Skip to content

Releases: camunda/camunda-platform-helm

camunda-platform-8.8-13.1.1

30 Oct 11:01
96fd240

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

Release Info

Supported versions:

  • Camunda applications: 8.8
  • Camunda version matrix: 8.8
  • Helm values: 13.1.1
  • Helm CLI: 3.19.0

Camunda images:

  • docker.io/camunda/camunda:8.8.2
  • docker.io/camunda/connectors-bundle:8.8.1
  • docker.io/camunda/console:8.8.17
  • docker.io/camunda/identity:8.8.0
  • docker.io/camunda/keycloak:26.3.3
  • docker.io/camunda/optimize:8.8.0
  • docker.io/camunda/web-modeler-restapi:8.8.1
  • docker.io/camunda/web-modeler-webapp:8.8.1
  • docker.io/camunda/web-modeler-websockets:8.8.1

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.18.0
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-13.1.1.tgz \
  --bundle "camunda-platform-13.1.1-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-13.1.1-cosign-verify.sh file.

camunda-platform-8.8-13.1.0

27 Oct 12:20
22c392f

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

camunda-platform-13.1.0 (2025-10-27)

Features

  • Data injection during testing (#4423)

Fixes

  • Consistent naming for migrations and importer (#4477)
  • Changing pod anti-affinity rules for migration jobs and importer (#4481)
  • Allows cpu to be set as either string or number (#4491)
  • Delete the migrator from 8.9 (#4503)
  • The oidc scenario was always running the upgrade. Removing here … (#4523)
  • Use joinPath helper to fix double slash issues in console configmap (#4562)
  • Apply dual-region exclusion logic to opensearch exporter as well (#4352)
  • Add back mapping rules in the orchestration cluster (#4545)

Revert

  • Update camunda-platform-8.8 major (#4461)
  • Install-tool-action part of feat - data injection during testing (#4467)

Release Info

Supported versions:

  • Camunda applications: 8.8
  • Camunda version matrix: 8.8
  • Helm values: 13.1.0
  • Helm CLI: 3.19.0

Camunda images:

  • docker.io/camunda/camunda:8.8.1
  • docker.io/camunda/connectors-bundle:8.8.1
  • docker.io/camunda/console:8.8.17
  • docker.io/camunda/identity:8.8.0
  • docker.io/camunda/keycloak:26.3.3
  • docker.io/camunda/optimize:8.8.0
  • docker.io/camunda/web-modeler-restapi:8.8.1
  • docker.io/camunda/web-modeler-webapp:8.8.1
  • docker.io/camunda/web-modeler-websockets:8.8.1

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.18.0
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-13.1.0.tgz \
  --bundle "camunda-platform-13.1.0-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-13.1.0-cosign-verify.sh file.

camunda-platform-8.7-12.6.3

21 Oct 12:53
6e7aecb

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

camunda-platform-12.6.3 (2025-10-21)

Fixes

  • Fix link to upgrade instructions (#4450)

Release Info

Supported versions:

  • Camunda applications: 8.7
  • Camunda version matrix: 8.7
  • Helm values: 12.6.3
  • Helm CLI: 3.18.6

Camunda images:

  • docker.io/camunda/connectors-bundle:8.7.10
  • docker.io/camunda/console:8.7.90
  • docker.io/camunda/identity:8.7.7
  • docker.io/camunda/keycloak:26.3.3
  • docker.io/camunda/operate:8.7.15
  • docker.io/camunda/optimize:8.7.11
  • docker.io/camunda/tasklist:8.7.15
  • docker.io/camunda/web-modeler-restapi:8.7.11
  • docker.io/camunda/web-modeler-webapp:8.7.11
  • docker.io/camunda/web-modeler-websockets:8.7.11
  • docker.io/camunda/zeebe:8.7.15

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.17.4
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-12.6.3.tgz \
  --bundle "camunda-platform-12.6.3-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-12.6.3-cosign-verify.sh file.

camunda-platform-8.6-11.10.2

21 Oct 11:16
4a70306

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

camunda-platform-11.10.2 (2025-10-21)

Fixes

  • Fix link to upgrade instructions (#4450)

Release Info

Supported versions:

Camunda images:

