Airbyte 2.4
Sometimes, you want to kubectl up with a blanket, some hot cocoa, and a new version of Airbyte. That's right, we pronounced it kubectl. Anyway, Airbyte version 2.4 was released on October 9, 2026.
Helm chart improvements
- Safer
airbyte-workload-api-serverrollouts: The deployment now surges one pod at a time during a rolling update (maxSurge: 1, previously100%). Its readiness probe now checks/health/readinessinstead of the liveness endpoint, so Kubernetes routes traffic to a pod only when it's ready to serve requests.
Connector & sync management
- Deleted streams leave the connection: When a source table is deleted and the connection is set to propagate field changes only, Airbyte now removes the stream from the connection's configured streams. Previously the stream stayed in the connection until you refreshed the schema.
- Failing connection warnings arrive sooner: Airbyte now warns about a failing connection when either
MAX_DAYS_OF_ONLY_FAILED_JOBS_BEFORE_CONNECTION_WARNINGorMAX_FAILED_JOBS_IN_A_ROW_BEFORE_CONNECTION_WARNINGis reached, instead of waiting for both. With the defaults, a daily connection gets a warning after four days of failures rather than 20. - Check, discover, and spec timeouts work again: The connector sidecar's file timeout now measures elapsed time correctly. Check, discover, and spec operations whose connector produces no output end at the timeout instead of hanging.
- Custom components with backslashes: Custom declarative connectors whose
components.pycontains a backslash no longer fail every check, discover, and sync with a checksum mismatch, and publishing them no longer returns a server error. - Slack schema change notifications for large schemas: Schema change notifications for sources with many streams and fields now reach Slack. Airbyte truncates the summary to fit Slack's message limit, where previously Slack rejected the message.
- More durable Bing Ads OAuth tokens: If you configure a Bing Ads OAuth app, Airbyte now sends the client secret when it exchanges the authorization code. The resulting refresh tokens are no longer revoked when the authorizing user changes or resets their password.
Security improvements
- Stricter request authorization: When a request refers to more than one resource, all of those resources must belong to the same workspace and organization, or Airbyte rejects the request with a 403. This fixes CVE-2026-80049 and applies to deployments with authentication enabled. The web app and other normal callers aren't affected.
- Patched base image: Platform images now build on
airbyte-base-java-imageversion3.3.16, which installs the latest Amazon Linux 2023 security updates, including fixes forcurl,rpm,pcre2, andlibxml2. - Arbitrary user IDs on OpenShift: Platform containers now start when they run as an arbitrary user ID with group
0, as OpenShift's restricted security context assigns. Containers on a read-only root filesystem no longer exit if the startup trust store refresh can't write, and fall back to the trust store built into the image. - No service account token in connector pods: Check, discover, and spec connector pods no longer mount a Kubernetes service account token, which they never used.
Bug fixes
- Stream status graph with retried syncs: The streams status graph no longer fails to load for connections that have a sync with more than one attempt.
- Deleted workspaces in permission lists: A user's permission list no longer includes grants on deleted workspaces.