servicemonitor (#4428)
- Release-please should create a non-alpha release for 8.8.0 (#4439)
- Correct 13.0.0 version number
- Undo part of the release notes thats wrong version
- Fix doc links for 8.8 (#4453)
camunda-platform-8.5-10.11.3 (2025-10-08)
Features
Refactor
- Differentiate between orchestration services (#4190)
- Move orchestration oidc from global to component (#4233)
- Move connectors oidc from global to component (#4234)
- Support auth values in components (#4279)
- Use the main config in migrations (#4235)
- Use postgresql 14 for web modeler (#4287)
- Use postgres 14 for web modeler (#4327)
- Add nodeSelector, affinity, and tolerations to orchestration extra resources (#4366)
Fixes
- NoSecondaryStorage constraint no longer breaks unit tests (#4223)
- Wrong openshift compatibilty helper elasticsearch commonLabels usage (#4180)
- Operate opensearch access in the unified config (#4224)
- 2 issues.. the configmap for optimize was using the elasticsearch prefix value for opensearch and the QA scenarios where reusing the global prefix to shared OS failed CI (#4238)
- Add the oidc group claim to opensearch (#4244)
- Simplify oidc mappings in 8.8 (#4229)
- Firstuser defaults should not fire constraint (#4227)
- Partition-count typo in 8.8 chart (#4245)
- Identity migration inital contactPoint port number (#4260)
- Revert orchestration service name for backward compatibility (#4264)
- Comment in values.yaml for enabling management identity auth (#4273)
- Comment for identity existing secret (#4275)
- Add conditional properties for management components in manageme… (#4276)
- Revert tls secret placeholders (#4239)
- Add missing opensearch fields in templates (#4280)
- Reintroduce capability to disable all exporters again (#4272)
- Add security config to webmodeler (#4285)
- Data migration and importer config (#4286)
- Opensearch config and index replica placement (#4297)
- Use correct upgrade strategy for importer deployment (#4310)
- Data and identity migraiton accept orchestration env (#4291)
- Es/os exporter inherit index replicas (#4309)
- Clean up redundant secret templates (#4328)
- This PR is enabling Entra for testing (#4294)
- Correctly configure data migration (#4343)
- Define importer node id based on regionId (#4349)
- Adjust autogenerated secret detection patterns (#4342)
- Fix configurations of identity migration (#4344)
- Remove importer affinity in 8.8 (#4357)
- Unique importer ids for swim (#4360)
- Add audiences for backward compatibility (#4351)
- Correct sysctlImage structure in values-enterprise.yaml (#4339)
- Web modeler extraConfiguration uses subcomponent subkey (#4097)
- Should be using 8.8 instead of 8.9 connectors (#4267)
- Couple importer deployment with migration (#4346)
- In optimize cm, set the zeebe name to be equal to prefix (#4382)
- Set correct value for identity migration configmap (#4387)
- Set client secret based on what it's bound to on identity-side (#4400)
- Update QA 8.8 opensearch values file (#4405)
Revert
- "refactor: set default value for contextPath in all component… (#4221)
camunda-platform-8.5-10.11.2 (2025-09-18)
Features
- Opensearch aws enabled config now affects usage of AWS credentials (#4163)
- Add the document store scenario to the qa scenario list (#4117)
- Introduce authenticationRefreshInterval config parameter (#3958)
- Add resource authorizations flag to identity migration (#4197)
- Add default roles for initial users (#4194)
- Add extra mapping for initial client for identity OIDC migration (#4202)
Refactor
- Set default replicas to 1 for secondary storage (#4150)
- Run orchestration cluster from unified config (#4138)
Fixes
- Update migration job labels so requests are not routed to them (#4143)
- Enable exporters when data migration is enabled (#4196)
- Add constraints for ES and Basic auth in noSecondaryStorage mode (#4170)
- Adjust secret constraint to reflect new secrets management (#4182)
- Add missing global.identity.auth.identity.secret configuration (#4222)
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/camunda:8.8.0
- docker.io/camunda/connectors-bundle:8.8.0
- docker.io/camunda/console:8.8.3
- docker.io/camunda/identity:8.8.0
- docker.io/camunda/keycloak:26.3.3
- docker.io/camunda/optimize:8.8.0
- docker.io/camunda/web-modeler-restapi:8.8.0
- docker.io/camunda/web-modeler-webapp:8.8.0
- docker.io/camunda/web-modeler-websockets:8.8.0
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.18.0
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-13.0.0.tgz \
--bundle "camunda-platform-13.0.0-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-13.0.0-cosign-verify.sh file.
camunda-platform-8.7-12.6.2
The changelog is automatically generated and it follows Conventional Commits format.
