Documentation

Karaf Runtime
4.x series
online html pdf
Latest update
3.x series
online html pdf
Latest update
Karaf Cellar
4.x series
online html pdf
Latest update
3.x series
online html pdf
Latest update
Karaf Decanter
2.x series
online html pdf
Latest update
1.x series
online html pdf
Latest update

Examples

You are looking for some examples to learn how to implement bundle for Apache Karaf ? There is some usefull examples include in the source code, you can also browse and view documentation on the github of the projet.
If you are looking for examples that are missing here or you want to share your example with the community, please contact us on the mailing list and we will add it with pleasure.

Name Description Github
Blueprintusing services with XML or annotations.GitHub
Brandingbranding the look'n feel of the shell console for your own Karaf distribution.GitHub
Bundlethe bundle is the core deployment unit when using OSGi.GitHub
Camelthis example shows how to use Apache Camel in Karaf. Apache Camel is a integration framework, allowing you to integrate several systems and applications all together.GitHub
CDIthis example shows how to use CDI in Karaf, with annotations (Inject, etc).GitHub
Shell Commandcreating a shell command.GitHub
Configurationthis example shows how to use configuration in your application, introducing different approach.GitHub
Deployercreating a Karaf deployer service on the deploy folder.GitHub
Dockerthis example shows how to easily create Docker image with Karaf and your applications. It shows two kinds of packages: static or dynamic.GitHub
Dumpcreating a dump provider service.GitHub
HTTP resourcecreating a very simple bundle that just register an empty resource service.GitHub
Integration testcreating integration tests in addition of unit tests for your bundles.GitHub
JAASusing the Karaf Security service in different way.GitHub
JDBCusing simple JDBC implementation with Pax-JDBC and an Apache Derby embedded database.GitHub
JMSusing a JMS ConnectionFactory service in code that you can implement to interact with JMS.GitHub
JPAusing JPA with entity manager for the persistence implementation.GitHub
Pax Logging Appenderregistering a custom Pax Logging appender.GitHub
Mavenusing the Karaf Maven plugin with goals like assembly, client, deploy, kar, run...GitHub
MBeanregistering a JMX MBean in the Apache Karaf MBeanServerGitHub
Profilecreating several profiles (in a registry) and use these profiles to create custom distributions.GitHub
Redisusing a Redis server (pub/sub, or key/value store) within Karaf.GitHub
RESTusing JAX-RS to implement a REST service.GitHub
Schedulercreating a runnable service periodically executed by the Apache Karaf scheduler.GitHub
Service Component Runtimeusing services with annotations with the OSGi compendium specification.GitHub
Servletregistering a servlet in the Karaf HTTP Service with different approaches.GitHub
SOAPusing JAX-WS to implement a SOAP service.GitHub
URL Namespace Handlercreating a new URL namespace handler and use it in all Apache Karaf parts.GitHub
Warcreating a regular war to be deployed in Apache Karaf.GitHub
Websocketthis example shows how to register a websocket in the Karaf HTTP Service.GitHub
GraphQLthis example shows how to use GraphQL in the context of a HTTP servlet, websocket and commands in Apache Karaf.GitHub

Security Advisories

CVE-2014-0219 : Apache Karaf enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.

Notes »

CVE-2016-8750 : Apache Karaf's LDAPLoginModule is vulnerable to LDAP injection.

Notes »

CVE-2018-11786 : Enforce SSH permission based on RBAC.

Notes »

CVE-2018-11787 : Unsecure access to Gogo shell in the webconsole.

Notes »

CVE-2018-11788 : XXE vulnerability found on Apache Karaf.

Notes »

CVE-2019-0191: Zip-slip vulnerability in KAR deployer.

Notes »

CVE-2019-0226: Arbitrary file write vulnerability in Config service.

Notes »

CVE-2020-11980: A remote client could create MBeans from arbitrary URLs.

Notes »

CVE-2021-41766: Insecure Java Deserialization.

Notes »

CVE-2022-22932: Path traversal flaws

Notes »

CVE-2022-40145: JDBC JAAS LDAP injection

Notes »

CVE-2024-34365: Cave SSRF and arbitrary file access

Notes »

CVE-2026-24656: Decanter log socket collector: Deserialization of Untrusted Data

Notes »

CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules

Notes »

CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)

Notes »

CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation

Notes »

CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create

Notes »

CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin

Notes »

CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations

Notes »

CVE-2026-92230: Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching

Notes »

Articles

Tutorials

Books

Bloggers