v0.6.0
Released September 30, 2026. Supported until March 30, 2027.
v0.6.0 ships 20 behavior changes, 4 security updates, 16 new features, and 13 bug fixes. Behavior between the management plane and the data plane changed in this release. The most severe security issue cleared is high.
A fully detailed version of these release notes (including artifact versions) is included in the Admin Console.
Click here to learn how to bring up the full release notes.
Upgrade and rollback
- No breaking changes. No operator action is required before upgrading.
- The upgrade rolls through without dropping traffic.
- Rollback to v0.5.1 is unconditional.
Behavior changes
Management plane API
GetProvider and the provider writes now also accept a platform role binding that grants the providers permission, such as platform_provider_admin.
Organization API keys can now manage roles, role assignments, groups and Team access groups through the management API, and existing admin keys get this without being reissued.
A fallback-policy write sent with a project is now refused unless its target stays inside that project: the organization-wide default (a CUSTOMER target), tag-targeted legacy policies, and any key or project outside it are rejected, even for an organization administrator.
Listing attribute-routing policies for a project now requires the user's own attribute_routing_policies.read grant on that project.
Corporate SSO sign-in through the management API now decides the first administrator the same way the auth service does: an administrator named by CORPORATE_ADMIN_EMAIL becomes a super admin, and the first-administrator seat is taken once per deployment without promoting the next person when an administrator already exists.
On a deployment that shares one auth database across customers (RBAC_AUTH_DB_MODE=shared), corporate SSO no longer seats the first sign-in as an administrator, matching the auth service: the first-user shortcut cannot tell tenants apart in a shared database.
A fallback policy now rejects an unsupported retry_on value with a clear message instead of silently storing it.
Latency metrics (response_latency, ttft, tpot and the guardrail latency metrics) now return an empty summary, and the metric catalog reports an empty function for them: the per-window average they carried was not a true average and is no longer computed.
Consoles
The Providers page shows providers read-only to users without catalog admin (platform_provider_admin).
Corporate sign-in now runs inside the Developer Console and the Admin Console instead of handing off to the auth service, and a failed sign-in shows the reason on the console's own page.
The consoles now validate the signed-in session against the platform's identity service rather than the auth service.
The management plane charts now fill in the corporate sign-in callback URL and the browser sign-in origins from the deployment domain, so a standard install no longer sets them by hand.
Gateway
A change to the proxy settings on the management plane now reaches data planes that serve project gateways.
tare CLI
tare install and tare upgrade now use Gateway API channel markers on the cluster's CRDs to avoid replacing standard-channel or managed-addon CRDs.
A release tag's chart tree now carries this release's real image tags.
Helm charts
Installing or upgrading the data plane with Helm, Argo CD or Flux now stops when the cluster's Gateway API CRDs are older than the version this release is tested against, matching what tare install and tare upgrade already do.
Auth
Tenant-scoped requests now use the organization selected by the active session instead of the user's home organization.
Release process
Promotion now refuses a candidate whenever it can be shown not to contain the previous release, for instance when that release is on the main line, or when the candidate predates the release branch it was cut from, instead of warning and continuing.
The scheduled release-upgrade canary now runs every 12 hours.
Observability
The management plane's DPO observability stack moves to a newer build.
Security updates
Management plane API
A service account token can no longer carry the claims that name the user or API key a request acts as, or the project a request is bound to.
Platform administrator access now requires a platform role binding.
Consoles
In the Admin Console, a write role on an Organization no longer grants administrator access to platform-wide operations, such as changes to the global provider and model catalog.
Gateway
The data plane's OTLP/gRPC log exporters, for request logs and guardrail events, now apply the CA and client certificate set through the OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, _CLIENT_CERTIFICATE and _CLIENT_KEY environment variables (GO-2026-6508).
New features
Gateway
Speech-to-text requests to /v1/audio/transcriptions are now routed to OpenAI-compatible backends; request logs keep the form fields, not the audio. Available once the data plane is on 0.6.0 or later.