camunda-platform-12.6.2 (2025-10-10)
Refactor
- Upgrade keycloak image from 26.3.1 to 26.3.3 (#4386)
Fixes
- 2 issues.. the configmap for optimize was using the elasticsearch prefix value for opensearch and the QA scenarios where reusing the global prefix to shared OS failed CI (#4238)
- This PR is enabling Entra for testing (#4294)
- Correct sysctlImage structure in values-enterprise.yaml (#4339)
- Revert renovate bot version bump (#4376)
- Web modeler extraConfiguration uses subcomponent subkey (#4097)
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/connectors-bundle:8.7.10
- docker.io/camunda/console:8.7.89
- docker.io/camunda/identity:8.7.7
- docker.io/camunda/keycloak:26.3.3
- docker.io/camunda/operate:8.7.15
- docker.io/camunda/optimize:8.7.11
- docker.io/camunda/tasklist:8.7.15
- docker.io/camunda/web-modeler-restapi:8.7.10
- docker.io/camunda/web-modeler-webapp:8.7.10
- docker.io/camunda/web-modeler-websockets:8.7.10
- docker.io/camunda/zeebe:8.7.15
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.17.4
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-12.6.2.tgz \
--bundle "camunda-platform-12.6.2-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-12.6.2-cosign-verify.sh file.
camunda-platform-8.6-11.10.1
The changelog is automatically generated and it follows Conventional Commits format.
camunda-platform-11.10.1 (2025-10-10)
Fixes
- Correct sysctlImage structure in values-enterprise.yaml (#4339)
- Web modeler extraConfiguration uses subcomponent subkey (#4097)
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/connectors-bundle:8.6.20
- docker.io/camunda/console:8.6.89
- docker.io/camunda/identity:8.6.20
- docker.io/camunda/keycloak:25.0.6
- docker.io/camunda/operate:8.6.29
- docker.io/camunda/optimize:8.6.18
- docker.io/camunda/tasklist:8.6.29
- docker.io/camunda/web-modeler-restapi:8.6.19
- docker.io/camunda/web-modeler-webapp:8.6.19
- docker.io/camunda/web-modeler-websockets:8.6.19
- docker.io/camunda/zeebe:8.6.29
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.15.4
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-11.10.1.tgz \
--bundle "camunda-platform-11.10.1-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-11.10.1-cosign-verify.sh file.
camunda-platform-8.5-10.11.3
The changelog is automatically generated and it follows Conventional Commits format.
camunda-platform-10.11.3 (2025-10-07)
Fixes
- Correct sysctlImage structure in values-enterprise.yaml (#4339)
- Web modeler extraConfiguration uses subcomponent subkey (#4097)
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/connectors-bundle:8.5.22
- docker.io/camunda/identity:8.5.22
- docker.io/camunda/operate:8.5.22
- docker.io/camunda/optimize:8.5.20
- docker.io/camunda/tasklist:8.5.24
- docker.io/camunda/zeebe:8.5.25
- registry.camunda.cloud/console/console-sm:8.5.119
- registry.camunda.cloud/web-modeler-ee/modeler-restapi:8.5.23
- registry.camunda.cloud/web-modeler-ee/modeler-webapp:8.5.23
- registry.camunda.cloud/web-modeler-ee/modeler-websockets:8.5.23
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.12.2
- docker.io/bitnamilegacy/keycloak:23.0.7
- docker.io/bitnamilegacy/os-shell:12-debian-12-r18
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-10.11.3.tgz \
--bundle "camunda-platform-10.11.3-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-10.11.3-cosign-verify.sh file.
camunda-platform-8.5-10.11.2
The changelog is automatically generated and it follows Conventional Commits format.
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/connectors-bundle:8.5.21
- docker.io/camunda/identity:8.5.21
- docker.io/camunda/operate:8.5.21
- docker.io/camunda/optimize:8.5.19
- docker.io/camunda/tasklist:8.5.23
- docker.io/camunda/zeebe:8.5.24
- registry.camunda.cloud/console/console-sm:8.5.119
- registry.camunda.cloud/web-modeler-ee/modeler-restapi:8.5.22
- registry.camunda.cloud/web-modeler-ee/modeler-webapp:8.5.22
- registry.camunda.cloud/web-modeler-ee/modeler-websockets:8.5.22
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.12.2
- docker.io/bitnamilegacy/keycloak:23.0.7
- docker.io/bitnamilegacy/os-shell:12-debian-12-r18
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-10.11.2.tgz \
--bundle "camunda-platform-10.11.2-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-10.11.2-cosign-verify.sh file.
camunda-platform-8.7-12.6.1
The changelog is automatically generated and it follows Conventional Commits format.
Release Info
Supported versions:
Camunda images:
- docker.io/camunda/connectors-bundle:8.7.8
- docker.io/camunda/console:8.7.72
- docker.io/camunda/identity:8.7.6
- docker.io/camunda/keycloak:26.3.2
- docker.io/camunda/operate:8.7.13
- docker.io/camunda/optimize:8.7.9
- docker.io/camunda/tasklist:8.7.13
- docker.io/camunda/web-modeler-restapi:8.7.9
- docker.io/camunda/web-modeler-webapp:8.7.9
- docker.io/camunda/web-modeler-websockets:8.7.9
- docker.io/camunda/zeebe:8.7.13
Non-Camunda images:
- docker.io/bitnamilegacy/elasticsearch:8.17.4
- docker.io/bitnamilegacy/os-shell:12-debian-12-r43
- docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
- docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2
Verification
For quick verification of the Helm chart integrity using Cosign:
cosign verify-blob camunda-platform-12.6.1.tgz \
--bundle "camunda-platform-12.6.1-cosign-bundle.json" \
--certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"For detailed verification instructions, check the steps in the camunda-platform-12.6.1-cosign-verify.sh file.