Spring Boot 3.0 Is Out — But I'm Holding Off on Upgrading for Now

Spring Boot 3.0.0 was officially released on November 25, 2022. As someone who likes chasing the new and eating crab first, I had to upgrade and try it. In the end, though, I gave up.

Spring Boot 3.0.0 was officially released on November 25, 2022. As someone who likes chasing the new and eating crab first, I had to upgrade and try it. In the end, though, I gave up.

The biggest change in Spring Boot 3.0 is JDK 17. You can’t cling to your JDK 8 anymore — you have to move to JDK 17! And then other requirements and dependencies changed massively too:

  • Maven: minimum supported version is now 3.5
  • Gradle: minimum supported version is now 7.5
  • Tomcat: Tomcat 10, Servlet 5.0
  • Spring Framework: 6.0.2 — straight to Spring 6
  • Spring Security: 6.0.0 — also straight to 6
  • Spring Data: 2022.0.0 — plenty of modules inside, basically all upgraded. The spring-data-elasticsearch I use jumped to 5.0 and dropped a lot of deprecated stuff

The Problems I Hit

Why did I put the upgrade on hold? I ran into a lot. Let me list them so you can dodge the pitfalls.

JDK 17

The eternal JDK 8 finally has to go; JDK 17 is the floor. It’s backward compatible, sure, but plenty of configuration and CI/CD base environments need heavy modification and debugging.

Tomcat 10

With Tomcat 10, Servlet moves to 5.0, and that caused most of my trouble. The first issue: package names changed! The old javax.servlet.http.HttpServlet is gone? Yep — renamed. It’s now jakarta.servlet.http.HttpServlet. Think a find-and-replace is enough? Too naive. Your source compiles, but the libraries you depend on haven’t changed yet, so everything looks fine in code and then bursts into flames at runtime with class-not-found errors everywhere.

That’s the main reason I’m holding off. The ecosystem needs time to adapt. If a library stops being maintained and nobody adapts it, you’d have to build and patch your own fork — potentially enormous work at too high a cost.

Spring Data 2022

I use Elasticsearch, and after upgrading I found many previous methods and classes gone. Learning and debugging costs real money here. I tweaked it until the errors stopped, but I’d still need heavy testing before shipping. The churn is just too big.

Summary

Arriving at Spring Boot 3.0 feels like stepping into a brand new world — JDK 17, Tomcat 10, Servlet 5.0. Familiar yet strange. I suspect most existing systems won’t upgrade; the change is too big, like being yanked straight up off the ground by the roots. Widespread adoption probably takes a few more years.

Right now my biggest headache is how my existing open source libraries can support both Spring Boot 2.x and 3.x, given that the servlet package names themselves changed. Splitting headache.