  • docker.io/camunda/connectors-bundle:8.6.20
  • docker.io/camunda/console:8.6.90
  • docker.io/camunda/identity:8.6.20
  • docker.io/camunda/keycloak:25.0.6
  • docker.io/camunda/operate:8.6.29
  • docker.io/camunda/optimize:8.6.18
  • docker.io/camunda/tasklist:8.6.29
  • docker.io/camunda/web-modeler-restapi:8.6.20
  • docker.io/camunda/web-modeler-webapp:8.6.20
  • docker.io/camunda/web-modeler-websockets:8.6.20
  • docker.io/camunda/zeebe:8.6.29

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.15.4
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-11.10.2.tgz \
  --bundle "camunda-platform-11.10.2-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-11.10.2-cosign-verify.sh file.

camunda-platform-8.8-13.0.0

13 Oct 17:31
cba4954

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

camunda-platform-13.0.0 (2025-10-13)

Refactor

  • Upgrade keycloak image from 26.3.1 to 26.3.3 (#4386)
  • Streamline OIDC and Microsoft Entra auth (#4416)
  • Rename zeebe/orchestration labels (#4430)

Fixes

  • No default backwardsCompatibleAudiences (#4421)
  • Remove duplicate servicemonitor (#4428)
  • Release-please should create a non-alpha release for 8.8.0 (#4439)
  • Correct 13.0.0 version number
  • Undo part of the release notes thats wrong version
  • Fix doc links for 8.8 (#4453)

camunda-platform-8.5-10.11.3 (2025-10-08)

Features

  • Support legacy retention age (#4179)
  • Support issuer backend url in the orchestration config (#4265)

Refactor

  • Differentiate between orchestration services (#4190)
  • Move orchestration oidc from global to component (#4233)
  • Move connectors oidc from global to component (#4234)
  • Support auth values in components (#4279)
  • Use the main config in migrations (#4235)
  • Use postgresql 14 for web modeler (#4287)
  • Use postgres 14 for web modeler (#4327)
  • Add nodeSelector, affinity, and tolerations to orchestration extra resources (#4366)

Fixes

  • NoSecondaryStorage constraint no longer breaks unit tests (#4223)
  • Wrong openshift compatibilty helper elasticsearch commonLabels usage (#4180)
  • Operate opensearch access in the unified config (#4224)
  • 2 issues.. the configmap for optimize was using the elasticsearch prefix value for opensearch and the QA scenarios where reusing the global prefix to shared OS failed CI (#4238)
  • Add the oidc group claim to opensearch (#4244)
  • Simplify oidc mappings in 8.8 (#4229)
  • Firstuser defaults should not fire constraint (#4227)
  • Partition-count typo in 8.8 chart (#4245)
  • Identity migration inital contactPoint port number (#4260)
  • Revert orchestration service name for backward compatibility (#4264)
  • Comment in values.yaml for enabling management identity auth (#4273)
  • Comment for identity existing secret (#4275)
  • Add conditional properties for management components in manageme… (#4276)
  • Revert tls secret placeholders (#4239)
  • Add missing opensearch fields in templates (#4280)
  • Reintroduce capability to disable all exporters again (#4272)
  • Add security config to webmodeler (#4285)
  • Data migration and importer config (#4286)
  • Opensearch config and index replica placement (#4297)
  • Use correct upgrade strategy for importer deployment (#4310)
  • Data and identity migraiton accept orchestration env (#4291)
  • Es/os exporter inherit index replicas (#4309)
  • Clean up redundant secret templates (#4328)
  • This PR is enabling Entra for testing (#4294)
  • Correctly configure data migration (#4343)
  • Define importer node id based on regionId (#4349)
  • Adjust autogenerated secret detection patterns (#4342)
  • Fix configurations of identity migration (#4344)
  • Remove importer affinity in 8.8 (#4357)
  • Unique importer ids for swim (#4360)
  • Add audiences for backward compatibility (#4351)
  • Correct sysctlImage structure in values-enterprise.yaml (#4339)
  • Web modeler extraConfiguration uses subcomponent subkey (#4097)
  • Should be using 8.8 instead of 8.9 connectors (#4267)
  • Couple importer deployment with migration (#4346)
  • In optimize cm, set the zeebe name to be equal to prefix (#4382)
  • Set correct value for identity migration configmap (#4387)
  • Set client secret based on what it's bound to on identity-side (#4400)
  • Update QA 8.8 opensearch values file (#4405)

