Back to blog

// OSSeva Blog

Operations

Who Provides Apache Kafka Support for 2.x and 3.x, Including ZooKeeper Mode?

Randall McClure10 min read

The short answer

For Kafka 3.8 and 3.9, the last lines that can run on ZooKeeper, the longest published dates come from Perforce OpenLogic, whose long-term support covers 3.8 to 30 November 2028 and 3.9 to 31 March 2029, and Confluent, whose Platform 7.8 and 7.9 run on Kafka 3.8 and 3.9 with Platinum support to December 2027 and February 2028. OSSeva publishes patched builds of community Kafka 2.8, 3.0, 3.3, 3.6, 3.7, 3.8 and 3.9, in ZooKeeper or KRaft mode. Amazon MSK, Aiven and Instaclustr still run 3.9 as managed services, and Red Hat supports its own Kafka 3.9 based Streams 2.9 until 31 October 2026.

For Kafka 2.x through 3.7, most of those doors have closed. Confluent Platform 7.7 left standard support in July 2026, MSK ended 3.7 on 1 September 2026, and Instaclustr lists 3.8 and below as retired. Patched builds from OSSeva, or an upgrade, are what remain.

Which Kafka versions Apache still supports

Kafka's download page lists three supported releases and archives everything else. The project's policy is to make bugfix releases as needed for the last three releases only.

LineStatus on 6 October 2026Latest releaseZooKeeper mode?
4.3, 4.2, 4.1Supported4.3.1 (25 June 2026), 4.2.2 (29 September 2026), 4.1.2 (17 March 2026)No, KRaft only
4.0Archived4.0.2 (16 March 2026)No, KRaft only
3.9Archived3.9.2 (21 February 2026)Yes, the last line that supports it
3.8Archived3.8.1 (29 October 2024)Yes
3.7 and earlier, including 2.8ArchivedNo further releasesYes

So no ZooKeeper-mode Kafka is supported upstream any more. Kafka's upgrade notes say ZooKeeper-mode clusters have to migrate to KRaft before they can upgrade to 4.0, which is why so many estates are sitting on 3.8 and 3.9. The Kafka end-of-life chart tracks every line, Kafka on ZooKeeper after 2026 collects every vendor date, and Kafka vulnerabilities by version lists what reaches each one.

Apache Kafka support providers compared

Each row reflects what the provider publishes on its own site as of 6 October 2026.

ProviderWhat it coversKafka 3.x coverageDelivery modelSelf-managed?
Confluent PlatformConfluent's Kafka distribution with its own components; standard support is two years per release, and Platinum adds a year7.9 (Kafka 3.9): standard to 19 February 2027, Platinum to 19 February 2028. 7.8 (3.8): 2 December 2026 and 2 December 2027. 7.7 (3.7): standard ended 26 July 2026Confluent subscriptionYes, on Confluent Platform
Red Hat streams for Apache KafkaRed Hat's Kafka distribution for RHEL and OpenShift; 2.9 is its long-term support release2.9, based on Kafka 3.9 with KRaft or ZooKeeper: maintenance ends 31 October 2026. Later 3.x releases move to Kafka 4Red Hat subscriptionYes, on Red Hat's distribution
Perforce OpenLogicLong-term support with patched builds after community end of life, plus technical support for Kafka and ZooKeeper3.8 to 30 November 2028 and 3.9 to 31 March 2029LTS subscriptionYes
Amazon MSKManaged Kafka; clusters past their end-of-support date can be upgraded automatically at any time, without notice3.6 ended 1 June 2026 and 3.7 on 1 September 2026; 3.8 and 3.9 have no end date yet, and 3.9 has extended support for at least two years from April 2025AWS managed serviceNo
Aiven for Apache KafkaManaged Kafka; services are upgraded automatically at end of life3.8 ended 30 September 2026; 3.9 to 30 September 2027Managed serviceNo
Instaclustr (NetApp)Managed Kafka, plus support from the same Kafka team for on-premises clusters3.9.2 generally available but deprecated from October 2026; 3.8 and below retiredManaged platform or support subscriptionYes, on supported versions
OSSevaBackported CVE fixes for brokers and client libraries, with Connect and Streams on higher tiers; ZooKeeper ensemble patching; Confluent exit design on Assure; 24/7 operations on Operate2.8, 3.0, 3.3, 3.6, 3.7, 3.8 and 3.9, ZooKeeper or KRaft modeSigned artifacts from OSSeva's registry and Helm chartsYes

Read the Confluent and Red Hat rows carefully. Both support their own distributions, so a cluster built from Apache's binaries is covered only after it moves onto theirs. The cloud rows are a route onto supported versions, not a way to stay on an old one.

How the providers differ

Confluent

Confluent is the natural choice if you already run Confluent Platform or depend on the components it adds to Kafka. Its 7.8 and 7.9 releases are the last that ship ZooKeeper, and Confluent Platform 8.0 removed it. With Platinum support, 7.9 is covered to 19 February 2028, the longest vendor date for a ZooKeeper-mode distribution. Confluent Platform 7.x end of support covers what ends on each date, and Confluent alternatives covers the other routes.

Red Hat

Red Hat's streams for Apache Kafka 2.9 is a long-term support release based on Kafka 3.9, with ZooKeeper or KRaft. Its maintenance phase ends on 31 October 2026, and Red Hat's 3.x releases, built on Kafka 4, are KRaft only. For estates already on RHEL or OpenShift subscriptions, Red Hat is the obvious vendor, as long as you can follow its release stream.

Perforce OpenLogic

OpenLogic is the one broad vendor with Kafka on its long-term support list. It publishes patches within 14 days of disclosure for critical CVEs and within 30 days for high ones, and its 3.9 date runs to 31 March 2029. It covers 3.8 and 3.9 only, so older clusters need an upgrade first. See OSSeva vs OpenLogic.

Amazon MSK, Aiven and Instaclustr

The managed services keep you current by upgrading for you. MSK recommends 3.9 and has said it will support it for at least two years from its April 2025 release on the service, but a cluster past its end-of-support date can be upgraded automatically at any time without notice. Aiven upgrades services at end of life, with monthly and then weekly reminders, and keeps 3.9 to 30 September 2027. Instaclustr still lists 3.9.2 as generally available but deprecated, and it supports self-managed clusters on the versions its lifecycle lists. Amazon MSK Kafka version end of support covers MSK in detail, and OSSeva vs Instaclustr covers the overlap there.

OSSeva

OSSeva for Apache Kafka patches community Kafka on the line you run, in ZooKeeper or KRaft mode, so a 2.8 or 3.x cluster is not forced through a KRaft migration and a major upgrade by a security deadline. Patch covers the broker and client libraries with quarterly fixes and signed artifacts. Assure adds Kafka Connect and Streams patches, a cluster configuration audit, a throughput and latency review, a compliance attestation package and migration design from Confluent Platform. Operate adds 24/7 broker and consumer-lag monitoring, a 15-minute P1 response, capacity planning and Connect and Streams operations, and patches Critical CVEs (CVSS 9.0 and above) within 48 hours and High within 7 days. The ZooKeeper ensemble under a ZooKeeper-mode cluster is covered under the same engagement. Pricing is per cluster, not per broker, partition or throughput tier.

How to choose

SituationUsual answer
Already on KRaft and able to upgrade a few times a yearCommunity Kafka 4.x, or a managed service
On Confluent Platform 7.8 or 7.9 and using its own componentsConfluent, with Platinum if the KRaft move runs into 2027
On Red Hat's streams for Apache Kafka 2.9Plan the move to Red Hat 3.x before 31 October 2026, or bridge with patched 3.9 builds
Apache Kafka 3.8 or 3.9 on ZooKeeper, one vendor for many technologiesOpenLogic LTS or OSSeva
Apache Kafka 2.8 to 3.7, self-managedOSSeva patched builds while the cluster moves to 3.9 and KRaft
Happy to hand Kafka to a cloud providerAmazon MSK, Aiven or Instaclustr, on their upgrade schedules

The ZooKeeper to KRaft migration guide covers the move itself, and Kafka on ZooKeeper as a bridge to KRaft covers running extended support while it happens.

Where OSSeva fits

OSSeva covers community Kafka from 2.8 through 3.9 and the ZooKeeper beneath it, which suits estates that run Apache's own binaries and cannot finish the KRaft migration before their vendor dates. Kafka on ZooKeeper extended support covers that case, ZooKeeper support providers compares who covers the ensemble, and Exit Confluent covers moving back to Apache Kafka.

Frequently asked questions

Best kafka support providers

For Confluent Platform, Confluent. For Red Hat's distribution, Red Hat. For managed Kafka, Amazon MSK, Aiven or Instaclustr. For long-term support of Apache Kafka 3.8 and 3.9 with one broad vendor, OpenLogic. For patched builds of Apache Kafka 2.8 to 3.9, including ZooKeeper-mode clusters, OSSeva.

Which companies offer Apache Kafka support besides the original vendor?

Red Hat, Perforce OpenLogic, Instaclustr, Aiven, Amazon MSK and OSSeva all support Apache Kafka in some form. Red Hat supports its own distribution, OpenLogic and OSSeva support Apache's, and the cloud providers run it for you.

What are the best Confluent Platform alternatives for self-managed Kafka?

Apache Kafka itself, supported by OpenLogic, Instaclustr or OSSeva, or Red Hat's streams for Apache Kafka on RHEL and OpenShift. Check which Confluent-only components you use first, since those are what a move has to replace.

Confluent Platform 7.x is reaching end of support. Who can support our ZooKeeper-based clusters?

Confluent itself, through Platinum support to 2 December 2027 for 7.8 and 19 February 2028 for 7.9. If you move to Apache Kafka on the same version, OpenLogic's LTS covers 3.8 and 3.9, and OSSeva patches 3.8 and 3.9 along with the ZooKeeper ensemble.

Is there commercial support for Apache Kafka 3.9 after end of life?

Yes. OpenLogic's LTS covers 3.9 to 31 March 2029, Confluent Platform 7.9 is supported to February 2028 with Platinum, Aiven runs 3.9 to 30 September 2027, and OSSeva ships patched 3.9 builds. Amazon MSK has not published an end date for 3.9.

Who provides CVE patches for Apache Kafka 3.9?

Apache's last 3.9 release was 3.9.2 in February 2026. After that, fixes come from OpenLogic LTS and OSSeva for Apache binaries, and from Confluent and Red Hat for their own distributions.

Who offers Apache Kafka extended lifecycle support?

OpenLogic, for 3.8 and 3.9, and OSSeva, for 2.8 through 3.9. Confluent's Platinum tier extends its own Platform releases by a year.

Amazon MSK Kafka 3.6 and 3.7 end of support: what are my options?

Upgrade in place to 3.9, MSK's recommended version, before MSK upgrades the cluster for you. Then plan the KRaft migration, since 4.x drops ZooKeeper. If you would rather leave MSK and run Kafka yourself, OSSeva can patch the version you land on.

Tags

Apache KafkaZooKeeperEnd of LifeExtended SupportVendor Comparison

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.