Infinispan 16.3
"Tripel Karmeliet"
Our 4-month brewing process has, yet again, come to completion. We are proud to present Infinispan 16.3 "Tripel Karmeliet", brewed by experts (us !) using the finest ingredients, for all you fine palates out there.
The main theme for this release is "robustness": we’ve been investigating several areas, especially in "fragile" conditions, such as scaling up/down, startup, shutdown, split-brains, huge caches and clusters with large number of caches, etc, with the following goals:
-
improve reliability, addressing more failure conditions encountered by our users
-
optimize resource usage by optimizing algorithms and increasing concurrency in certain operations
-
better recovery in situations where data was inevitably lost or corrupted
This task is obviously open-ended, so look for more improvements in future releases.
Conflict detection and resolution
When partitions merge, resolving conflicts traditionally requires transferring entries from every owner to compare replicas. In 16.3 this has been made dramatically more efficient with hash-based conflict detection: each segment is summarized by a compact, order-independent XOR hash that is maintained incrementally as the cache is modified, so it costs almost nothing to read at merge time.
On merge, these summaries are compared first (prefetched in one batched RPC per node). Segments whose hashes match on all owners are skipped entirely — zero entries transferred. Only for mismatching segments does the comparison drill down into fixed-size buckets derived from entry keys, and only the entries in differing buckets are fetched to find the actual conflicts. The optimization is fail-safe: any failure falls back to a full fetch without changing the resolution outcome. [#16887] [#17620]
For a detailed walkthrough of partition handling, detection and conflict resolution see the architecture documentation.
Concurrent cache start
User caches are now started concurrently without blocking the cache manager start. As soon as a cache is started it is ready to serve requests, without having to wait for other caches. [#16900]
Get optimizations
Introduce an optimized interceptor chain for get and getCacheEntry operations that skips interceptors not participating in read commands.
Benchmarks show 23-36% improvement on pure get operations across LOCAL
and DIST_SYNC cache modes, with no regressions on put paths. [#17698]
Configuration enhancements
Per-node mutable configuration attributes are now persisted in the persistent state, making them survive restarts. [#17889]
Additionally, configuration attributes are now version-aware so that, during rolling upgrades, newer configurations are not sent to older nodes, which would not know how to parse them. [#18038]
Transaction table management
Logging
Logging excessive failures under load has an amplification effect which can deteriorate performance even more. Also, log flooding makes it hard to identify the root cause of the failures. For this reason, several improvements have been made to reduce the amount of logging:
Update by query
Ikcle has gained the ability to update entities with the following syntax:
UPDATE FROM <entityName> {SET | ADD | REMOVE} <field> = <value> [, ...]* [WHERE condition]
-
Use
SETto assign a new value to a field. When the target is a collection, the list replaces the entire existing collection. -
Use
ADDto add values to a collection field without replacing its contents. -
Use
REMOVEto remove values from a collection field without affecting other members.
The following example sets a new title, adds two tags, and removes one tag from all books whose price is greater than 100:
UPDATE FROM org.infinispan.sample.Book SET title = 'Updated Title', ADD tags = ('sale', 'featured'), REMOVE tags = ['discount'] WHERE price > 100
Values can currently only be constants, but Infinispan 16.4 will allow the use of expressions and functions.
Peek
A cache.peek(K key) method has been added for embedded and emote clients. This retrieves a cache entry without updating its last acces time or recency, meaning it will be unaffected for max idle expiration or eviction purposes. Also REST can utilize this via the flags header (e.g."PEEK") that is automatically parsed on server-side and converted to Flag enum values.
This behavior can also be used via a flag:
cache.withFlags(Flag.PEEK).get(key);
Security enhancements
Brute-force authentication protection
Security realms which handle username/password credentials (properties, ldap) are now automatically wrapped by a brute-force authentication protection mechanism: repeated failed attempts to authenticate a user will result in temporary lockdowns. [#18001]
Post-Quantum Cryptography configuration
TLS named groups, used by Post-Quantum Cryptography (PQC) algorithms, can be fine-tuned to cater for specific restrictions. This feature requires JDK 27 or JDK 25.0.5. [#17842]
Console enhancements
Update by query
The new update-by-query capability (see above) is also available from the console: an "Update entries" action in the cache Query tab executes an Ickle UPDATE statement against all matching entries, with a confirmation modal and result reporting, alongside the existing delete-by-query. [#868]
Editor and i18n improvements
The code editor used to create and download cache configurations has been improved, and translation loading was fixed so that localized bundles resolve correctly when the console is served from a custom base path. [#707]
CLI enhancements
Zero local authentication
A new local security realm allows the CLI to authenticate against a local Infinispan instance without prompting for a username and password, provided it is running local to the server with the same system account. Authentication grants all permissions, so this realm should always be combined with another one (e.g., properties) as a fallback: if the local mechanism fails, the CLI falls back to prompting for credentials of a configured user.
