live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
releaseINTEGRATION

Camel 4.22 LTS is a migration checkpoint, not a feature-count release

The consequential changes sit in route hardening, AI-tool governance and compatibility checks that teams should test before adopting the new upstream LTS.

Camel 4.22 migration checkpoint with security and AI routing changes.
Side by side: what changed
By The News Desk· Sep 13, 2026the quick take — two AI hosts go live when you do

Apache Camel 4.22.0 is the project’s new long-term-support release, but the useful signal is not the size of its resolved-issue list. The release notes show a platform tightening route security and operability while making AI integrations first-class parts of the routing model.

What changed

The largest architectural addition is a unified AI-tool abstraction for route-based tools. Camel can expose those routes through a built-in MCP server over Streamable HTTP, carry nested parameters as raw JSON Schema and attach MCP hints such as read-only, destructive and idempotent metadata. The same release adds OpenAI Responses API and audio operations, AWS Bedrock agent operations and more model choices in Camel’s terminal interface.

That AI work sits beside changes with broader production consequences. Camel 4.22 can apply an allow-list to dynamic-URI EIPs including toD, recipientList, routingSlip, dynamicRouter, enrich and pollEnrich. It can validate Keycloak token type and authorized-party claims, fail closed when platform HTTP JWT authentication lacks an issuer or audience, configure a JEP 290 object-input filter and strip path segments from externally derived filenames. JFR instrumentation now covers exchanges, processors and endpoints.

The release also fixes failure modes that can look like data loss rather than clean exceptions: S3 streaming uploads larger than the configured part size could be truncated, DDB Streams consumers could miss shards created after startup, and several AWS producers could silently do nothing when pojoRequest=true received the wrong body type.

Who should care

Teams maintaining integration routes should review the components they actually use rather than treating the resolved-ticket total as one risk class. AI-platform teams gain a path from existing routes to MCP tools, but the annotations are descriptive metadata; deployments still need policy enforcement around tool discovery and invocation.

For Red Hat build of Apache Camel users, this is upstream evidence, not a statement that 4.22 is already in a supported Red Hat stream. Adoption should follow Red Hat’s supported-version and compatibility guidance when product packaging catches up.

What to test

Camel supports Java 17, 21 and 25 in this release. A jump from an earlier LTS still crosses intermediate compatibility boundaries. Camel’s upgrade guidance says multi-minor moves require each intervening guide; among the documented changes, camel-exec now blocks control headers unless allowControlHeaders=true, JBang accepts route YAML only under route-specific naming conventions, and the Pulsar 4.2 client rejects old four-segment V1 topic names.

The practical migration plan is therefore component-led: inventory route schemes and dynamic endpoints, run regression tests for message delivery and error paths, check authentication and egress assumptions, and validate observability before promoting 4.22 as the next LTS baseline. The release page confirms the artifacts are available through Apache mirrors and Maven coordinates.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.