NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2356 by repository stars
Last release 15 days ago
23 Sep 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 32 of 32 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
109 releases · first in 2023
One column per quarter.
Helm: fix invalid value name for telemetry.serviceMonitor.enabled (#786): GH-790
Fix:
Nothing published for this version
Important: this release contains CRD schema changes that must be applied manually when deploying VSO with Helm. Please see updating-crds for more deta
Important: this release contains CRD schema changes that must be applied manually when deploying VSO with Helm. Please see updating-crds for more details.
Behavioral changes:
Features:
Improvements:
Fix:
Build:
Dependency Updates:
VDS: reconcile instances on lifetimeWatcher done events and other Vault client rotation events: GH-665
Fix:
Improvements:
Build:
skips from the last release: GH-703Dependency Updates:
VDS: support configuring an explicit sync delay for non-renewable leases without an explicit TTL: GH-641
Improvements:
Fix:
Build:
Dependency Updates:
Nothing published for this version
Sync: mitigate potential schema validation failures by only adding finalizers after a status update: GH-609
Fix:
Dependency Updates:
Nothing published for this version
Upgrades via OperatorHub may fail due to some new required fields in VaultConnection and the Secret types as described in GH-631
KNOWN ISSUES:
Features:
Improvements:
Fix:
Build:
sdk-generate in CI: GH-590Dependency Updates:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
update go version to fix CVE-2023-45284,CVE-2023-39326,CVE-2023-48795: GH-541
Fix:
Dependency Updates:
Nothing published for this version
Include viewer and editor RBAC roles in the chart: GH-501
The previous flag for the manager --max-concurrent-reconciles-vds is now deprecated and replaced by --max-concurrent-reconciles which applies to all c…
Improvements:
controller.manager.maxConcurrentReconciles now applies to all Syncable Secret controllers. The previous flag for the manager --max-concurrent-reconciles-vds is now deprecated and replaced by --max-concurrent-reconciles which applies to all controllers. GH-483Fix:
vso to avoid subchart name collisions: GH-487Dependency Updates:
VaultAuth: Support for the GCP authentication method when using GKE workload identity: GH-411
Features:
Fix:
Dependency Updates:
UBI image: Include the tls-ca-bundle.pem from ubi-minimal: GH-415
Fix:
Important security update to address some Golang vulnerabilities GH-414
Handle invalid Client race after restoration: GH-400
Fix:
Dependency Updates:
Helm: bump the chart version and default tags to 0.3.1: GH-386
Fix:
VDS: Support for DB schedule-based static role rotations: GH-369
Improvements:
Features:
Revert:
Add support for HCP Vault Secrets: GH-315
Nothing published for this version
Helm: controller.imagePullSecrets stanza is added to provide imagePullSecrets to the controller's containers via the serviceAccount: GH-266
Improvements:
controller.imagePullSecrets stanza is added to provide imagePullSecrets to the controller's containers via the serviceAccount: GH-266controller.manager.resources values now also apply to the pre-delete-controller-cleanup-job. GH-280Changes:
v0.11.0 to v0.14.1: GH-267Bugs:
Nothing published for this version
Helm: Breaking Change Fix typos in values.yaml that incorrectly referenced approle roleid and secretName which should be appRole roleId and secretRef…
Improvements:
Changes:
approle roleid and secretName which should be appRole roleId and secretRef respectively under defaultAuthMethod and controller.manager.clientCache.storageEncryption: GH-257Helm: Breaking Change: Adds support for additional Auth Methods in the Transit auth method template: GH-226 To migrate, set Kubernetes specific auth m…
Features:
controller.manager.clientCache.storageEncryption
using the new stanza controller.manager.clientCache.storageEncryption.kubernetes.Improvements:
Build:
Changes:
Spec.Name with Spec.Path: GH-240Spec.Name with Spec.Role: GH-233controller.manager.clientCache.storageEncryption
has been moved to controller.manager.clientCache.storageEncryption.kubernetes.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
VaultPKISecret (VPS): Make Spec.OtherSANS a string slice (breaking change): GH-190
Bugs:
controller.kubernetesClusterDomain works as defined in values.yaml: GH-183vaultConnectionRef to controller.manager.clientCache.storageEncryption for transit auth method configuration and provide a default value which uses the default vaultConnection. GH-201Spec.AltNames, and Spec.IPSansare properly formatted for the Vault request: GH-130Spec.OtherSANS a string slice (breaking change): GH-190Spec.CACertSecretRef is relative to the connection's Namespace: GH-195Features:
Revoke field which will result in the dynamic secret lease being revoked on CR deletion. Note:
The VaultAuthMethod referenced by the VDS Secret must have a policy which provides ["update"] on sys/leases/revoke: GH-143 GH-209RenewalPercent field to control when a lease is renewed: GH-170Improvements:
Spec.Role with Spec.Path (breaking change): GH-172commonName optional: GH-160Spec.Version field to support fetching a specific kv-v2 secret version: GH-200Changes:
Spec.Role renamed to Spec.Path which can be set to any path supported by the
Vault secret's engine.Spec.OtherSANS takes a slice of strings like Spec.AltNames and Spec.IPSansNothing published for this version
* Initial Beta Release
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →