Releases: hashicorp/vault
v1.16.3
1.16.3
May 30, 2024
CHANGES:
- auth/jwt: Update plugin to v0.20.3 [GH-26890]
- core/identity: improve performance for secondary nodes receiving identity related updates through replication [GH-27184]
- core: Bump Go version to 1.22.2.
IMPROVEMENTS:
- secrets/pki (enterprise): Disable warnings about unknown parameters to the various CIEPS endpoints
- ui: Update PGP display and show error for Generate Operation Token flow with PGP [GH-26993]
BUG FIXES:
- activity (enterprise): fix read-only storage error on upgrades
- auto-auth: Addressed issue where having no permissions to renew a renewable token caused auto-auth to attempt to renew constantly with no backoff [GH-26844]
- core (enterprise): Fix an issue that prevented the seal re-wrap status from reporting that a re-wrap is in progress for up to a second.
- core/audit: Audit logging a Vault request/response will now use a minimum 5 second context timeout.
If the existing context deadline occurs later than 5s in the future, it will be used, otherwise a
new context, separate from the original will be used. [GH-26616] - core: Add missing field delegated_auth_accessors to GET /sys/mounts/:path API response [GH-26876]
- core: Address a data race updating a seal's last seen healthy time attribute [GH-27014]
- core: Fix
redact_version
listener parameter being ignored for some OpenAPI related endpoints. [GH-26607] - events (enterprise): Fix bug preventing subscribing and receiving events within a namepace.
- pki: Fix error in cross-signing using ed25519 keys [GH-27093]
- replication (enterprise): fix "given mount path is not in the same namespace as the request" error that can occur when enabling replication for the first time on a secondary cluster
- secrets-sync (enterprise): Secondary nodes in a cluster now properly check activation-flags values.
- secrets/azure: Update vault-plugin-secrets-azure to 0.17.2 to include a bug fix for azure role creation [GH-26896]
- secrets/pki (enterprise): cert_role parameter within authenticators.cert EST configuration handler could not be set
- secrets/transit: Use 'hash_algorithm' parameter if present in HMAC verify requests. Otherwise fall back to deprecated 'algorithm' parameter. [GH-27211]
- ui: Fix KVv2 cursor jumping inside json editor after initial input. [GH-27120]
- ui: Fix KVv2 json editor to allow null values. [GH-27094]
- ui: Fix broken help link in console for the web command. [GH-26858]
- ui: Fix link to v2 generic secrets engine from secrets list page. [GH-27019]
- ui: Prevent perpetual loading screen when Vault needs initialization [GH-26985]
- ui: Refresh model within a namespace on the Secrets Sync overview page. [GH-26790]
v1.17.0-rc1
[VAULT-27613] This is an automated pull request to build all artifact… …s for a release (#27253)
v1.15.8+ent
1.15.8 Enterprise
April 24, 2024
This release is created to share the Vault Enterprise changelog and notify consumers of availability. The attached source and assets do not include Vault Enterprise code and should not be used in place of official Docker images or binaries.
CHANGES:
- core: Bump Go version to 1.21.9.
- ui: Update dependencies including D3 libraries [GH-26346]
IMPROVEMENTS:
- activity (enterprise): Change minimum retention window in activity log to 48 months
- core: make the best effort timeout for encryption count tracking persistence configurable via an environment variable. [GH-25636]
- license utilization reporting (enterprise): Add retention months to license utilization reports.
- sdk/decompression: DecompressWithCanary will now chunk the decompression in memory to prevent loading it all at once. [GH-26464]
- ui: show banner instead of permission denied error when batch token is expired [GH-26396]
BUG FIXES:
- core (enterprise): fix bug where raft followers disagree with the seal type after returning to one seal from two. [GH-26523]
- secrets/pki: fixed validation bug which rejected ldap schemed URLs in crl_distribution_points. [GH-26477]
- storage/raft (enterprise): Fix a bug where autopilot automated upgrades could fail due to using the wrong upgrade version
- ui: fixed a bug where the replication pages did not update display when navigating between DR and performance [GH-26325]
v1.15.7+ent
1.15.7 Enterprise
March 28, 2024
This release is created to share the Vault Enterprise changelog and notify consumers of availability. The attached source and assets do not include Vault Enterprise code and should not be used in place of official Docker images or binaries.
SECURITY:
- auth/cert: validate OCSP response was signed by the expected issuer and serial number matched request [GH-26091]
IMPROVEMENTS:
- auth/cert: Allow validation with OCSP responses with no NextUpdate time [GH-25912]
- core (enterprise): Avoid seal rewrapping in some specific unnecessary cases.
