September 30, 2026

Release 3.2.0-b137 of Cloudera Data Flow introduces automatic PostgreSQL updates, a new controller service allowing you to send data between different NiFi clusters in the same environment without having to manage certificates, plus several bugfixes.

New features

Automatic PostgreSQL upgrades
PostgreSQL DB is now automatically upgraded alongside Cloudera Data Flow upgrades. An upgrade to Cloudera Data Flow 3.2.0 upgrades PostgreSQL to version 17.
Default Node SSL Context Service

This release of Cloudera Data Flow introduces a new DefaultNodeSSLContextService controller service. This controller service allows you to send data from one NiFi cluster (deployment or test session) to another within the same Cloudera Data Flow environment, without having to manually manage and rotate certificates.

For more information, see Securing communication between NiFi clusters using the Default Node SSL Context Service

Platform updates

New Kubernetes version support

Cloudera Data Flow now supports EKS/AKS 1.36.

Changes and improvements

ZooKeeper removed

As of release 3.2.0, Apache ZooKeeper has been removed from Cloudera Data Flow.

HashiCorp Vault replaced with OpenBao

OpenBao replaces Vault in Cloudera Data Flow.

Cleaner test session cancellation

Canceling a freshly started test session now fully cleans up its underlying resources (volumes, namespace) rather than leaving them suspended, avoiding wasted cloud resources. A confirmation dialog explains the behavior; resumed sessions still preserve data.

Clearer suspend-failure handling

A failed test-session suspend now reports a distinct, accurate failure state with a retry path, instead of a misleading “failed to terminate.”

Reliable termination of orphaned deployments

Terminating a deployed flow now succeeds even when its underlying NiFi process group was already deleted, instead of leaving the deployment stuck.

Alphabetically sorted workspace selector

The Target Workspace/environment dropdown in the deployment dialog now lists environments alphabetically, matching the create-draft dialog.

Accurate validation state in the deployment wizard

A failed NiFi configuration validation (for example, a bad custom NAR) now stays flagged as failed when navigating between steps, instead of incorrectly showing a green checkmark.

Smarter execution-node defaults

Processors that can only run on the primary node (e.g., ListS3, QueryDatabaseTable) now default to and are validated against “Primary Node” execution, preventing invalid multi-node configurations.

Faster shared parameter group handling

Drafts that import shared parameter groups now perform far fewer backend lookups, sync parameters concurrently, and use longer timeouts, thus improving performance and reliability at scale.

Fixed issues

ENGESC-33608: Unable to enable Controller Services followed by start or stop of the Process Groups

Fixes an issue where enabling controller services after starting or stopping a process group failed with an error message.

CDPDFX-11587: Unable to reconfigure flow design sessions using custom NARs

Fixes an issue where configuring a custom NAR prevented Flow Designer test sessions from being reconfigured.

CDPDFX-11634: Issues in UpdateAttribute Advanced options in Flow Designer

Fixes two issues: The first issue resulted in an error message in an UpdateAttribute processor with any rules defined. The cause of the error was JAXB not being on the classpath.

The second issue caused flows with annotationData without any rules to fail due to a restriction in Flow Designer.

CDPDFX-11535: UI/CLI: creating a deployment with shared parameter groups containing sensitive parameters is missing documentation

Fixes an issue where the CLI command generated by the UI missed the required "sensitive”: true field for shared parameter groups with sensitive parameters, which caused the deployments to fail. The CLI help has also been updated with information on this field.

CDPDFX-11695: JWT refresh resets auth_time, allowing indefinite token extension

Fixes an issue that allowed authentication token validity to be extended indefinitely.

CDPDFX-11588: CDF Azure Upgrade failed on demo tenant

Fixes an issue where ZooKeeper operator caused upgrades to fail.

CDPDFX-11564: delete-flow-draft removes flow draft but leaves orphaned test session, blocking environment disable

Fixes an issue where deleting a flow draft immediately after terminating a test session (while termination was still in progress) resulted in a partial deletion: the flow draft was removed from the database, but the test session record remained. This orphaned test session later prevented the Cloudera Data Flow environment from being disabled.

CDPDFX-11553: Asset/file properties honored at deploy

File uploads to a processor property are now correctly recognized as asset-capable at deployment, so the deploy wizard lets you supply the file.

CDPDFX-11587: Reconfiguring sessions with custom NARs

You can now suspend and resume flow design sessions that use custom NARs without errors or workarounds.

CDPDFX-11495: Flow migration without parameter providers

Flow migration no longer fails with a 500 error when a flow definition has no parameter providers.

CDPDFX-11729: NiFi Prometheus metrics

Fixed a broken metrics endpoint that redirected monitoring scrapers to the NiFi UI; Prometheus integration now works correctly.