NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2575 by repository stars
Last release 10 days ago
28 Sep 2026
Release timing varies
gaps range from 9 days to 3 months
Most releases are documented
notes for 15 of 20 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
68 releases · first in 2020
One column per quarter.
Nothing published for this version
TLS policy environment variables using the KEDA_HTTP_PROXY_TLS_* prefix are deprecated in favor of the corresponding KEDA_HTTP_TLS_* variables. The ol…
InterceptorRoute now supports staticRoutes for requests that should not trigger autoscaling, including health checks, redirects, and maintenance pages.
responseMode: WhenUnavailable forwards requests when the backend is ready and serves a static response otherwise.
responseMode: Always always serves the configured static response.
The interceptor can route requests directly to ready pod IPs instead of through the Service ClusterIP.
This can bypass kube-proxy and Service-layer behavior such as session affinity, topology-aware routing, and Service-level NetworkPolicy.
Cold-start pending requests can now be bounded per interceptor replica with coldStart.maxPendingRequests and coldStart.overflow.
Requests exceeding the limit receive 503 or the configured placeholder response.
The global KEDA_HTTP_COLD_START_MAX_PENDING_REQUESTS environment variable provides a default.
The interceptor now exposes interceptor_cold_start_duration_seconds with ready, timeout, and cancelled outcomes.
Request duration metrics also include a cold_start label, with histogram buckets extended to 300s.
The release adds custom CA support for outbound backend TLS, automatic serving-certificate reloads, and SLSA Build Level 2 provenance attestations for release and canary images.
KEDA_HTTP_PROXY_TLS_* prefix are deprecated in favor of the corresponding KEDA_HTTP_TLS_* variables.Full Changelog: v0.15.0...v0.16.0
actions/attest. Attestations are pushed to GHCR alongside images and can be verified with gh attestation verify oci://ghcr.io/kedacore/http-add-on-operator:<version> --owner kedacore (#1604)staticRoutes to InterceptorRoute for defining routes that should not trigger autoscaling, such as health checks, redirects, and maintenance pages. Supports responseMode: WhenUnavailable (forward to backend when ready, static response otherwise) and responseMode: Always (always serve static response) (#1622)KEDA_HTTP_DIRECT_POD_ROUTING environment variable (true | false, default true). When enabled, the interceptor routes requests directly to a ready pod IP instead of through the Service ClusterIP, bypassing kube-proxy and other Service-layer features (Service-level NetworkPolicy, session affinity, topology-aware routing). (#1473)KEDA_HTTP_TLS_CA_DIRS environment variable to trust custom CA bundles for outbound backend connections. (#1728)coldStart.maxPendingRequests and coldStart.overflow (Reject | Placeholder), plus a global KEDA_HTTP_COLD_START_MAX_PENDING_REQUESTS env var (default 0, unlimited). The limit applies per interceptor replica, so effective cluster-wide capacity scales with the replica count. Requests arriving when the limit is reached get 503 or the route's placeholder response, and are counted by the new interceptor.cold_start.rejections metric (#1732)interceptor_cold_start_duration_seconds histogram with ready, timeout, and cancelled outcomes to expose time spent waiting for scaled-from-zero backends to become ready (#1721)interceptor_request_duration_seconds buckets up to 300s (was 10s) and add a cold_start label to both interceptor_request_duration_seconds and interceptor_request_count_total, identifying requests that waited for backend readiness, including waits that ended before the backend became ready (#1776)ServerName per-dial via DialTLSContext, using the original service hostname captured in context, so SNI stays correct when the upstream URL is rewritten to a pod IP. (#1473)ReadyEndpointsCache now tracks full (ip, port) pairs per named port from EndpointSlices, enabling direct-pod routing (replaces the previous bool-only ready state). (#1473)TLS12/TLS13 TLS version format in addition to 1.2/1.3 for compatibility with KEDA and the operator (#1718)499 instead of 502 when the client cancels the request before the backend responds, so cancelled requests are no longer counted as backend failures (#1779)KEDA_HTTP_QUEUE_TICK_DURATION (minimum 250ms), so one unresponsive interceptor can no longer stall metric collection (#1730)requestRate with large window/granularity ratios (>2000) (#1692)KEDA_HTTP_PROXY_TLS_* to KEDA_HTTP_TLS_* (MIN_VERSION, MAX_VERSION, CIPHER_SUITES, CURVE_PREFERENCES, SKIP_VERIFY). Old names still work but log a deprecation warning. (#1718)Nothing published for this version
Nothing published for this version
Nothing published for this version
Old names still work but log a deprecation warning.