- core (enterprise): persist seal rewrap status, so rewrap status API is consistent on secondary nodes.
- ui: remove leading slash from KV version 2 secret paths [GH-25874]
BUG FIXES:
- audit: Operator changes to configured audit headers (via
/sys/config/auditing
)
will now force invalidation and be reloaded from storage when data is replicated
to other nodes. - auth/cert: Address an issue in which OCSP query responses were not cached [GH-25986]
- auth/cert: Allow cert auth login attempts if ocsp_fail_open is true and OCSP servers are unreachable [GH-25982]
- cli: fixes plugin register CLI failure to error when plugin image doesn't exist [GH-24990]
- core (enterprise): fix issue where the Seal HA rewrap system may remain running when an active node steps down.
- core/login: Fixed a potential deadlock when a login fails and user lockout is enabled. [GH-25697]
- replication (enterprise): fixed data integrity issue with the processing of identity aliases causing duplicates to occur in rare cases
- ui: Fix kubernetes auth method roles tab [GH-25999]
- ui: call resultant-acl without namespace header when user mounted at root namespace [GH-25766]
v1.14.12+ent
1.14.12 Enterprise
April 24, 2024
This release is created to share the Vault Enterprise changelog and notify consumers of availability. The attached source and assets do not include Vault Enterprise code and should not be used in place of official Docker images or binaries.
CHANGES:
- core: Bump Go version to 1.21.9.
- ui: Update dependencies including D3 libraries [GH-26346]
IMPROVEMENTS:
- activity (enterprise): Change minimum retention window in activity log to 48 months
- core: make the best effort timeout for encryption count tracking persistence configurable via an environment variable. [GH-25636]
- license utilization reporting (enterprise): Add retention months to license utilization reports.
- sdk/decompression: DecompressWithCanary will now chunk the decompression in memory to prevent loading it all at once. [GH-26464]
- ui: show banner instead of permission denied error when batch token is expired [GH-26396]
BUG FIXES:
- secrets/pki: fixed validation bug which rejected ldap schemed URLs in crl_distribution_points. [GH-26477]
- storage/raft (enterprise): Fix a bug where autopilot automated upgrades could fail due to using the wrong upgrade version
v1.14.11+ent
1.14.11 Enterprise
March 28, 2024
This release is created to share the Vault Enterprise changelog and notify consumers of availability. The attached source and assets do not include Vault Enterprise code and should not be used in place of official Docker images or binaries.
SECURITY:
- auth/cert: validate OCSP response was signed by the expected issuer and serial number matched request [GH-26091]
CHANGES:
- core: Bump Go version to 1.21.8.
IMPROVEMENTS:
- auth/cert: Allow validation with OCSP responses with no NextUpdate time [GH-25912]
- openapi: Fix generated types for duration strings [GH-20841]
- raft/snapshotagent (enterprise): upgrade raft-snapshotagent to v0.0.0-20221104090112-13395acd02c5
BUG FIXES:
- auth/cert: Address an issue in which OCSP query responses were not cached [GH-25986]
- auth/cert: Allow cert auth login attempts if ocsp_fail_open is true and OCSP servers are unreachable [GH-25982]
- core/login: Fixed a potential deadlock when a login fails and user lockout is enabled. [GH-25697]
- openapi: Fixing response fields for rekey operations [GH-25509]
- ui: Fix kubernetes auth method roles tab [GH-25999]
v1.16.2
[VAULT-26312] This is an automated pull request to build all artifact… …s for a release (#26587)
v1.16.1
1.16.1
April 04, 2024
Please note that Vault 1.16.1 is the first Enterprise release of the Vault Enterprise 1.16 series.
