Skip to content

2609 Update

Latest

Choose a tag to compare

@joshgrayscale joshgrayscale released this 02 Oct 17:03
200f445

AIO2609 Public Release Notes

Release date: September 2026

Release type: Patch

Current GA version: 2609 · Version history

Azure IoT Operations 2609 adds general availability support for Red Hat OpenShift Container Platform and delivers reliability and security fixes for industrial connectors, MQTT messaging, state store workloads, and deployment workflows. It improves connector continuity, broker recovery under memory pressure, configuration validation, media clip storage, and managed identity protection.


Release Highlights

  • Red Hat OpenShift Container Platform support now generally available: Deploy Azure IoT Operations on Red Hat OpenShift Container Platform (x86_64). Supported environments | Prepare your cluster

  • MQTT broker resilience: Broker recovery and state store processing now remain available when durable client state exceeds a reconnecting client's in-flight limit, when long-lived state entries use time-to-live settings, and when response memory is under pressure.

  • Connector continuity: OPC UA connector deployments no longer restart unnecessarily after supervisor restarts, and heartbeat monitoring no longer grows memory while an OPC UA server is offline.

  • Media clip storage: Media connector MP4 and MKV clip tasks can now complete when writing to filesystem-backed persistent storage.

  • Stronger MQTT configuration validation: MQTT Connector configuration now enforces safe source-to-destination mappings, and authenticated access.

  • Deployment reliability: Deployments that disable OPC UA now complete without waiting for an unused connector template.

  • Security hardening: This release strengthens shared-subscription authorization and managed identity authentication for transform artifact registries.

  • Deployment Image List (DIL): Download the DIL for this release to support dependency scanning and private-registry mirroring. Download the DIL for this release | How to mirror images to a private registry

Upgrade recommended if you use OPC UA, Media, REST or SSE connectors; MQTT shared subscriptions; long-lived state store entries; persisted MQTT sessions; transform artifact registries with managed identity; or deployments that disable OPC UA. This release contains reliability, validation, observability, and security fixes across these scenarios.

Upgrade to 2609 from any supported GA version to receive the latest deployment and runtime reliability improvements. Staying current is recommended for continued support and reliability.

Version support: Azure IoT Operations 2609 continues the 1.4.x minor version series. Under the N-2 version support policy, the supported versions remain 1.4.x, 1.3.x, and 1.2.x. The 1.1.x series is no longer supported. Customers still on 1.1.x should upgrade to remain eligible for Azure support.


Known Issues

For the full list of active known issues, see Known Issues.

  • Fixed in this release: MQTT shared-subscription authorization no longer allows a topic wildcard to match shared-subscription topics outside its intended scope.

Components Overview

This release improves OPC UA, MQTT, Media, REST, and SSE connectors; strengthens MQTT broker recovery and state store memory handling; corrects deployment behavior when OPC UA is disabled; removes obsolete metrics from the sample monitoring dashboard; and hardens authorization and managed identity use.


Connectors

OPC UA

Fixes

  • Stable connector deployment names: Supervisor restarts could generate different names for long secret-volume identifiers and trigger a rollout of every affected connector pod, interrupting asset telemetry. Generated names are now stable across restarts, preventing these unnecessary rollouts.

  • Heartbeat memory usage: Heartbeat monitoring could steadily consume memory while a monitored OPC UA server was offline. Monitoring now releases resources correctly while the server is unavailable.

For configuration guidance, see OPC UA connector.

MQTT

Improvements

  • Publish-loop prevention: Configurations that use the built-in MQTT broker now reject an identical source and destination topic, preventing circular publish loops.

Breaking Changes

  • MQTT connector authentication validation: MQTT connector configurations now reject anonymous authentication for external brokers. Existing deployments that rely on anonymous authentication must be updated to use a supported authentication mechanism before upgrading.

Media

Fixes

  • clip-to-fs .wav file generation: clip-to-fs tasks supports audio-only .wav file generation.
  • -to-fs task destination: 'snapshot-to-fs' and 'clip-to-fs' tasks do respect an Asset's defaultStreamsDestinations' storage path configuration.
  • snapshot and clip filenames: Snapshot and clip files now use stable UTC timestamp-based names
    • Snapshots: snapshot_YYYYMMDD-HHMMSS-NNNNNNNNNZ.<ext>
    • Clips: clip_YYYYMMDD-HHMMSS-000000000Z_<duration>s.<ext>
  • Duplicate task starts no longer interrupt active work. Repeated start management calls for clip, snapshot, or stream tasks are ignored while the task is already running, rather than cancelling and restarting it.
  • Filesystem clip output: MP4 and MKV clip capture could start but fail when handing the completed clip to filesystem-backed persistent storage. Clip tasks can now write completed files to the configured destination.
  • Asset deletion now stops associated tasks. Deleting an Asset or device endpoint cleans up remaining data-operation tasks and management-action handlers, preventing orphaned workloads.
  • FFmpeg task cleanup was improved. Task cancellation and panic handling were hardened to reduce the risk of orphaned FFmpeg processes.

Messaging and MQTT

Fixes

  • Persisted session recovery: Broker recovery could repeatedly restart while restoring durable client state that contained more unacknowledged messages than the reconnecting client's current in-flight limit. Recovery now restores the state safely while continuing to enforce flow control for new messages.

  • State store time-to-live memory: State entries with long time-to-live values could retain request buffers until expiry, eventually causing memory backpressure and rejecting unrelated publishes. State store processing now releases the request buffer after copying the entry into state store memory.

  • State store responses under pressure: Completing a state store operation could restart a broker backend when response memory crossed its allocation threshold after the operation was accepted. Accepted operations and notifications can now complete while existing backpressure continues to reject new work at the configured threshold.

  • Shared-subscription authorization: Subscription authorization could apply a wildcard match to shared-subscription topics and grant unintended message access. Shared-subscription topics now receive the required authorization handling.


Azure IoT Operations CLI

Fixes

  • Deployments with OPC UA disabled: Creating an Azure IoT Operations instance with OPC UA disabled could wait indefinitely because the deployment still included an OPC UA connector template. The template is now omitted when OPC UA is disabled, allowing the deployment to complete.

For full changelog, see Releases · Azure/azure-iot-ops-cli-extension.


Observability

Fixes

  • Sample dashboard metrics: The sample Grafana dashboard no longer includes obsolete discovered-asset and discovered-device metrics that are not emitted by current releases.

Security

Fixes

  • Transform artifact registry authentication: Managed identity authentication for transform artifact registries now validates the destination before requesting and transmitting credentials, preventing tokens from being sent to untrusted endpoints.

For more information, see the Azure IoT Operations documentation.