v0.7.0
Released October 8, 2026. Supported until April 8, 2027.
v0.7.0 ships 40 behavior changes, 4 security updates, 47 new features, 35 bug fixes, and 7 deprecations. Behavior between the management plane and the data plane changed in this release. The most severe security issue cleared is high.
A fully detailed version of these release notes (including artifact versions) is included in the Admin Console.
Click here to learn how to bring up the full release notes.
Upgrade and rollback
- No breaking changes. No operator action is required before upgrading.
- The upgrade rolls through without dropping traffic.
- Rollback to v0.6.1 is conditional. See the note below.
Rolling back reverts the data plane workloads only; roll back with helm rollback. The Gateway API, Envoy Gateway and AI Gateway CRDs stay at this release's versions, which the previous release runs on unchanged. Do not re-apply the previous release's CRDs: the cluster refuses Gateway API CRDs older than v1.5. With GitOps, roll back the workload release and keep the CRD chart on this release. See "Rolling back from 0.7.0" in Upgrade a self-hosted data plane.
Behavior changes
Gateway
The data plane's AI Gateway routing configuration is capped by controller.filterConfigBundleMaxSlots in the AI Gateway chart, at 700 KiB per slot (16 slots, about 11 MiB, by default).
A data plane running 0.7.0 or later refuses a key on a hostname its project is not served from with one fixed message, saying the key's project is not served at that hostname. Available once the data plane is on 0.7.0 or later.
A request for a model that the Catalog switched off because its retirement date passed now gets 404 with code model_retired and the date in the message, plus the model to use instead when the Catalog names one (by model name) in metadata.replaced_by. Available once the data plane is on 0.7.0 or later.
The data plane now runs Envoy Gateway v1.9.1 and supports Kubernetes 1.33 to 1.36.
When tare (on a cluster without Gateway API, or with --force-gateway-api-crds) or the data plane CRD chart (crds.gatewayAPI: true) installs the Gateway API CRDs, it now also installs the safe-upgrade ValidatingAdmissionPolicy and ValidatingAdmissionPolicyBinding safe-upgrades.gateway.networking.k8s.io.
The data plane's router_* metrics on the egress Envoy Prometheus endpoint (:19001/stats/prometheus) now carry an envoy_dynamicmodulescustom_ prefix, for example envoy_dynamicmodulescustom_router_requests_total instead of router_requests_total.
The data plane now runs Envoy AI Gateway v1.1.0+g9945796, and every gateway pod restarts once during the upgrade.
Upgrading rolls every gateway proxy: the guardrails filter is now built with the rest of the data plane, so the gateway image tag changes.
A request refused by an API key's token rate limit now gets a rate_limit_exceeded error body naming the limit's window and retry_after_seconds, with a matching retry-after header, instead of an empty 429. Available once the data plane is on 0.7.0 or later.
Upgrading a data plane to 0.7.0 with untouched values keeps it answering its readiness probe on the address set for it through the admin API. Available once the data plane is on 0.7.0 or later.
A 0.7 data plane's /healthz readiness probe answers for the whole data plane rather than for one project gateway on it: 200 on every hostname its chart declares, or on its stored address while the chart declares none, as projects come and go. Available once the data plane is on 0.7.0 or later.
The gateway now removes the identity headers only it sets, such as x-tars-user and x-router-project-id, and every x-ai-eg-* and x-internal-traces-* header from every request a caller sends, including to /mcp and the OAuth endpoints. Available once the data plane is on 0.7.0 or later.
A fallback policy's retry delay is now the wait before each retry, clamped to 1-60 seconds, instead of the time each attempt had to start responding.
Archived request logs now carry their model parameters and attribute-routing decision into object storage with the request bodies, and the database copy is cleared once the hourly usage rollup has aggregated it.
The guardrails filter now answers to the filter name tars-guardrails as well as aidiscovery, so a later release can switch to the new name without a proxy rejecting its guardrails configuration.
Management plane API
Corporate SSO sign-in applies the provider's role sync mode before the session is issued, so a changed IdP role promotes or demotes the user on that sign-in.
A provider endpoint or key override now applies to one project on a data plane and names that project, so another project the same data plane serves keeps calling the provider with the bundle endpoint and credential. Available once the data plane is on 0.7.0 or later.
Listing data plane addresses with an inference key issued for a project other than default now returns only that project's addresses, where it used to return every address in the organization.
Once a data plane declares hostnames in its chart, these three calls accept only a hostname that data plane declared, and refuse anything else with FailedPrecondition naming the chart key.
Deleting a project now revokes the API keys scoped to it, rather than refusing while any of them is live.
