OpenBao Rust Crate 0.14.0 #19
Closed
eldryoth
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
OpenBao Rust SDK 0.14.0 Release Notes
Version
Summary
0.14.0is the system backend completion line. It adds operator-gatedgenerate-root, generate-recovery-token, decode-token, legacy recovery-key
rekey, and in-flight request inspection helpers, plus ungated password policy
and resultant ACL helpers.
Added
0.14.0release line.recovery-key rekey helpers behind
operator-opsplusoperator-ops-acknowledged.feature gate. Generated passwords return
SecretString.internal-endpoint stability caveat and conservative capability maps.
helper with
SecretStringtoken accessors and bounded response maps.with operator ceremony types still gated by
operator-ops.internal counters, and internal request inspection rejected for stable scope.
2.5.xendpoint matrix. It now records643documented rows,
597/643strict typed or operator-gated coverage, and zeroplannedordecisionrows.Security Notes
operator-opsplusoperator-ops-acknowledged.generated passwords, and token accessors must be stored as
SecretStringand redacted from
Debug.stability caveats.
lease count query validation, Raft snapshot request bounds, and Raft peer path
construction. The local
PENTEST.mdreport was deleted before commit.residual for the ephemeral AES key; HSM or audited-boundary wrapping remains
the recommended path for high-assurance deployments.
decode categories from user-facing errors, tightened RADIUS host validation,
and added post-write verification for non-CAS bootstrap convergence paths.
The local second
PENTEST.mdreport was deleted before commit.them to callers, moves retry jitter to direct OS randomness, adds
acknowledgment gates for
transit-importandsensitive-http-test-only, andstrengthens documentation for TLS revocation limits, RADIUS suitability,
tracing path-shape metadata, Transit request-body residuals, and BYOK
software wrapping residuals. The local third
PENTEST.mdreport was deletedbefore commit.
Security And Stability Gate
scripts/release_0_14_gate.shscripts/openbao_integration.shtagging
v0.14.0.This discussion was created from the release OpenBao Rust Crate 0.14.0.
Beta Was this translation helpful? Give feedback.
All reactions