Optional transcoders
The JSON POJO (Jackson) and XML (XStream) transcoders have been moved out of the server core into dedicated modules, joining JBoss Marshalling as an optional module. These are no longer included in the default server distribution: install them with the CLI install command if you need their data conversion capabilities on a running server, or add the corresponding artifact to your dependencies for embedded usage.
Install with dependencies
The install command now supports installing an artifact together with its declared external dependencies via the -d|--with-dependencies option. Artifacts can list their required dependencies in a META-INF/infinispan-dependencies.txt file, and those are downloaded and installed automatically (dependencies already present in server/lib are skipped). For example, this makes it easy to install modules with native or third-party requirements such as the RocksDB cachestore or the optional transcoder modules.
Operator enhancements
Schema CRD
A new Schema custom resource allows registering, updating and deleting Protobuf schemas on Infinispan clusters via the REST API (/rest/v2/schemas). It follows the same patterns as the existing Cache CRD, including bidirectional synchronization . This was highly requested, and we’re glad we could finally deliver it! [#2379]
Custom ServiceAccount
The Infinispan CR now accepts a custom serviceAccountName for the server (and GossipRouter, Batch, Backup and Restore) pods. The ConfigListener can also be given its own service account; when one is specified, the operator does not create RBAC resources for it, leaving that entirely in user hands. [#2404]
Pausing reconciliation
Reconciliation of any managed resource (Infinispan, Cache, Schema, Batch, Backup or Restore) can be paused by annotating it with infinispan.org/paused: true. While paused, spec changes are not applied to the underlying resources - useful for debugging or maintenance windows. Remove the annotation to resume normal operation. [PR #2585]
Other notable improvements:
-
the
storageClassNameis now immutable after creation [#2368] -
The operator itself runs as a non-root user with a restricted security context (seccomp profile, no privilege escalation, all capabilities dropped), making it compatible with restrictive Pod Security Standards. [#2573]
-
The operator now talks to Infinispan 16 servers without using deprecated REST endpoints, eliminating the associated deprecation warnings. [#2474]
Spring AI integration
Infinispan now has a dedicated Spring AI integration, released as version 1.0.0. It provides two capabilities for building AI-powered applications with Spring Boot:
-
Vector Store - store and search document embeddings using Infinispan’s vector search capabilities with Ickle query language. Supports cosine, L2 and inner-product similarity metrics, metadata filtering, and auto-creates Protobuf schemas and indexed caches on startup.
-
Chat Memory Repository - persist conversation history (user, assistant, system and tool messages) in Infinispan, enabling stateful conversational AI applications.
Both modules come with Spring Boot auto-configuration starters, so getting started is as simple as adding the dependency and pointing to your Infinispan server.
For details, see the Spring AI integration documentation.
Architecture documentation
The Infinispan documentation now includes a detailed architecture document that describes in detail the various components and algorithms doing the dirty work behind the scenes.
Backwards compatibility
Infinispan 16.3 is fully backwards compatible with 16.x deployments and can be upgraded in-place.
The next release
16.3 is our third release using our time-boxed schedule. Adopting predictable release dates, in combination with the backwards compatibility guarantees of our rolling upgrade test harness, has allowed us to achieve great momentum: we’re delivering features, improvements and bug fixes more quickly. According to our roadmap, our next release will be 16.4, and it will happen on 2027-02-03. And you can trust it will happen exactly as the roadmap says !
Release notes
You can look at the release notes to see what was changed since our previous release.
Get them from our download page.
Get it, Use it, Ask us!
We’re hard at work on new features, improvements and fixes, so watch this space for more announcements!Please, download and test the latest release.
The source code is hosted on GitHub. If you need to report a bug or request a new feature, look for a similar one on our GitHub issues tracker. If you don’t find any, create a new issue.
If you have questions, are experiencing a bug or want advice on using Infinispan, you can use GitHub discussions. We will do our best to answer you as soon as we can.
The Infinispan community uses Zulip for real-time communications. Join us using either a web-browser or a dedicated application on the Infinispan chat.


