Kafka client fails ApiVersions negotiation against WarpStream after franz-go v1.21.5 → v1.22.0
Summary
After bumping github.com/twmb/franz-go from v1.21.5 to v1.22.0, Loki's Kafka-based ingest path fails to establish connections to a Warpstream Kafka-protocol-compatible agent. Every connection attempt fails during ApiVersions negotiation, logged as an EOF that franz-go misattributes to a TLS/plaintext mismatch — but TLS is not in use on this path (SASL_PLAINTEXT).
Root cause (suspected)
twmb/franz-go#1455 (KIP-1242), shipped in v1.22.0, changes the client's connection-negotiation behavior: every new connection now starts by sending an ApiVersions request at v5. Against a real Kafka broker older than 4.4, the broker replies UNSUPPORTED_VERSION and the client transparently retries at the broker's max supported version — one extra round trip, no visible error.
WarpStream's Kafka-protocol-compatible agent appears not to implement that graceful UNSUPPORTED_VERSION fallback for a v5 ApiVersions request. Instead of replying with an error the client can handle, it closes the connection outright, which franz-go then reports as the EOF/TLS-guess error above.
Impact
- Any client using franz-go
v1.22.0+ against a WarpStream Kafka-protocol endpoint that doesn't yet support ApiVersions v5 negotiation cannot connect at all — this is a hard connectivity break, not a degraded/retriable state.
- Reproduced with Loki's Kafka-based ingest path (producer and consumer), but the issue is generic to any franz-go client talking to an affected WarpStream agent version.
Kafka client fails ApiVersions negotiation against WarpStream after franz-go v1.21.5 → v1.22.0
Summary
After bumping
github.com/twmb/franz-gofromv1.21.5tov1.22.0, Loki's Kafka-based ingest path fails to establish connections to a Warpstream Kafka-protocol-compatible agent. Every connection attempt fails duringApiVersionsnegotiation, logged as an EOF that franz-go misattributes to a TLS/plaintext mismatch — but TLS is not in use on this path (SASL_PLAINTEXT).Root cause (suspected)
twmb/franz-go#1455 (KIP-1242), shipped in
v1.22.0, changes the client's connection-negotiation behavior: every new connection now starts by sending anApiVersionsrequest at v5. Against a real Kafka broker older than 4.4, the broker repliesUNSUPPORTED_VERSIONand the client transparently retries at the broker's max supported version — one extra round trip, no visible error.WarpStream's Kafka-protocol-compatible agent appears not to implement that graceful
UNSUPPORTED_VERSIONfallback for a v5ApiVersionsrequest. Instead of replying with an error the client can handle, it closes the connection outright, which franz-go then reports as the EOF/TLS-guess error above.Impact
v1.22.0+ against a WarpStream Kafka-protocol endpoint that doesn't yet supportApiVersionsv5 negotiation cannot connect at all — this is a hard connectivity break, not a degraded/retriable state.