BUG FIXES:
- auth/ldap: Fix login error for group search anonymous bind. [GH-26200]
- auth/ldap: Fix login error missing entity alias attribute value. [GH-26200]
- cli: fixed a bug where the Vault CLI would error out if HOME was not set. [GH-26243]
- core: Only reload seal configuration when enable_multiseal is set to true. [GH-26166]
- secret/database: Fixed race condition where database mounts may leak connections [GH-26147]
v1.16.0
1.16.0
March 26, 2024
SECURITY:
- auth/cert: compare public keys of trusted non-CA certificates with incoming
client certificates to prevent trusting certs with the same serial number
but not the same public/private key. [GH-25649] - auth/cert: validate OCSP response was signed by the expected issuer and serial number matched request [GH-26091]
- secrets/transit: fix a regression that was honoring nonces provided in non-convergent modes during encryption. [GH-22852]
CHANGES:
- Upgrade grpc to v1.58.3 [GH-23703]
- Upgrade x/net to v0.17.0 [GH-23703]
- api: add the
enterprise
parameter to the/sys/health
endpoint [GH-24270] - auth/alicloud: Update plugin to v0.16.1 [GH-25014]
- auth/alicloud: Update plugin to v0.17.0 [GH-25217]
- auth/approle: Normalized error response messages when invalid credentials are provided [GH-23786]
- auth/azure: Update plugin to v0.16.1 [GH-22795]
- auth/azure: Update plugin to v0.17.0 [GH-25258]
- auth/cf: Update plugin to v0.16.0 [GH-25196]
- auth/gcp: Update plugin to v0.16.2 [GH-25233]
- auth/jwt: Update plugin to v0.19.0 [GH-24972]
- auth/jwt: Update plugin to v0.20.0 [GH-25326]
- auth/jwt: Update plugin to v0.20.1 [GH-25937]
- auth/kerberos: Update plugin to v0.10.1 [GH-22797]
- auth/kerberos: Update plugin to v0.11.0 [GH-25232]
- auth/kubernetes: Update plugin to v0.18.0 [GH-25207]
- auth/oci: Update plugin to v0.14.1 [GH-22774]
- auth/oci: Update plugin to v0.15.1 [GH-25245]
- cli: Using
vault plugin reload
with-plugin
in the root namespace will now reload the plugin across all namespaces instead of just the root namespace. [GH-24878] - cli:
vault plugin info
andvault plugin deregister
now require 2 positional arguments instead of accepting either 1 or 2. [GH-24250] - core (enterprise): Seal High Availability (HA) must be enabled by
enable_multiseal
in configuration. - core: Bump Go version to 1.21.8.
- database/couchbase: Update plugin to v0.10.1 [GH-25275]
- database/elasticsearch: Update plugin to v0.14.0 [GH-25263]
- database/mongodbatlas: Update plugin to v0.11.0 [GH-25264]
- database/redis-elasticache: Update plugin to v0.3.0 [GH-25296]
- database/redis: Update plugin to v0.2.3 [GH-25289]
- database/snowflake: Update plugin to v0.10.0 [GH-25143]
- database/snowflake: Update plugin to v0.9.1 [GH-25020]
- events: Remove event noficiations websocket endpoint in non-Enterprise [GH-25640]
- events: Source URL is now
vault://{vault node}
[GH-24201] - identity (enterprise): POST requests to the
/identity/entity/merge
endpoint
are now always forwarded from standbys to the active node. [GH-24325] - plugins/database: Reading connection config at
database/config/:name
will now return a computedrunning_plugin_version
field if a non-builtin version is running. [GH-25105] - plugins: Add a warning to the response from sys/plugins/reload/backend if no plugins were reloaded. [GH-24512]
- plugins: By default, environment variables provided during plugin registration will now take precedence over system environment variables.
Use the environment variableVAULT_PLUGIN_USE_LEGACY_ENV_LAYERING=true
to opt out and keep higher preference for system environment
variables. When this flag is set, Vault will check during unseal for conflicts and print warnings for any plugins with environment
variables that conflict with system environment variables. [GH-25128] - plugins:
/sys/plugins/runtimes/catalog
response will always include a list of "runtimes" in the response, even if empty. [GH-24864] - sdk: Upgrade dependent packages by sdk.
This includes github.com/docker/docker to v24.0.7+incompatible,
google.golang.org/grpc to v1.57.2 and golang.org/x/net to v0.17.0. [GH-23913] - secrets/ad: Update plugin to v0.16.2 [GH-25058]
- secrets/ad: Update plugin to v0.17.0 [GH-25187]
- secrets/alicloud: Update plugin to v0.16.0 [GH-25257]
- secrets/azure: Update plugin to v0.17.0 [GH-25189]
- secrets/gcp: Update plugin to v0.18.0 [GH-25173]
- secrets/gcpkms: Update plugin to v0.16.0 [GH-25231]
- secrets/keymgmt: Update plugin to v0.10.0
- secrets/kubernetes: Update plugin to v0.7.0 [GH-25204]
- secrets/kv: Update plugin to v0.16.2 [GH-22790]
- secrets/kv: Update plugin to v0.17.0 [GH-25277]
- secrets/mongodbatlas: Update plugin to v0.10.2 [GH-23849]
- secrets/mongodbatlas: Update plugin to v0.11.0 [GH-25253]
- secrets/openldap: Update plugin to v0.11.3 [GH-25040]
- secrets/openldap: Update plugin to v0.12.0 [GH-25251]
- secrets/openldap: Update plugin to v0.12.1 [GH-25524]
- secrets/terraform: Update plugin to v0.7.5 [GH-25288]
- telemetry: Seal wrap encrypt/decrypt metrics now differentiate between seals using a metrics label of seal name rather than separate metric names. [GH-23837]
- ui: Update icons to use Flight icons where available. [GH-24823]
- ui: add subnav for replication items [GH-24283]
FEATURES:
- Add Snapshot Inspector Tool: Add CLI tool to inspect Vault snapshots [GH-23457]
- Audit Filtering: Audit devices support expression-based filter rules (powered by go-bexpr) to determine which entries are written to the audit log. [GH-24558]
- Controlled Access to Unauthenticated Endpoints (enterprise): Gives admins more control over how unauthenticated endpoints in Vault can be accessed and in some cases what information they return. [GH-23547] [GH-23534] [GH-23740]
- Custom messages (enterprise): Introduces custom messages settings, allowing users to view, and operators to configure system-wide messages.
- Database Event Notifications: The database plugin now emits event notifications. [GH-24718]
- Default Lease Count Quota (enterprise): Apply a new global default lease count quota of 300k leases for all
new installs of Vault. [GH-24382] - Experimental Raft-WAL Option: Reduces risk of infinite snapshot loops for follower nodes in large-scale Integrated Storage deployments. [GH-21460]
- Manual License Utilization Reporting: Added manual license
utilization reporting, which allows users to create manual exports of product-license [metering
data] to report to Hashicorp. - Plugin Identity Tokens: Adds secret-less configuration of AWS secret engine using web identity federation. [GH-24987]
- Plugin Workload Identity (enterprise): Vault can generate identity tokens for plugins to use in workload identity federation auth flows.
- Quotas in Privileged Namespaces: Enable creation/update/deletion of quotas from the privileged namespace
- Reload seal configuration on SIGHUP: Seal configuration is reloaded on SIGHUP so that seal configuration can
be changed without shutting down vault [GH-23571] - Request Limiter (enterprise): Add adaptive concurrency lim...
v1.16.0-rc3
1.16.0-rc3
March 13, 2024
SECURITY:
- auth/cert: compare public keys of trusted non-CA certificates with incoming
client certificates to prevent trusting certs with the same serial number
but not the same public/private key. [GH-25649] - secrets/transit: fix a regression that was honoring nonces provided in non-convergent modes during encryption. [GH-22852]
CHANGES:
- Upgrade grpc to v1.58.3 [GH-23703]
- Upgrade x/net to v0.17.0 [GH-23703]
- api: add the
enterprise
parameter to the/sys/health
endpoint [GH-24270] - auth/alicloud: Update plugin to v0.16.1 [GH-25014]
- auth/alicloud: Update plugin to v0.17.0 [GH-25217]
- auth/approle: Normalized error response messages when invalid credentials are provided [GH-23786]
- auth/azure: Update plugin to v0.16.1 [GH-22795]
- auth/azure: Update plugin to v0.17.0 [GH-25258]
- auth/cf: Update plugin to v0.16.0 [GH-25196]
- auth/gcp: Update plugin to v0.16.2 [GH-25233]
- auth/jwt: Update plugin to v0.19.0 [GH-24972]
- auth/jwt: Update plugin to v0.20.0 [GH-25326]
- auth/kerberos: Update plugin to v0.10.1 [GH-22797]
- auth/kerberos: Update plugin to v0.11.0 [GH-25232]
- auth/kubernetes: Update plugin to v0.18.0 [GH-25207]
- auth/oci: Update plugin to v0.14.1 [GH-22774]
- auth/oci: Update plugin to v0.15.1 [GH-25245]
- cli: Using
vault plugin reload
with-plugin
in the root namespace will now reload the plugin across all namespaces instead of just the root namespace. [GH-24878] - cli:
vault plugin info
andvault plugin deregister
now require 2 positional arguments instead of accepting either 1 or 2. [GH-24250] - core: Bump Go version to 1.21.8.
- database/couchbase: Update plugin to v0.10.1 [GH-25275]
- database/elasticsearch: Update plugin to v0.14.0 [GH-25263]
- database/mongodbatlas: Update plugin to v0.11.0 [GH-25264]
- database/redis-elasticache: Update plugin to v0.3.0 [GH-25296]
- database/redis: Update plugin to v0.2.3 [GH-25289]
- database/snowflake: Update plugin to v0.10.0 [GH-25143]
- database/snowflake: Update plugin to v0.9.1 [GH-25020]
- events: Remove event noficiations websocket endpoint in non-Enterprise [GH-25640]
- events: Source URL is now
vault://{vault node}
[GH-24201] - identity (enterprise): POST requests to the
/identity/entity/merge
endpoint
are now always forwarded from standbys to the active node. [GH-24325] - plugins/database: Reading connection config at
database/config/:name
will now return a computedrunning_plugin_version
field if a non-builtin version is running. [GH-25105] - plugins: Add a warning to the response from sys/plugins/reload/backend if no plugins were reloaded. [GH-24512]
- plugins: By default, environment variables provided during plugin registration will now take precedence over system environment variables.
Use the environment variableVAULT_PLUGIN_USE_LEGACY_ENV_LAYERING=true
to opt out and keep higher preference for system environment
variables. When this flag is set, Vault will check during unseal for conflicts and print warnings for any plugins with environment
variables that conflict with system environment variables. [GH-25128] - plugins:
/sys/plugins/runtimes/catalog
response will always include a list of "runtimes" in the response, even if empty. [GH-24864] - sdk: Upgrade dependent packages by sdk.
This includes github.com/docker/docker to v24.0.7+incompatible,
google.golang.org/grpc to v1.57.2 and golang.org/x/net to v0.17.0. [GH-23913] - secrets/ad: Update plugin to v0.16.2 [GH-25058]
- secrets/ad: Update plugin to v0.17.0 [GH-25187]
- secrets/alicloud: Update plugin to v0.16.0 [GH-25257]
- secrets/azure: Update plugin to v0.17.0 [GH-25189]
- secrets/gcp: Update plugin to v0.18.0 [GH-25173]
- secrets/gcpkms: Update plugin to v0.16.0 [GH-25231]
- secrets/keymgmt: Update plugin to v0.10.0
- secrets/kubernetes: Update plugin to v0.7.0 [GH-25204]
- secrets/kv: Update plugin to v0.16.2 [GH-22790]
- secrets/kv: Update plugin to v0.17.0 [GH-25277]
- secrets/mongodbatlas: Update plugin to v0.10.2 [GH-23849]
- secrets/mongodbatlas: Update plugin to v0.11.0 [GH-25253]
- secrets/openldap: Update plugin to v0.11.3 [GH-25040]
- secrets/openldap: Update plugin to v0.12.0 [GH-25251]
- secrets/openldap: Update plugin to v0.12.1 [GH-25524]
- secrets/terraform: Update plugin to v0.7.5 [GH-25288]
- telemetry: Seal wrap encrypt/decrypt metrics now differentiate between seals using a metrics label of seal name rather than separate metric names. [GH-23837]
- ui: Update icons to use Flight icons where available. [GH-24823]
- ui: add subnav for replication items [GH-24283]
FEATURES:
- Add Snapshot Inspector Tool: Add CLI tool to inspect Vault snapshots [GH-23457]
- Audit Filtering: Audit devices support expression-based filter rules (powered by go-bexpr) to determine which entries are written to the audit log. [GH-24558]
- Controlled Access to Unauthenticated Endpoints (enterprise): Gives admins more control over how unauthenticated endpoints in Vault can be accessed and in some cases what information they return. [GH-23547] [GH-23534] [GH-23740]
- Custom messages (enterprise): Introduces custom messages settings, allowing users to view, and operators to configure system-wide messages.
- Database Event Notifications: The database plugin now emits event notifications. [GH-24718]
- Default Lease Count Quota (enterprise): Apply a new global default lease count quota of 300k leases for all
new installs of Vault. [GH-24382] - Experimental Raft-WAL Option: Reduces risk of infinite snapshot loops for follower nodes in large-scale Integrated Storage deployments. [GH-21460]
- Manual License Utilization Reporting: Added manual license
utilization reporting, which allows users to create manual exports of product-license [metering
data] to report to Hashicorp. - Plugin Identity Tokens: Adds secret-less configuration of AWS secret engine using web identity federation. [GH-24987]
- Plugin Workload Identity (enterprise): Vault can generate identity tokens for plugins to use in workload identity federation auth flows.
- Quotas in Privileged Namespaces: Enable creation/update/deletion of quotas from the privileged namespace
- Reload seal configuration on SIGHUP: Seal configuration is reloaded on SIGHUP so that seal configuration can
be changed without shutting down vault [GH-23571] - Request Limiter (enterprise): Add adaptive concurrency limits to
write-based HTTP methods and special-casepki/issue
requests to prevent
overloading the Vault server. [GH-25093] - Rotate Root for LDAP auth: Rotate root operations are now supported for the LDAP auth engine. [GH-24099]
- **Seal High Availability (...