Revert

  • "refactor: set default value for contextPath in all component… (#4221)

camunda-platform-8.5-10.11.2 (2025-09-18)

Features

  • Opensearch aws enabled config now affects usage of AWS credentials (#4163)
  • Add the document store scenario to the qa scenario list (#4117)
  • Introduce authenticationRefreshInterval config parameter (#3958)
  • Add resource authorizations flag to identity migration (#4197)
  • Add default roles for initial users (#4194)
  • Add extra mapping for initial client for identity OIDC migration (#4202)

Refactor

  • Set default replicas to 1 for secondary storage (#4150)
  • Run orchestration cluster from unified config (#4138)

Fixes

  • Update migration job labels so requests are not routed to them (#4143)
  • Enable exporters when data migration is enabled (#4196)
  • Add constraints for ES and Basic auth in noSecondaryStorage mode (#4170)
  • Adjust secret constraint to reflect new secrets management (#4182)
  • Add missing global.identity.auth.identity.secret configuration (#4222)

Release Info

Supported versions:

  • Camunda applications: 8.8
  • Camunda version matrix: 8.8
  • Helm values: 13.0.0
  • Helm CLI: 3.18.6

Camunda images:

  • docker.io/camunda/camunda:8.8.0
  • docker.io/camunda/connectors-bundle:8.8.0
  • docker.io/camunda/console:8.8.3
  • docker.io/camunda/identity:8.8.0
  • docker.io/camunda/keycloak:26.3.3
  • docker.io/camunda/optimize:8.8.0
  • docker.io/camunda/web-modeler-restapi:8.8.0
  • docker.io/camunda/web-modeler-webapp:8.8.0
  • docker.io/camunda/web-modeler-websockets:8.8.0

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.18.0
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-13.0.0.tgz \
  --bundle "camunda-platform-13.0.0-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-13.0.0-cosign-verify.sh file.

camunda-platform-8.7-12.6.2

10 Oct 13:42
157b9fd

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

camunda-platform-12.6.2 (2025-10-10)

Refactor

  • Upgrade keycloak image from 26.3.1 to 26.3.3 (#4386)

Fixes

  • 2 issues.. the configmap for optimize was using the elasticsearch prefix value for opensearch and the QA scenarios where reusing the global prefix to shared OS failed CI (#4238)
  • This PR is enabling Entra for testing (#4294)
  • Correct sysctlImage structure in values-enterprise.yaml (#4339)
  • Revert renovate bot version bump (#4376)
  • Web modeler extraConfiguration uses subcomponent subkey (#4097)

Release Info

Supported versions:

  • Camunda applications: 8.7
  • Camunda version matrix: 8.7
  • Helm values: 12.6.2
  • Helm CLI: 3.18.6

Camunda images:

  • docker.io/camunda/connectors-bundle:8.7.10
  • docker.io/camunda/console:8.7.89
  • docker.io/camunda/identity:8.7.7
  • docker.io/camunda/keycloak:26.3.3
  • docker.io/camunda/operate:8.7.15
  • docker.io/camunda/optimize:8.7.11
  • docker.io/camunda/tasklist:8.7.15
  • docker.io/camunda/web-modeler-restapi:8.7.10
  • docker.io/camunda/web-modeler-webapp:8.7.10
  • docker.io/camunda/web-modeler-websockets:8.7.10
  • docker.io/camunda/zeebe:8.7.15

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.17.4
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-12.6.2.tgz \
  --bundle "camunda-platform-12.6.2-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-12.6.2-cosign-verify.sh file.

camunda-platform-8.6-11.10.1

10 Oct 12:59
7bdeccd

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

camunda-platform-11.10.1 (2025-10-10)

Fixes

  • Correct sysctlImage structure in values-enterprise.yaml (#4339)
  • Web modeler extraConfiguration uses subcomponent subkey (#4097)

Release Info

Supported versions:

Camunda images:

  • docker.io/camunda/connectors-bundle:8.6.20
  • docker.io/camunda/console:8.6.89
  • docker.io/camunda/identity:8.6.20
  • docker.io/camunda/keycloak:25.0.6
  • docker.io/camunda/operate:8.6.29
  • docker.io/camunda/optimize:8.6.18
  • docker.io/camunda/tasklist:8.6.29
  • docker.io/camunda/web-modeler-restapi:8.6.19
  • docker.io/camunda/web-modeler-webapp:8.6.19
  • docker.io/camunda/web-modeler-websockets:8.6.19
  • docker.io/camunda/zeebe:8.6.29

