Back to blog

// OSSeva Blog

Operations

Apache Druid Support Options: Releases, ZooKeeper and Upgrades

Randall McClure7 min read

The short answer

Apache Druid support comes in three forms: the open-source community, commercial Druid distributions, and third-party extended support for the version you already run. The community publishes no support windows. The downloads page offers only the latest release, 37.0.0 (8 May 2026), and the previous major release, 36.0.0 (9 February 2026). Anything older is in the archive, and Druid releases a new major version every few months.

Druid also still runs on Apache ZooKeeper by default. Druid 25.0.0 bundles ZooKeeper 3.5.9, a line that reached end of life in June 2022. A supported Druid cluster needs a supported ZooKeeper under it.

What is Apache Druid?

The Druid docs describe Apache Druid as a real-time analytics database designed for fast slice-and-dice (OLAP) queries on large data sets. It uses column-oriented storage, handles real-time ingestion from streams such as Kafka and Kinesis alongside batch loads, and answers queries in Druid SQL or native JSON queries. Common uses are clickstream, network and application metrics, and the back end of user-facing dashboards.

Is Druid a data warehouse? Its architecture borrows from data warehouses, timeseries databases and log search systems, but it is built for low-latency, high-concurrency queries on event data. Druid SQL supports a join, yet wide joins across many large tables are not what it is designed for, so it usually sits beside a warehouse rather than replacing one.

Druid architecture in brief

  • Coordinator and Overlord manage data availability and ingestion tasks.
  • Broker and Router handle and route queries from users and applications.
  • Historical services store queryable segments, and Middle Manager, Peon or Indexer services run ingestion.
  • External dependencies: deep storage (S3, HDFS or a shared file system), a metadata store (MySQL or PostgreSQL in production; Derby for a single server), and ZooKeeper.

Release cadence and version numbers

Druid jumped from 0.23.0 straight to 24.0.0, and each release since has been a new major version. The versioning page follows semantic versioning, so moving between majors can include incompatible changes. The upgrade notes list them release by release, and several matter for anyone running an older Druid cluster:

ReleaseUpgrade note
0.22.0ZooKeeper 3.4 support removed. Upgrade the ensemble before Druid.
24.0.0Firehose ingestion removed.
25.0.0HTTP becomes the default for segment discovery and task management: druid.serverview.type=http, druid.coordinator.loadqueuepeon.type=http, druid.indexer.runner.type=httpRemote.
30.0.0ZooKeeper-based segment loading removed.
32.0.0Legacy non-ANSI SQL settings removed; Java 8 support removed; Hadoop-based ingestion deprecated.
35.0.0Java 11 support removed (use 17 or 21); Jetty 12.

The 32.0.0 change deserves care: if a legacy null-handling setting is still present, Druid services fail to start, and any query that relied on the old behaviour returns different results. Read each note before every update, not only the latest one.

ZooKeeper is still the default

Druid moved segment loading and task management to HTTP, but it still uses ZooKeeper for service discovery, Coordinator and Overlord leader election, and cluster state. The only way to run without it is the Kubernetes extension, which the docs mark as experimental. Bundled ZooKeeper versions:

Druid releaseBundled ZooKeeper
0.22.13.5.9
25.0.03.5.9
37.0.03.8.6

ZooKeeper 3.5 has no fix for CVE-2023-44981, and even 3.8.6 predates the September 2026 fixes in 3.8.7 (see the ZooKeeper CVE list by version). The Druid and ZooKeeper page has the detail. To check a node:

ls lib/ | grep -E '^zookeeper-[0-9]'
grep -E '^druid.zk.service.host' conf/druid/cluster/_common/common.runtime.properties
echo srvr | nc zk1.internal 2181 | head -1

Hortonworks also shipped Druid: HDP 2.6.5 includes Druid 0.10.1, and HDP 3.1 includes 0.12.1, both on ZooKeeper 3.4.6.

Apache Druid support options

  1. Community. The Druid documentation, mailing lists and GitHub issues. Good for questions on current releases; no fixes for old ones.
  2. Commercial distributions. Vendors package Druid with their own tooling and managed cloud services. This usually means adopting their build and upgrade schedule.
  3. Extended support for your version. Keep the Druid database you run, patched, while the upgrade across several majors is planned.

OSSeva's Apache Druid support ships patched, signed builds for older Druid releases today, together with patched ZooKeeper 3.5 to 3.7 builds for the ensemble beneath them. Patch covers the security backports, Assure adds a dependency map and CVE attestation for auditors, and Operate adds 24/7 monitoring and incident response with a named engineer. Start with Patch, or book a discovery call to plan the upgrade path.

Frequently asked questions

Which Apache Druid versions are supported?

The project publishes no end-of-life dates. The downloads page lists 37.0.0 as the latest stable release and 36.0.0 as the previous major; older releases are archived.

Does Druid support SQL?

Yes. Druid SQL is translated into native queries, and a JDBC driver is available for SQL clients.

Which metadata stores does Druid support?

Derby, MySQL and PostgreSQL. The docs recommend MySQL or PostgreSQL for production; Oracle is not on the list.

Can Druid run without ZooKeeper?

Only through the experimental Kubernetes extension. ZooKeeper remains the default in every release, including 37.0.0.

Tags

Apache DruidZooKeeperUpgradeReal-time analytics

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.