The interceptor now supports HTTP/2 (h2c and h2 over TLS), enabling autoscaling of gRPC workloads. Backend transport is selected based on the Kubernetes appProtocol field on the Service port (#1676): cleartext backends default to HTTP/1.1 unless appProtocol: kubernetes.io/h2c is set; TLS backends negotiate via ALPN.
The KEDA_HTTP_FORCE_HTTP2 environment variable has been removed — HTTP/2 is now negotiated automatically.
New coldStart.placeholder support lets you return static HTTP responses while a workload scales from zero, instead of holding the request until a pod is ready.
The scaler now tolerates partial interceptor pod failures instead of restarting on a single unreachable endpoint. Last-known concurrency is cached for unreachable pods to prevent underreporting.
The interceptor now drains in-flight requests before exiting. It waits for active handlers to complete (bounded by KEDA_HTTP_DRAIN_TIMEOUT), marks the readiness probe unhealthy immediately on SIGTERM, and delays listener closure by KEDA_HTTP_SHUTDOWN_DELAY to let Kubernetes propagate endpoint removal.
KEDAHTTP_OPERATOR_EXTERNAL_SCALER_SERVICE and KEDAHTTP_OPERATOR_EXTERNAL_SCALER_PORT have been renamed to KEDA_HTTP_OPERATOR_EXTERNAL_SCALER_SERVICE and KEDA_HTTP_OPERATOR_EXTERNAL_SCALER_PORT. Old names still work but log a deprecation warning. (#1623)Full Changelog: v0.14.0...v0.15.0
coldStart.placeholder support for returning static HTTP responses during scale-from-zero (#874)appProtocol instead of mirroring the client's protocol. Cleartext backends default to HTTP/1.1 unless the Service port sets appProtocol: kubernetes.io/h2c; TLS backends negotiate via ALPN (#1676)KEDA_HTTP_DRAIN_TIMEOUT), marks the readiness probe unhealthy immediately on SIGTERM, and delays listener closure by KEDA_HTTP_SHUTDOWN_DELAY to let Kubernetes propagate endpoint removal. (#1636)KEDA_HTTP_FORCE_HTTP2 environment variable. This is not a breaking change — HTTP/2 is now negotiated automatically. (#1084)KEDAHTTP_OPERATOR_EXTERNAL_SCALER_SERVICE and KEDAHTTP_OPERATOR_EXTERNAL_SCALER_PORT environment variables to KEDA_HTTP_OPERATOR_EXTERNAL_SCALER_SERVICE and KEDA_HTTP_OPERATOR_EXTERNAL_SCALER_PORT. Old names are still accepted but log a deprecation warning and will be removed in a future release. (#1623)HTTPScaledObject remains supported but is now deprecated — a warning is logged per resource to guide migration.
Default timeout behavior has been redesigned. KEDA_HTTP_REQUEST_TIMEOUT now defaults to 0 (disabled), KEDA_HTTP_RESPONSE_HEADER_TIMEOUT defaults to 300s (was 500ms), and KEDA_HTTP_READINESS_TIMEOUT defaults to 0 (disabled, was 20s). Timeout errors now return 504 instead of 502.
The following environment variables have been removed: KEDA_HTTP_TLS_HANDSHAKE_TIMEOUT, KEDA_HTTP_EXPECT_CONTINUE_TIMEOUT, KEDA_HTTP_KEEP_ALIVE, KEDA_HTTP_IDLE_CONN_TIMEOUT, KEDA_HTTP_DIAL_RETRY_TIMEOUT. These now use Go's DefaultTransport defaults.
Metrics now use bounded labels: path/host replaced by route_name/route_namespace, and non-standard HTTP methods are normalized to _OTHER. Metrics have also been renamed to follow OTel semantic conventions: interceptor_requests_total → interceptor_request_count_total, interceptor_pending_requests → interceptor_request_concurrency. Dashboards must be updated.
The documentation has been completely rewritten and now lives at keda.sh/http-add-on. It features versioned docs, improved navigation, a quick start and guides for different personas (developers, cluster operators). The legacy in-repo docs have been removed.
A new InterceptorRoute CRD separates routing/interceptor configuration from scaling configuration. HTTPScaledObject remains supported but is now deprecated — a warning is logged per resource to guide migration.
See the user guide and the migration guide for details.
InterceptorRoute supports per-route timeouts via the timeouts spec with request, responseHeader, and readiness fields. When unset, global env var defaults are used.
The new httpscaledobject.keda.sh/orphan-scaledobject annotation lets you preserve the auto-created ScaledObject when deleting an HTTPScaledObject during migration to InterceptorRoute, avoiding scaling gaps.
Full Changelog: v0.13.0...v0.14.0
KEDA_HTTP_REQUEST_TIMEOUT) defaults to 0 (disabled), response header timeout (KEDA_RESPONSE_HEADER_TIMEOUT → KEDA_HTTP_RESPONSE_HEADER_TIMEOUT) defaults to 300s (was 500ms), and readiness timeout (KEDA_CONDITION_WAIT_TIMEOUT → KEDA_HTTP_READINESS_TIMEOUT) defaults to 0 (disabled, was 20s). Timeout errors return 504 instead of 502. (#1474)path/host labels replaced by route_name/route_namespace; non-standard HTTP methods normalized to _OTHER; dashboards must be updated (#1559)KEDA_HTTP_TLS_HANDSHAKE_TIMEOUT, KEDA_HTTP_EXPECT_CONTINUE_TIMEOUT, KEDA_HTTP_KEEP_ALIVE, KEDA_HTTP_IDLE_CONN_TIMEOUT, and KEDA_HTTP_DIAL_RETRY_TIMEOUT environment variables; these now use Go's DefaultTransport defaults. (#1474)interceptor_requests_total → interceptor_request_count_total, interceptor_pending_requests → interceptor_request_concurrency, interceptor_request_duration_seconds unchanged (#1589)InterceptorRoute CRD to separate routing/interceptor config from scaling config; HTTPScaledObject remains supported but will be deprecated in a future release (#1501)timeouts spec with request, responseHeader, and readiness fields. When unset, global env var defaults are used. When a fallback service is configured and no readiness timeout is set, it defaults to 30s. (#1474)httpscaledobject.keda.sh/orphan-scaledobject annotation to preserve ScaledObjects during HTTPScaledObject-to-InterceptorRoute migration (#1593)OTEL_TRACES_SAMPLER and OTEL_TRACES_SAMPLER_ARG for trace sampling configuration (#1534)/metrics path only, matching the Prometheus scrape convention (#1591)KEDA_CONDITION_WAIT_TIMEOUT and KEDA_RESPONSE_HEADER_TIMEOUT environment variables in favor of KEDA_HTTP_READINESS_TIMEOUT and KEDA_HTTP_RESPONSE_HEADER_TIMEOUT. Old vars take precedence when set and log deprecation warnings. (#1474)Nothing published for this version
fix: replace deprecated release asset upload actions by @linkvt in #1490
Full Changelog: v0.12.2...v0.13.0
scalingMetric/targetValue instead of deprecated targetPendingRequests (#1536)roundToNDigits using math.Round instead of math.Floor to correctly round small negative floating-point errors to zero (#1483)KEDA_HTTP_ENDPOINTS_CACHE_POLLING_INTERVAL_MS and hardcode EndpointSlice informer resync to 60m (#1485)KEDA_HTTP_SCALER_DEPLOYMENT_INFORMER_RSYNC_PERIOD env var (#1533)CurrentNamespace field and KEDA_HTTP_CURRENT_NAMESPACE env var from interceptor config (#1484)Interceptor health probe endpoints moved to the admin port ( 9090 ). No action needed if using the Helm chart. If you use custom external health check
9090). No action needed if using the Helm chart. If you use custom external health checks (e.g., GCP HealthCheckPolicy), update them to target port 9090 for /readyz and /livez.KEDA_HTTP_DIAL_RETRY_TIMEOUT (#1449)Full Changelog: v0.12.1...v0.12.2
Nothing published for this version
chore: cleanup old docs and examples by @linkvt in #1430
Full Changelog: v0.12.0...v0.12.1
X-Forwarded-Proto and X-Forwarded-Host headers from upstream proxies (#1432)chore: fix devcontainer build by updating deprecated Go tools by @linkvt in #1384
You must update the HTTPScaledObject CRD before upgrading the operator. The .status.conditions field now uses the standard Kubernetes metav1.Condition format.