Gateway authentication policies now verify identity-provider tokens at the gateway, including providers from every project attached to a shared gateway. Available once the data plane is on 0.6.0 or later.
One gateway can now carry several trusted identity providers, each with its own key source and its own accepted audiences. Available once the data plane is on 0.6.0 or later.
A gateway auth policy can require scopes from a trusted identity provider. Available once the data plane is on 0.6.0 or later.
Management plane API
Provider reads have a new field, has_credential: true when the provider's platform key is stored, false when it is not, and unset when the check could not run (the read still succeeds).
CreateProvider adds a provider and returns AlreadyExists if the id is taken, and DeleteProviderCredential removes a provider's platform key.
UpsertProvider has a new field, remove_metadata_keys, that removes the named top-level keys from the provider's metadata.
The management API can now store gateway authentication policies and the rules that map a verified identity onto a caller.
Project gateway attachments now record accepted_credentials; existing attachments read API_KEY.
Attribute-routing policies now report their routing decisions over a selected lookback period.
Attribute-routing policies can now be listed across the whole organization by leaving out project_id, with each policy naming the project it applies to.
Attribute-routing policies now report rule_count and distinct_destination_model_count on every read, including the list, so a list can show how many rules a policy has and how many models they route to without loading the rules.
Project owners can now manage fallback policies for their own project: creating, updating, deleting, activating and deactivating project- and API-key-scoped policies inside a project they own needs only the project owner's own grants.
Administrators can preview up to 12 UTC months of billable spend for a team, its highest-spending member, or an API key before creating a budget, with month/spend filters, sorting and pagination.
Budget policy reads now include the stored target client's name and, when spending is requested, the number of keys matching a tag budget.
tare CLI
tare doctor now checks a data plane's gateway authentication policies and reports one left behind by a deleted gateway, one whose settings would refuse API key traffic, one copying token claims into headers that a caller sending no token can set itself, two policies contending for one route, and a gateway already carrying as many identity providers as one policy accepts.
Bug fixes
Management plane API
Project-scoped traffic-split, fallback-chain and attribute routing policies now create and update successfully when no tag selector is supplied.
A fallback or traffic-split policy write with a missing or unrecognized target_scope_type now explains that unknown JSON names are ignored and names the target id fields to check.
Corporate SSO sign-in through the management API applies the identity provider's role mapping again: the provider's role claim path, mapping and sync mode set a user's role on every sign-in, reading the claim from the OIDC ID token, the OIDC userinfo response, or the SAML assertion.
The effective fallback-policy view now merges fallback entries per protected model across scopes and folds bound allow-lists over the merged set, matching what the data plane enforces.
GET /api/rbac/roles?includeApiScope=true also lists the roles an API key can hold, such as api_audit_logs_reader, so an administrator can see which scopes exist.
Deleting a project now also deletes its project fallback overrides, so a project created later with the same ID starts with none.
Gateway
Upgrading now keeps namespaces you added to gateway.config.envoyGateway.provider.kubernetes.watch.namespaces.
An MCP server that needs a credential now keeps working between configuration syncs. Available once the data plane is on 0.6.0 or later.
Claude Code passthrough keeps using the developer's own Claude login when they also have a bring-your-own Anthropic key. Available once the data plane is on 0.6.0 or later.
Guardrail metrics now reach your observability backend when observability and its metrics signal are enabled on the data plane; before, the guardrail filter recorded nothing. Available once the data plane is on 0.6.0 or later.
Release process
Candidate validation and the scheduled release-upgrade E2E now resolve a final release tag to the commit its images were built from and use that commit as the image coordinate, instead of reading it off the tag.
Consoles
Sign out in the Developer Console now removes the session cookie from the browser, so the next page load shows the sign-in page instead of failing or staying signed in.
After sign-out, the Admin Console no longer shows a signed-in super admin the member view; the session and permissions now both come from the management API.