September 30, 2026
Release 3.2.0-b137 of Cloudera Data Flow introduces automatic PostgreSQL updates, a new controller service allowing you to send data between different NiFi clusters in the same environment without having to manage certificates, plus several bugfixes.
New features
- Automatic PostgreSQL upgrades
- PostgreSQL DB is now automatically upgraded alongside Cloudera Data Flow upgrades. An upgrade to Cloudera Data Flow 3.2.0 upgrades PostgreSQL to version 17.
- Default Node SSL Context Service
-
This release of Cloudera Data Flow introduces a new DefaultNodeSSLContextService controller service. This controller service allows you to send data from one NiFi cluster (deployment or test session) to another within the same Cloudera Data Flow environment, without having to manually manage and rotate certificates.
For more information, see Securing communication between NiFi clusters using the Default Node SSL Context Service
Platform updates
- New Kubernetes version support
-
Cloudera Data Flow now supports EKS/AKS 1.36.
Changes and improvements
- ZooKeeper removed
-
As of release 3.2.0, Apache ZooKeeper has been removed from Cloudera Data Flow.
- HashiCorp Vault replaced with OpenBao
-
OpenBao replaces Vault in Cloudera Data Flow.
- Cleaner test session cancellation
-
Canceling a freshly started test session now fully cleans up its underlying resources (volumes, namespace) rather than leaving them suspended, avoiding wasted cloud resources. A confirmation dialog explains the behavior; resumed sessions still preserve data.
- Clearer suspend-failure handling
-
A failed test-session suspend now reports a distinct, accurate failure state with a retry path, instead of a misleading “failed to terminate.”
- Reliable termination of orphaned deployments
-
Terminating a deployed flow now succeeds even when its underlying NiFi process group was already deleted, instead of leaving the deployment stuck.
- Alphabetically sorted workspace selector
-
The Target Workspace/environment dropdown in the deployment dialog now lists environments alphabetically, matching the create-draft dialog.
- Accurate validation state in the deployment wizard
-
A failed NiFi configuration validation (for example, a bad custom NAR) now stays flagged as failed when navigating between steps, instead of incorrectly showing a green checkmark.
- Smarter execution-node defaults
-
Processors that can only run on the primary node (e.g., ListS3, QueryDatabaseTable) now default to and are validated against “Primary Node” execution, preventing invalid multi-node configurations.
- Faster shared parameter group handling
-
Drafts that import shared parameter groups now perform far fewer backend lookups, sync parameters concurrently, and use longer timeouts, thus improving performance and reliability at scale.
Fixed issues
- ENGESC-33608: Unable to enable Controller Services followed by start or stop of the Process Groups
-
Fixes an issue where enabling controller services after starting or stopping a process group failed with an error message.
- CDPDFX-11587: Unable to reconfigure flow design sessions using custom NARs
-
Fixes an issue where configuring a custom NAR prevented Flow Designer test sessions from being reconfigured.
- CDPDFX-11634: Issues in UpdateAttribute Advanced options in Flow Designer
-
Fixes two issues: The first issue resulted in an error message in an UpdateAttribute processor with any rules defined. The cause of the error was JAXB not being on the classpath.
The second issue caused flows with annotationData without any rules to fail due to a restriction in Flow Designer.
- CDPDFX-11535: UI/CLI: creating a deployment with shared parameter groups containing sensitive parameters is missing documentation
-
Fixes an issue where the CLI command generated by the UI missed the required
"sensitive”: truefield for shared parameter groups with sensitive parameters, which caused the deployments to fail. The CLI help has also been updated with information on this field. - CDPDFX-11695: JWT refresh resets auth_time, allowing indefinite token extension
-
Fixes an issue that allowed authentication token validity to be extended indefinitely.
- CDPDFX-11588: CDF Azure Upgrade failed on demo tenant
-
Fixes an issue where ZooKeeper operator caused upgrades to fail.
- CDPDFX-11564: delete-flow-draft removes flow draft but leaves orphaned test session, blocking environment disable
-
Fixes an issue where deleting a flow draft immediately after terminating a test session (while termination was still in progress) resulted in a partial deletion: the flow draft was removed from the database, but the test session record remained. This orphaned test session later prevented the Cloudera Data Flow environment from being disabled.
- CDPDFX-11553: Asset/file properties honored at deploy
-
File uploads to a processor property are now correctly recognized as asset-capable at deployment, so the deploy wizard lets you supply the file.
- CDPDFX-11587: Reconfiguring sessions with custom NARs
-
You can now suspend and resume flow design sessions that use custom NARs without errors or workarounds.
- CDPDFX-11495: Flow migration without parameter providers
-
Flow migration no longer fails with a 500 error when a flow definition has no parameter providers.
- CDPDFX-11729: NiFi Prometheus metrics
-
Fixed a broken metrics endpoint that redirected monitoring scrapers to the NiFi UI; Prometheus integration now works correctly.