If you have tooling that parses HTTPScaledObject conditions, update it to expect standard fields (lastTransitionTime, observedGeneration).
This fixes duplicate Ready conditions that caused issues with GitOps tools like ArgoCD and Flux.
Use wildcard patterns like *.example.com to match any subdomain with a single HTTPScaledObject.
spec:
hosts:
- "*.example.com" # matches foo.example.com, bar.foo.example.com, etc.Route requests to different backends based on HTTP headers. Multiple HTTPScaledObjects can now match the same host and path with different header requirements.
apiVersion: http.keda.sh/v1alpha1
kind: HTTPScaledObject
spec:
hosts:
- api.example.com
headers:
- name: X-API-Version
value: v2
scaleTargetRef:
name: api-v2The interceptor now uses significantly less memory under load, with reduced memory growth over time. Latency is also improved for high-throughput workloads.
Bidirectional streaming now works correctly - response bodies can start streaming while request bodies are still being sent.
Request logging in the interceptor is now optional. Disable it to reduce log volume in high-traffic environments.
Full Changelog: v0.11.1...v0.12.0
metav1.Condition type (#1409)None
Update Kubernetes compatibility documentation to include v1.33, v1.34, and v0.11.0 release by @Copilot in #1349
Full Changelog: v0.11.0...v0.11.1
chore(deps): bump the all-updates group with 4 updates by @dependabot [bot] in #1263
Full Changelog: v0.10.0...v0.11.0
v1.Endpoints to discoveryv1.EndpointSlices (#1297)Nothing published for this version
Nothing published for this version
General : Fix infrastructure crashes when deleting ScaledObject while scaling
Full Changelog: v0.9.0...v0.10.0
General : Drop support for deprecated field spec.scaleTargetRef.deployment
We are happy to release KEDA HTTP Add-on v0.9.0 🎉
spec.scaleTargetRef.deployment (#1061)Full Changelog: v0.8.0...v0.9.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
You can find all deprecations in this overview and join the discussion here.
You can find all deprecations in this overview and join the discussion here.
targetPendingRequests in favor of spec.scalingMetric.*.targetValue (#959)Nothing published for this version
Nothing published for this version
Nothing published for this version
You can find all deprecations in this overview and join the discussion here.
/scale subresource (#438)You can find all deprecations in this overview and join the discussion here.
New deprecation(s):
KEDA_HTTP_DEPLOYMENT_CACHE_POLLING_INTERVAL_MS in favor of KEDA_HTTP_ENDPOINTS_CACHE_POLLING_INTERVAL_MS (#438)Nothing published for this version
Nothing published for this version
You can find all deprecations in this overview and join the discussion here.
name & app custom labels (#717)You can find all deprecations in this overview and join the discussion here.
New deprecation(s):
host field deprecated in favor of hosts in HTTPScaledObject (#552)Nothing published for this version
Nothing published for this version
You can find all deprecations in this overview and join the discussion here.
None.
HTTPScaledObject (#552)You can find all deprecations in this overview and join the discussion here.
New deprecation(s):
host field deprecated in favor of hosts in HTTPScaledObject (#552)Previously announced deprecation(s):
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →