Charmed Apache Spark (revision 7)

July 29th, 2026

We’re excited to announce a new stable release for Charmed Apache Spark.

This release most notably brings the support for Apache Spark 4.0 and a Charmed Apache Spark Terraform Module to deliver a seamless, production-ready and fully open-source data lake experience. Moreover, this new release also comes with enhanced security and bug fixes to the various components that makes the Charmed Apache Spark solution.

Charmhub: 4.0/stable | Docs | Deploy guide | System requirements

Features

This release includes the following major feature:

  • [PRA-9] Support for Apache Spark 4.0

  • [PRA-234] Terraform modules refactor following CC008 (#208)

Enhancements

This release includes general enhancements across the solution, as well as to the individual components, as follows.

General

  • [PRA-9] Support for Apache Spark 4.0

  • [PRA-322] Components upgrade:

    • Apache Spark versions: 4.0.2-ubuntu2

    • Apache Kyuubi versions: 1.11.1-ubuntu1

    • NVIDIA Spark-RAPIDS version: 26.04.2

  • General updates of Python dependencies, craft build tools, CI workflows and Github actions

  • [PRA-63] Run integration tests using spread

  • [PRA-74][PRA-76] Configure Renovate to update OCI resources

  • [PRA-264] Improve TIOBE workflow reliability

Apache Kyuubi

  • [MISC] Enable renovate on track 4, fix oci updates (#233)

  • [MISC] Log creation of a user and password update events (#149) (#248) (#246)

Apache Spark History Server

  • [PRA-287] Use s3 integrator from track 2 and adopt object-storage-charmlib (#174) (#173)

Spark Integration Hub

  • [PRA-277] Use s3 integrator from track 2 and adopt object-storage-charmlib (#187) (#205)

Apache Spark Client snap

  • Component bumps (see General section for versions of various components)

  • [MISC] Reduce the K8s matrix validation and disable fail-fast feature (#148) (#149)

  • [PRA-211] Reorder PYTHONPATH to give priority to the snap’s stdlib (#146) (#150)

  • [PRA-256] Set driver metrics sink to JmxSink for shell entrypoints (#159) (#160)

  • [MISC] Remove workflow on_spark_update_available (#154)

  • [MISC] Fix permissions for snap release workflow (#156)

  • chore: adding scheduled test runs on weekends (#168)

  • [MISC] Update renovate configuration (#162)

Canonical security maintained OCI Images for Apache Spark

  • Component bumps (see General section for versions of various components)

  • [PRA-222] Add additional labels (commit hash, source, description, etc.) to the images (#225) (#226)

Charmed Apache Spark Terraform Module

  • [PRA-101] Remove deprecated mailing and updating lock file (#222)

  • [PRA-257] Automatic promotion bundle (#214)

  • [MISC] Let users decide whether to use COS in UAT tests (#232)

  • [PRA-306] Unpin juju-agent-version in Spark K8s Bundle integration tests (#231)

  • [PRA-7][KF-8066] Enable Spark <> Kubeflow integration with new standard (#233)

  • [PRA-318] Implement automated OCI getter for our products (#240)

  • [PRA-324] Split bundle by tracks

  • [PRA-330] Update Postgresql to latest revision on 14/stable (#251)

  • [PRA-324] Update renovate configuration (3.5) (#253) (#255) (#256)

  • [MISC] chore: adding CODEOWNERS file (#287) (#289)

  • [PRA-330] Bump postgresql charm to 16/stable on track/4.0 (#246)

  • [PRA-312] Split TLS private key and admin password secrets (#241)

Bug Fixes

This release includes several bug fixes across the solution, which are listed below categorized to individual components.

Apache Kyuubi

  • [MISC] Fix invalid JSON5 syntax in Renovate repository config (#213) (#217) (#218)

Apache Spark History Server

  • [MISC] Fix Github workflow permissions (#181) (#182)

Spark Integration Hub

  • [PRA-168] Charm errors when related to the s3-integrator and bucket name is empty (#203)

  • [MISC] Grant actions: read and contents: read permissions to Release workflow ci-tests caller (#216)

Canonical security maintained OCI Images for Apache Spark

Breaking Changes

This release includes the following breaking change:

Charmed Apache Spark Terraform Module

  • [PRA-234] Terraform modules refactor following CC008 (#208)

Documentation improvements

The current release also features the following documentation changes:

  • [PRA-11] Automated tutorial testing (#221)

  • docs: FE Feedback fixes (#210)

  • [PRA-309] Update docs for s3-integrator 2/stable and multi-track awareness (#237)

  • [PRA-165] Update docs to reflect correct behavior when S3 region is not configured (#257) (#284) (#286)

  • [PRA-324] Adapt docs content to match Spark version on various tracks (#252) (#258) (#254)

Security

The following CVEs have been fixed in the new artifacts:

Component

Severity

Fixed

Apache Spark

High

CVE-2025-48734, CVE-2025-67721, CVE-2026-24281, CVE-2026-24308, CVE-2025-54920

Medium

CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480

Apache Kyuubi

High

CVE-2025-48734, CVE-2026-33870, CVE-2026-33871, CVE-2026-35554, CVE-2026-42198, CVE-2026-42577, CVE-2026-42579, CVE-2026-42583, CVE-2026-42584, CVE-2026-42587, CVE-2026-44249, CVE-2026-45416, CVE-2026-45674, CVE-2026-47691, CVE-2026-50010

Medium

CVE-2026-33558, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480, CVE-2026-41417, CVE-2026-42580, CVE-2026-42581, CVE-2026-42585, CVE-2026-45536, CVE-2026-45673, CVE-2026-47244, CVE-2026-48043, CVE-2026-50020, CVE-2026-50560, CVE-2026-6860

Low

CVE-2026-42578

Compatibility

The following table summarize the compatibility matrix of the solution:

Note

Model destruction for controllers above 3.6.18+ may sometimes freeze (see Juju issue #22105). In these cases, we recommend destroying the resources manually.

Acknowledgements

We are extremely grateful to the Apache Spark and Apache Kyuubi communities for their continuous work, involvement and engagement with open-source to make technologies that process data at scale available to the broader audience.