NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2356 by repository stars
Last release 15 days ago
23 Sep 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 32 of 32 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
109 releases · first in 2023
One column per quarter.
Remove HCP Vault Secrets (HVS) support. HVS reached end-of-life on July 1, 2026. The HCPAuth and HCPVaultSecretsApp CRDs, their controllers, credentia
BREAKING CHANGES:
HCPAuth and HCPVaultSecretsApp CRDs, their controllers, credentials provider, RBAC manifests, Helm chart assets, and the github.com/hashicorp/hcp-sdk-go dependency have all been permanently removed. Clusters with existing HCPVaultSecretsApp or HCPAuth resources must clean up those instances before upgrading to avoid resources becoming stuck in Terminating due to the finalizer hcpvaultsecretsapp.secrets.hashicorp.com/finalizer. (#1307)Enhancements:
spec.syncConfig.instantUpdates) for any Vault secret engine that supports Vault events, covering both static roles (allowStaticCreds=true) and dynamic leases: (#1295)X-Vault-Index header on event-triggered reconciles to prevent stale reads on Performance Standbys (Requires Vault 1.20+): (#1285)controller.rbac.enabled flag to allow skipping RBAC resource creation (ClusterRole, ClusterRoleBinding, Role, RoleBinding). When set to false, the chart still creates ServiceAccounts, the controller Deployment, and hook Jobs — equivalent RBAC must be pre-provisioned out-of-band by a cluster administrator using the same Helm release name (or fullnameOverride) before running helm install/helm upgrade. (#1291)Fix:
pki/issuer/<name>/<role> instead of the correct pki/issuer/<name>/issue/<role>, causing Vault to return 404 for all cert issuance requests when issuerRef was specified (#1336)rolloutRestartTargets being triggered on every reconcile for static roles consumed with allowStaticCreds: false; static-creds detection now uses Vault response metadata instead of spec.allowStaticCreds, so restarts only occur when the HMAC-compared credentials actually change (#1299)spec.namespace from the default VaultAuth and transit VaultAuth resources when no Vault namespace is configured, instead of rendering an empty namespace: key. Server-side apply deserialized the empty key as null, which failed CRD schema validation and blocked installs where Vault namespaces are not in use (#1319)RequeueAfter on Vault failures so resources are re-queued with backoff instead of being silently dropped after a transient Vault HA event (#1323)Build:
Dependency Updates:
Nothing published for this version
Nothing published for this version
Add ppc64le (IBM Power) architecture support: build and publish UBI-based images to icr.io/cpopen/ibm-vault and quay.io/redhat-isv-containers
Build:
ppc64le (IBM Power) architecture support: build and publish UBI-based images to icr.io/cpopen/ibm-vault and quay.io/redhat-isv-containers (#1325)chart-upgrade-tests matrix to cover the last 6 chart versions (1.1.0–1.5.0); drop stale entries 0.2.0–1.0.1Dependency Updates:
google.golang.org/api from 0.291.0 to 0.292.0 in the gomod-backward-compatible group (#1330)actions/setup-node from v6.4.0 to v7.0.0 in .github/workflows/build.yamlVaultAuth / VaultAuthGlobal AppRole spec.appRole.secretIDPath has been removed. Use spec.appRole.secretRef instead, which references a Kubernetes Secr
BREAKING CHANGES:
VaultAuth/VaultAuthGlobal AppRole spec.appRole.secretIDPath has been removed. Usespec.appRole.secretRef instead, which references a Kubernetes Secret containing the AppRoleDependency Updates:
Build:
Nothing published for this version
Test with Vault 2.0.3, 1.21.8, 1.20.13, 1.19.19
Build:
Dependency Updates:
Nothing published for this version
Detect TTL reset for uneven rotation schedules with ttl rollover bug:
Fix:
Dependency Updates:
Nothing published for this version
Add additional printer column fields:
Enhancements:
Fix:
Build:
Dependency Updates:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Suppress CVE-2025-6020 on the container only:
Fix:
Enhancements:
Build:
Dependency Updates:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add support for linux/s390x and linux/arm64 (Red Hat):
Enhancements:
Fixes:
Build:
Dependency Updates:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
VSS: rollout restarts were being executed erroneously GH-1126
Nothing published for this version
Add support for the VSO CSI Driver (Vault Enterprise only): GH-1098
Features:
Enhancements:
Fix:
Build:
Dependency Updates:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add Kubernetes Client QPS and Burst Configuration: GH-1013
Enhancements:
Fix:
Build:
Dependency Updates:
Memory: Prevent OOM due to large K8s Secrets cache: GH-982 GH-984
Fix:
Improvements:
Build:
Dependency Updates:
Nothing published for this version
Nothing published for this version
Add support for syncing HVS rotating secrets: GH-893 GH-889
Features:
Fix:
spec.timeout to be a string: GH-906Improvements:
Build:
Dependency Updates:
Nothing published for this version
Log build info on startup: GH-872
Improvements:
Fix:
Build:
Dependency Updates:
Helm: CRD schema changes are now automatically applied at upgrade time.
Important
Helm: CRD schema changes are now automatically applied at upgrade time.
See updating-crds for more details.
This release contains CRD schema changes which remove the field validation on most VaultAuth spec fields. That means invalid VaultAuth configurations will no longer be handled at resource application time. Please review the VSO logs and K8s events when troubleshooting Vault authentication issues.
Features:
Improvements:
Fix:
Build:
Dependency Updates:
Your coding agent can read these notes before it upgrades. Set up the MCP server →