// OSSeva Blog
OperationsApache Druid Support Options: Releases, ZooKeeper and Upgrades
The short answer
Apache Druid support comes in three forms: the open-source community, commercial Druid distributions, and third-party extended support for the version you already run. The community publishes no support windows. The downloads page offers only the latest release, 37.0.0 (8 May 2026), and the previous major release, 36.0.0 (9 February 2026). Anything older is in the archive, and Druid releases a new major version every few months.
Druid also still runs on Apache ZooKeeper by default. Druid 25.0.0 bundles ZooKeeper 3.5.9, a line that reached end of life in June 2022. A supported Druid cluster needs a supported ZooKeeper under it.
What is Apache Druid?
The Druid docs describe Apache Druid as a real-time analytics database designed for fast slice-and-dice (OLAP) queries on large data sets. It uses column-oriented storage, handles real-time ingestion from streams such as Kafka and Kinesis alongside batch loads, and answers queries in Druid SQL or native JSON queries. Common uses are clickstream, network and application metrics, and the back end of user-facing dashboards.
Is Druid a data warehouse? Its architecture borrows from data warehouses, timeseries databases and log search systems, but it is built for low-latency, high-concurrency queries on event data. Druid SQL supports a join, yet wide joins across many large tables are not what it is designed for, so it usually sits beside a warehouse rather than replacing one.
Druid architecture in brief
- Coordinator and Overlord manage data availability and ingestion tasks.
- Broker and Router handle and route queries from users and applications.
- Historical services store queryable segments, and Middle Manager, Peon or Indexer services run ingestion.
- External dependencies: deep storage (S3, HDFS or a shared file system), a metadata store (MySQL or PostgreSQL in production; Derby for a single server), and ZooKeeper.
Release cadence and version numbers
Druid jumped from 0.23.0 straight to 24.0.0, and each release since has been a new major version. The versioning page follows semantic versioning, so moving between majors can include incompatible changes. The upgrade notes list them release by release, and several matter for anyone running an older Druid cluster:
| Release | Upgrade note |
|---|---|
| 0.22.0 | ZooKeeper 3.4 support removed. Upgrade the ensemble before Druid. |
| 24.0.0 | Firehose ingestion removed. |
| 25.0.0 | HTTP becomes the default for segment discovery and task management: druid.serverview.type=http, druid.coordinator.loadqueuepeon.type=http, druid.indexer.runner.type=httpRemote. |
| 30.0.0 | ZooKeeper-based segment loading removed. |
| 32.0.0 | Legacy non-ANSI SQL settings removed; Java 8 support removed; Hadoop-based ingestion deprecated. |
| 35.0.0 | Java 11 support removed (use 17 or 21); Jetty 12. |
The 32.0.0 change deserves care: if a legacy null-handling setting is still present, Druid services fail to start, and any query that relied on the old behaviour returns different results. Read each note before every update, not only the latest one.
ZooKeeper is still the default
Druid moved segment loading and task management to HTTP, but it still uses ZooKeeper for service discovery, Coordinator and Overlord leader election, and cluster state. The only way to run without it is the Kubernetes extension, which the docs mark as experimental. Bundled ZooKeeper versions:
| Druid release | Bundled ZooKeeper |
|---|---|
| 0.22.1 | 3.5.9 |
| 25.0.0 | 3.5.9 |
| 37.0.0 | 3.8.6 |
ZooKeeper 3.5 has no fix for CVE-2023-44981, and even 3.8.6 predates the September 2026 fixes in 3.8.7 (see the ZooKeeper CVE list by version). The Druid and ZooKeeper page has the detail. To check a node:
ls lib/ | grep -E '^zookeeper-[0-9]'
grep -E '^druid.zk.service.host' conf/druid/cluster/_common/common.runtime.properties
echo srvr | nc zk1.internal 2181 | head -1
Hortonworks also shipped Druid: HDP 2.6.5 includes Druid 0.10.1, and HDP 3.1 includes 0.12.1, both on ZooKeeper 3.4.6.
Apache Druid support options
- Community. The Druid documentation, mailing lists and GitHub issues. Good for questions on current releases; no fixes for old ones.
- Commercial distributions. Vendors package Druid with their own tooling and managed cloud services. This usually means adopting their build and upgrade schedule.
- Extended support for your version. Keep the Druid database you run, patched, while the upgrade across several majors is planned.
OSSeva's Apache Druid support ships patched, signed builds for older Druid releases today, together with patched ZooKeeper 3.5 to 3.7 builds for the ensemble beneath them. Patch covers the security backports, Assure adds a dependency map and CVE attestation for auditors, and Operate adds 24/7 monitoring and incident response with a named engineer. Start with Patch, or book a discovery call to plan the upgrade path.
Frequently asked questions
Which Apache Druid versions are supported?
The project publishes no end-of-life dates. The downloads page lists 37.0.0 as the latest stable release and 36.0.0 as the previous major; older releases are archived.
Does Druid support SQL?
Yes. Druid SQL is translated into native queries, and a JDBC driver is available for SQL clients.
Which metadata stores does Druid support?
Derby, MySQL and PostgreSQL. The docs recommend MySQL or PostgreSQL for production; Oracle is not on the list.
Can Druid run without ZooKeeper?
Only through the experimental Kubernetes extension. ZooKeeper remains the default in every release, including 37.0.0.
Tags
Related articles
ZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9
September 29, 2026MigrationZooKeeper Alternatives: ZooKeeper vs etcd, Consul, KRaft and ClickHouse Keeper
September 29, 2026ComplianceWhy Your Scanner Flags the ZooKeeper Inside a Product You Bought, and How VEX Attestation Answers It
September 29, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.