github apolloconfig/apollo v3.0.0
Apollo 3.0.0 Release

3 hours ago

Highlights

Apollo 3.0.0 takes a step toward Agent First configuration management, giving agents structured APIs, user-delegated access, and machine-readable capabilities for configuration workflows.

A modern server foundation

The server baseline moves to Java 17, Spring Boot 4.1.1, Spring Framework 7, and Spring Cloud 2025.1.3, with updated discovery integrations. See #5585 and #5671.

Portal moves to OpenAPI-first

Portal management flows now use generated OpenAPI contracts, including configuration items, namespaces, releases, gray branches, permissions, and import/export. Portal and external integrations share an API foundation that agents can use directly. See #5608, #5610, #5612, #5616, #5617, and #5618.

User access tokens for AI agents

Users can delegate scoped access to agents and automation, with expiry, rate limits, revocation, and auditing. Each request is checked against the token scopes and the owning user's current permissions. Capability discovery exposes identity, scopes, and available OpenAPI actions. See #5632 and the user access token guide.

Independent companion projects apollo-cli and apollo-evals provide command-line workflows and evaluation of agent task results and resource boundaries.

What's Changed

  • Change: migrate the server runtime to Java 17 and Jakarta APIs, and update official Docker runtime images to Java 17 by @nobodyiam in #5555
  • Fix: include super admin in hasAnyPermission semantics by @nobodyiam in #5568
  • Test: add edge-case coverage for NamespaceService.loadNamespaceBO, including deleted items, missing releases, and public/private namespace resolution by @lmj798 in #5574
  • Change: official Config/Admin packages now default to database discovery; upgraded Eureka deployments should explicitly keep the github profile to preserve legacy behavior by @nobodyiam in #5580
  • Refactor: extract config constants and methods in BizConfig, PortalConfig, and RefreshableConfig by @youngzil in #5583
  • Change: migrate Apollo server baseline to Spring Boot 4.0.x, align Spring Cloud discovery integrations, and add external discovery smoke workflow by @nobodyiam in #5585
  • Feature: auto-provision an enabled AccessKey per environment when creating a new app, controlled by apollo.access-key.auto-provision.enabled in ApolloConfigDB.ServerConfig by @youngzil in #5589
  • Feature: support ServerConfig create/update/delete by key + cluster in ConfigDB management, with UI cluster awareness and multi-cluster safety tests by @youngzil in #5601
  • Change: establish Portal OpenAPI compatibility checks, fix frontend context-path handling, and migrate application read operations to OpenAPI by @nobodyiam in #5607
  • Change: adapt Apollo Portal OpenAPI migration to apollo-openapi v0.2.0 by @nobodyiam in #5608
  • Change: migrate Apollo Portal config item UI operations to OpenAPI by @nobodyiam in #5610
  • Change: migrate Apollo Portal namespace core UI operations to OpenAPI by @nobodyiam in #5612
  • Change: migrate Apollo Portal release, branch, and instance UI operations to OpenAPI by @nobodyiam in #5616
  • Change: migrate Apollo Portal permission and AccessKey UI operations to OpenAPI by @nobodyiam in #5617
  • Change: complete Apollo Portal UI management OpenAPI migration by @nobodyiam in #5618
  • Perf: reuse serialized long-poll notification responses to reduce CPU and memory overhead by @nobodyiam in #5620
  • Feature: allow explicitly authorized consumer tokens to manage portal users by @nobodyiam in #5623
  • Feature: add user access tokens for AI agents and automation by @klboke in #5632
  • Fix: handle null old configuration values in ConfigChangeContentBuilder.updateItem by @vasiliy-mikhailov in #5634
  • Fix: honor parent namespace value-length limits in gray namespaces by @vasiliy-mikhailov in #5635
  • Fix: return 429 instead of redirecting to sign-in for OpenAPI user token rate limits by @nobodyiam in #5637
  • Security: enforce AccessKey authentication against the actual application ID for the raw configfiles API by @Shawyeok in #5639
  • Fix: physically delete retained release history and unreferenced release rows by @klboke in #5641
  • Fix: preserve item type when revoking unpublished changes by @Lin-1997 in #5646
  • Security: disable remote H2 Console access by default in Quick Start and clarify local-only usage by @nobodyiam in #5649
  • Fix: restore H2 Console frame loading and auto-configuration in all-in-one deployments with the auth profile by @nobodyiam in #5652
  • Docs: document User Management and Permission Management Open APIs and their token authorization rules by @habiibullahm in #5654
  • Feature: support configurable OIDC username claim (spring.security.oidc.user-id-claim-name) for the Apollo user identity by @nikhiln64 in #5655
  • Feature: support revoking unpublished changes for non-properties namespaces by @klboke in #5656
  • Feature: add formatted and raw JSON views in Portal by @klboke in #5657
  • Fix: strict JSON/YAML well-formedness validation at the authoritative save path by @pavanandhukuri in #5660
  • Feature: add batch create/update/delete OpenAPI operations for namespace items by @shalk in #5665
  • Change: upgrade Apollo server baseline to Spring Boot 4.1.1 and Spring Cloud 2025.1.3 by @nobodyiam in #5671
  • Fix: preserve last-modified metadata of unchanged items when revoking changes by @henriquejsza in #5672
  • Docs: link the complete generated OpenAPI reference from the English and Chinese platform guides by @shalk in #5673
  • Fix: support user-token deletion of keys containing slashes or backslashes by @nobodyiam in #5676
  • Fix: preserve Portal OpenAPI timestamps, gray rules, instance details and app audit names, and retain item types when omitted on update by @nobodyiam in #5677
  • Fix: snapshot AccessKey cache under lock to avoid concurrent iteration failures by @youngzil in #5678
  • Fix: handle encoded and literal-percent keys, preserve item types and audit display names, enforce full namespace name limits, report partial import failures and honor overwrite selections, restore token actions and audit filters, show gray-rule labels, and correct restricted namespace visibility, API error responses and namespace views by @nobodyiam in #5681
  • Fix: restore service startup on JDK 26, recover background console logs, and consolidate startup log configuration by @nobodyiam in #5682
  • Fix: support open-ended audit date filters and align release regression checks with supported Portal behavior by @nobodyiam in #5684
  • Change: remove the user-token audit foreign key to preserve historical token IDs and allow asynchronous audit writes after token deletion by @nobodyiam in #5685

Installation

Please refer to the Distributed Deployment Guide.

How to upgrade from v2.5.2 to v3.0.0

Runtime and discovery changes:

  • Apollo server's Java runtime baseline has moved from Java 8 to Java 17. Upgrade the runtime for apollo-configservice, apollo-adminservice, and apollo-portal before deploying 3.0.0. This change concerns the server runtime; client SDK runtime requirements remain specific to the SDK in use.
  • Official ConfigService/AdminService packages and Docker images now default to database-discovery. To keep an existing Eureka deployment, explicitly set SPRING_PROFILES_ACTIVE=github for both services before starting the new version. See #5580.

Database migration and deployment:

The v250-v300 migration scripts also apply when upgrading from v2.5.2. They add a ConfigDB index and the PortalDB UserToken and UserTokenAudit tables.

  1. Apply apolloconfigdb-v250-v300.sql to ApolloConfigDB.
  2. Apply apolloportaldb-v250-v300.sql to ApolloPortalDB.
  3. Deploy the v3.0.0 executables in this order:
    1. apollo-configservice
    2. apollo-adminservice
    3. apollo-portal

New Contributors

Full Changelog: v2.5.2...v3.0.0

Don't miss a new apollo release

NewReleases is sending notifications on new releases.