v0.20.0
🚀 Release 0.20.0
0.20.0 (2026-07-14)
Bug Fixes
- admin: enhance populateRealmName tests for default behavior (#467) (edd48fa)
- common-server: "scopes" → "scope" JWT claim rename (#488) (37fb583)
- file-manager: allow tls-insecure for buckets (#436) (67f5169)
- improve failover handling; add mesh-flag to routing-config (#466) (bd1134a)
- organization: use secure generate-secret function for team-user (#456) (64de706)
- secret-manager: harden k8s onboarder (#438) (ddee2fc)
Features
- align condition handling and improve rover-server status determination (#414) (6242df2)
- cpapi: add deployment derived Gateway URLs (#429) (7e79289)
- cpapi: project and query Approval.Spec.ExpiresAt and Team.Spec.DisplayName + Description (#443) (5cddae0)
- cpapi: project and query EventExposure + EventSubscription (#444) (218801d)
- cpapi: project and query missing Application, ApiExposure & ApiSubscription fields (#431) (648cc2f)
- cpapi: security hardening, disable mock auth, add JWT (#454) (996ebaf)
- enforce team api category (#432) (923d113)
- event: add category to all event resources (#468) (77c5abd)
- harden deployment config especially securityContext (#457) (022acf8)
- local-setup: deploy step of the script can be custom (#455) (6b3dd19)
- projector-expired-filter: internal state Expired is filtered by (#434) (132a0fa)
- restructure gateway integration and admin-bootstrapping; improved failover features (#435) (4692c0a)
- rover: Added Team watch to Rover (#428) (0220563)
- security: require tokenRequest and grantType for external IDP (#439) (7e25c80)
- team-user-ns-migration: team user is now in the same namespace as (#433) (e56bb76)
✨🎉