SPIRE
v1.15.3Security2026년 8월 21일
새로운 attestor와 플러그인, 설정 옵션, CLI 및 API 기능이 추가됐고 동작 변경과 의존성 업데이트, 결함 수정이 포함됐습니다. 보안 권고나 명시적인 취약점 관련 내용은 없습니다.
그 외 기록된 변경 22건 전체additions 10 · value changes 6 · fixes 5 · constraints 1
additions (10)
- - Slurm workload attestor (#7160)
- -
azure_blobBundlePublisher plugin for publishing the trust bundle to Azure Blob Storage (#7030) - -
trust_bundle_spiffe_workload_apiagent configuration option to fetch the initial trust bundle from a Workload API endpoint, simplifying nested agent deployments (#7148) - -
disable_workload_apianddisable_sds_apiagent options to disable the Workload API and SDS APIs on the public endpoint (#7122) - -
disable_kubelet_clientoption for thek8sworkload attestor (#7142) - -
use_pod_uid_for_agent_idoption in thek8s_psatnode attestor to derive agent IDs from pod UIDs instead of node UIDs (#7123) - - Opt-in
enable_namespace_labelsoption in thek8sworkload attestor, producingns-labelselectors from namespace labels (#7094) - -
account_list_fileoption in theaws_iidnode attestor to source theverify_organizationaccount list from a file instead of the AWS Organizations API (#7092) - -
debug getinfocommand in thespire-serverandspire-agentCLIs to access the Debug APIs (#7133) - - Incremental WIT-SVID work, including support for building WIT-SVIDs in the
svid.API client and marshalling support for WIT-SVID keys (#7132, #7134)v1
value changes (6)
- - The Broker API endpoint is now included in health checks when enabled (#7141)
- - Improved coordination of kubelet pod list fetching in the
k8sworkload attestor, reducing attestation latency and redundant kubelet requests (#7085) - - The agent now warns when the
memoryKey Manager is used with a node attestor that does not support re-attestation (#7139) - - Reworded the OIDC Discovery Provider
allow_insecure_schemewarning to describe the actual safety condition instead of implying development-only use (#7165) - - Updated AWS CA certificates in the
aws_iidnode attestor (#7138) - - Updated Go to 1.26.6 (#7188, #7212)
fixes (5)
- - The events-based cache now fetches events ordered by ID, preventing spurious skipped-event tracking and unnecessary event lookups at startup (#7189)
- - Agent telemetry sinks now start before node attestation, so metrics are served while the agent is still attesting (#7166)
- - The agent and server no longer log a crash message and exit with a non-zero status when shut down during startup (#7154)
- - The
hashicorp_vaultKey Manager plugin no longer triggers unrecognized parameter warnings in Vault and OpenBao audit logs (#7150) - - The example Grafana dashboard no longer includes empty query targets that caused panel query errors (#7178)
constraints (1)
- - The
gcp_kmsKey Manager plugin no longer requireskey_identifier_valueto be 36 characters long (#7140)
SPIRE 스택에 추가
조치가 필요한 변경이 나오면 주간 메일로 받아볼 수 있습니다. 이번 릴리스처럼 조치가 없는 주에는 메일을 보내지 않습니다.