// Apache Storm extended support

Storm 2.8.9 was the last 2.x release.
Storm 3 needs Java 25. Your topologies may not be ready.

On 22 July 2026 the Storm project released 3.0.0 and, the same day, 2.8.9 as the final release of the 2.x line. The 2.x branch is no longer maintained. Storm 3 requires Java 25 and removes the Clojure DSL. Every Storm version still requires ZooKeeper, and 2.8.9 bundles ZooKeeper 3.9.5, which predates the fixes released in September 2026. OSSeva ships patched, signed Storm 2.x builds today, patches the ZooKeeper under them, and moves topologies to Storm 3 once the Java work is done.

Storm 2.82.72.62.52.4Nimbus and supervisorsZooKeeper 3.5 to 3.9

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why Storm 2.x clusters are stuck

The Storm API barely changed. The platform under it did.

Java 25 is a platform change

Storm 3.0 requires Java 25. Hosts, container images, JVM flags and every library on the topology classpath have to move with it, which is usually a bigger job than the Storm upgrade itself.

Clojure topologies need porting

Storm 3.0 removed the Clojure DSL. The Java API stays backwards-compatible with 2.x, but topologies written in Clojure have to be ported before they can run on 3.x.

ZooKeeper is still required

Nimbus and the supervisors coordinate through ZooKeeper, and storm.zookeeper.servers is mandatory configuration in 3.1.0 as well. Storm 2.8.9 and 3.1.0 both bundle ZooKeeper 3.9.5, and the five advisories of 16 September 2026 were fixed in 3.9.6. Storm 2.4.0 bundles 3.5.9, from a line that reached end of life in June 2022.

The dates that matter

  1. 2022-06-01

    ZooKeeper 3.5 end of life. Storm 2.4.0 bundles 3.5.9.

  2. 2026-07-22

    Storm 3.0.0 released with a Java 25 requirement. Storm 2.8.9 released the same day as the final 2.x release.

  3. 2026-09-12

    Storm 3.1.0 released. A ZooKeeper cluster is still step one of cluster setup.

  4. 2026-09-16

    Five ZooKeeper advisories fixed in 3.9.6 and 3.8.7. Storm 2.8.9 and 3.1.0 bundle 3.9.5.

What OSSeva delivers

1

Patched Storm 2.x builds

Backported security fixes for Nimbus, the supervisors, the UI and the client on the 2.x release you run, delivered as signed tarballs, Maven artifacts and container images on the Java version you run today.

2.4 to 2.8.9Nimbus and supervisorsSigned builds
2

The ZooKeeper under Storm

Patched builds of ZooKeeper 3.4 to 3.7 and support for 3.8 and 3.9, for the ensemble that holds heartbeats and assignments. VEX statements cover the bundled jar your scanner flags.

ZooKeeper 3.4 to 3.9Heartbeats and assignmentsVEX
3

Storm 3 migration

Java 25 readiness for hosts and dependencies, Clojure topology ports, and a topology-by-topology cut-over to Storm 3.1.

Java 25Clojure portsStorm 3.1

Your options, compared

OptionWhat you getTrade-off
Upgrade to Storm 3 nowA maintained Storm lineJava 25 across every host and dependency, and Clojure topologies ported first.
Replace StormA different stream processing engineEvery topology rewritten and retested.
OSSeva extended supportPatched Storm 2.x and ZooKeeper today, and the move to Storm 3A subscription while 2.x stays in production.
Stay on 2.8.9 unpatchedNothing more from the communityNew Storm and ZooKeeper advisories stay open on a branch nobody maintains.

Release dates and the Java 25 requirement from the storm.apache.org release announcements. The ZooKeeper requirement from the Storm 3.1.0 cluster setup guide. Bundled ZooKeeper versions from pom.xml at each release tag. ZooKeeper advisories from zookeeper.apache.org/security.

Frequently asked questions

Is Storm 2.x end of life?

Yes. Storm 2.8.9, released on 22 July 2026 alongside 3.0.0, is the final 2.x release, and the project no longer maintains the 2.x branch.

What Java version does Storm 3 need?

Java 25. The Storm 3.0.0 release announcement says to upgrade the environment before migrating. The Java API is backwards-compatible with 2.x, and the Clojure DSL is removed.

Does Storm 3 still use ZooKeeper?

Yes. The 3.1.0 setup guide makes a ZooKeeper cluster step one, and storm.zookeeper.servers is mandatory configuration.

Can we keep running Storm 2.x?

With patched builds, yes, for as long as the Java 25 work takes. OSSeva ships patched Storm 2.x and ZooKeeper builds now, so the migration can follow the platform upgrade rather than race it.

Which support tier fits a Storm cluster?

Patch covers signed builds with backported fixes. Assure adds an ensemble audit and an attestation package for auditors. Operate adds 24/7 monitoring and named engineers.

Keep Storm 2.x patched until Java 25 is ready.

Start with Patch today. Add Assure or Operate when the cluster needs them.