| - Faster availability after restart + Pending | -GA | +Pending |
- Identity loading on restart is up to 40% faster and Vault logs include new
- diagnostic information to troubleshoot cluster slowness with the
- `post_unseal_trace_directory` configuration setting.
+ Pending
- Learn more: `post_unseal_trace_directory` parameter details - |
-
| - Raft integrated storage - | -ENHANCED | -- Corrects a previous issue with Raft nodes generating stale data by - preventing stale nodes from servicing requests to the cluster. + Learn more: TDB |
| Description | +|||
|---|---|---|---|
| - Identity + Pending | -ENHANCED | +Pending |
- Opt-in resolution of accidental duplicates in the identity system with a
- gated feature to force deduplication.
+ Pending
- Learn more: Find and resolve duplicate Vault identities - |
-
| - Autopilot - | -ENHANCED | -
- Improved upgrade stability with better cluster leadership reconciliation.
- - Learn more: Autopilot overview - |
- |
| - Database support - | -ENHANCED | -
- Onboard static database accounts without immediate rotation, precise
- timing, or coordinating with maintenance windows.
- - Learn more: Onboarding static DB users - |
- |
| - Events - | -ENHANCED | -- Vault now sends event notifications to subscribers on all Vault nodes - within a cluster. - | -|
| ENHANCED | -- Notification subscriptions for secret deletion no longer requires a root - token. - | -||
| - Plugin support - | -ENHANCED | -- Run Vault Enterprise plugins external to Vault. Running plugins externally - is useful in deployments when the plugin requires different environment - variable values than the Vault binary. - | -|
| - Automated root credential rotation - | -GA | -- Use a rotation manager to regularly rotate credentials for - AWS ( - secrets, - - authN - ), - Azure ( - secrets, - - authN - ), - GCP ( - secrets, - - authN - ), - LDAP ( - secrets, - - authN - ), - and DB plugins - - without manual intervention. - | -|
| - AWS plugin - | -ENHANCED | -
- Vault now supports AWS static role credentials for multiple AWS accounts
- with a single mount path to better manage AWS credentials at scale.
- - Learn more: STS AssumeRole - |
- |
| - GUI support for WIF plugin configuration - | -GA | -- Use the Vault GUI to enable and configure WIF with - AWS, - Azure, and - GCP - | -|
| - PKI: Constrained CA support - | -GA | -
- Use the PKI plugin to instantiate intermediate CAs with customer defined
- constraints (permitted URI , IPs, excluded DNS, etc.) and delegate PKI
- administration.
- - Learn more: PKI plugin API + Learn more: TDB + |
+
| Release | +Update | +Description | +
|---|---|---|
| + Pending + | +Pending | +
+ Pending
+ + Learn more: TDB + |
+
| Release | +Update | +Description | +
|---|---|---|
| + Pending + | +Pending | +
+ Pending
+ + Learn more: TDB + |
+
| Release | +Update | +Description | +
|---|---|---|
| + Pending + | +Pending | +
+ Pending
+ + Learn more: TDB + |
+
| Release | +Update | +Description | +
|---|---|---|
| + Pending + | +Pending | +
+ Pending
+ + Learn more: TDB + |
+
| Release | +Update | +Description | +
|---|---|---|
| + Pending + | +Pending | +
+ Pending
+ + Learn more: TDB |