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.15.4
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-11.10.1.tgz \
  --bundle "camunda-platform-11.10.1-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-11.10.1-cosign-verify.sh file.

camunda-platform-8.5-10.11.3

08 Oct 13:20
07206ff

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

camunda-platform-10.11.3 (2025-10-07)

Fixes

  • Correct sysctlImage structure in values-enterprise.yaml (#4339)
  • Web modeler extraConfiguration uses subcomponent subkey (#4097)

Release Info

Supported versions:

Camunda images:

  • docker.io/camunda/connectors-bundle:8.5.22
  • docker.io/camunda/identity:8.5.22
  • docker.io/camunda/operate:8.5.22
  • docker.io/camunda/optimize:8.5.20
  • docker.io/camunda/tasklist:8.5.24
  • docker.io/camunda/zeebe:8.5.25
  • registry.camunda.cloud/console/console-sm:8.5.119
  • registry.camunda.cloud/web-modeler-ee/modeler-restapi:8.5.23
  • registry.camunda.cloud/web-modeler-ee/modeler-webapp:8.5.23
  • registry.camunda.cloud/web-modeler-ee/modeler-websockets:8.5.23

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.12.2
  • docker.io/bitnamilegacy/keycloak:23.0.7
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r18
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-10.11.3.tgz \
  --bundle "camunda-platform-10.11.3-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-10.11.3-cosign-verify.sh file.

camunda-platform-8.5-10.11.2

18 Sep 10:47
280a603

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

Release Info

Supported versions:

Camunda images:

  • docker.io/camunda/connectors-bundle:8.5.21
  • docker.io/camunda/identity:8.5.21
  • docker.io/camunda/operate:8.5.21
  • docker.io/camunda/optimize:8.5.19
  • docker.io/camunda/tasklist:8.5.23
  • docker.io/camunda/zeebe:8.5.24
  • registry.camunda.cloud/console/console-sm:8.5.119
  • registry.camunda.cloud/web-modeler-ee/modeler-restapi:8.5.22
  • registry.camunda.cloud/web-modeler-ee/modeler-webapp:8.5.22
  • registry.camunda.cloud/web-modeler-ee/modeler-websockets:8.5.22

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.12.2
  • docker.io/bitnamilegacy/keycloak:23.0.7
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r18
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-10.11.2.tgz \
  --bundle "camunda-platform-10.11.2-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-10.11.2-cosign-verify.sh file.

camunda-platform-8.7-12.6.1

17 Sep 17:41
71ef4fc

Choose a tag to compare

The changelog is automatically generated and it follows Conventional Commits format.

Release Info

Supported versions:

  • Camunda applications: 8.7
  • Camunda version matrix: 8.7
  • Helm values: 12.6.1
  • Helm CLI: 3.18.6

Camunda images:

  • docker.io/camunda/connectors-bundle:8.7.8
  • docker.io/camunda/console:8.7.72
  • docker.io/camunda/identity:8.7.6
  • docker.io/camunda/keycloak:26.3.2
  • docker.io/camunda/operate:8.7.13
  • docker.io/camunda/optimize:8.7.9
  • docker.io/camunda/tasklist:8.7.13
  • docker.io/camunda/web-modeler-restapi:8.7.9
  • docker.io/camunda/web-modeler-webapp:8.7.9
  • docker.io/camunda/web-modeler-websockets:8.7.9
  • docker.io/camunda/zeebe:8.7.13

Non-Camunda images:

  • docker.io/bitnamilegacy/elasticsearch:8.17.4
  • docker.io/bitnamilegacy/os-shell:12-debian-12-r43
  • docker.io/bitnamilegacy/postgresql:14.18.0-debian-12-r0
  • docker.io/bitnamilegacy/postgresql:15.10.0-debian-12-r2

Verification

For quick verification of the Helm chart integrity using Cosign:

cosign verify-blob camunda-platform-12.6.1.tgz \
  --bundle "camunda-platform-12.6.1-cosign-bundle.json" \
  --certificate-identity-regex "https://github.com/camunda/camunda-platform-helm" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com"

For detailed verification instructions, check the steps in the camunda-platform-12.6.1-cosign-verify.sh file.