A project gateway now holds several projects. Available once the data plane is on 0.7.0 or later.
Deleting a data plane now refuses while it is the only one serving a project, and the refusal names up to ten of those projects and reports how many there are in all.
A project owner now creates, edits and deletes the guardrails and guardrail rules of a project they own, without an organization-wide guardrails credential.
Creating a project over the tenancy API now refuses, with InvalidArgument, a project_id longer than 253 characters or one using anything other than lowercase letters, digits, hyphens, underscores and dots, or not starting and ending with a letter or digit.
The call that lists a data plane's hostnames now returns its stored address while its chart declares none: the address set through SetDataplaneURL, then its project gateway URLs.
Creating a gateway auth policy, or changing its jwks_uri, is now refused when the jwks_uri carries a user name or password, writes an IPv4 address as anything other than a dotted quad, or names or resolves to a carrier-grade NAT, multicast, reserved or other internal address.
Creating a gateway auth policy, or changing its jwks_inline key set, is now refused when the key set holds more than 32 keys or more than 16 KiB.
Creating an identity mapping rule now refuses a jit_project_id that is not a project of the policy's customer or is not attached to the policy's gateway, a jit_principal_cap on a pre_registered rule, and a jit rule whose principal_type is not external.
Creating a gateway auth policy, or changing its extraction_header, is now refused unless the gateway can remove that header after verifying the token, which rules out the identity headers the gateway sets and credential headers such as x-api-key, cookie and proxy-authorization.
Saving an SSO provider with role sync set to strict is refused when the provider is SAML, has no usable role mapping (a role claim path and at least one entry), or names no recovery administrator.
Helm charts
Upgrading the management plane no longer pauses request logging while the database builds this release's new request log index.
The management plane applies pending database migrations when its app pods start, so an upgrade that only rolls images no longer runs new code against an old schema.
Consoles
Integration examples use the configured project endpoint, falling back to the selected gateway URL when unset and showing a placeholder when neither URL is available.
The model catalog lists first-party providers first, then the newest models.
The Admin Console reaches a project only through the data planes that serve it.
The Developer Console now holds back the base URL, the code samples and the integration snippets for a project no data plane serves, and says the project is ready but nothing is callable until a platform administrator labels a data plane with it.
tare CLI
Images built from this repo now carry the chart's version string as their tag, so a running pod maps back to its release without the release manifest.
tare doctor now reports an ERROR for a serving TLS certificate that is not valid yet, alongside the expired and expiring readings it already gave.
Observability
Guardrail trigger logs sent to a custom observability backend now carry service.name tars-guardrails (previously aidiscovery).
Release process
A minor release can now be cut from a release/X.Y branch: the branch tip whose version is X.Y.0 moves the internal latest pointer, soaks for the full window, is validated by an e2e run taken from the candidate's own commit, promotes against the highest prior final of any line, and closes out on main.
Security updates
Management plane API
Project-scoped attribute-routing reads now stay within the authorized project, so callers can no longer view another project's routing rules, condition values, or policy target identifiers such as target_api_key_id.
Consoles
Test connection, and running tools from the Developer Console, on an OAuth 2.0 MCP server no longer send the OAuth client ID, client secret, the user's refresh token or the token URL to the MCP server.
Auth
With corporate login on, the management plane's OIDC, SAML, CLI, Google and GitHub sign-in paths now refuse an email domain not in global.corporate.emailDomains before creating a user; the existing corporate-login path already enforced that allowlist.
Revoking a user's super admin role, or lowering a user's role through SSO role sync, now also removes the platform administrator access and the access to edit the global provider catalog that the old role gave, unless a role the user still holds grants it.
New features
Management plane API
A new call counts one project's requests on each of several data planes in one request, naming the project rather than every API key it holds.
Catalog model lists can be paged with page, and support search, mode, modality, context-window and price filters, sorting and snapshot grouping.
A data plane now reports each whitelisted field on which it serves something other than the bundle the management plane sent, with both values, and a project reports the fields its data planes disagree on.
GetProjectDeletionImpact reads what deleting a project costs, and how far a delete under way has got.
DeleteProject now answers with the data planes whose label for the project it removed, so a caller confirming a delete reads the affected fleet out of the delete's own response rather than a follow-up call.
The API call that lists the hostnames a data plane declares now carries the certificate reading beside each address: whether it covers that address, how long it has left, the issuer, the fingerprint, the names it carries, where the reading was taken from, the address the handshake reached and whether that is the data plane's own gateway or a proxy. Available once the data plane is on 0.7.0 or later.
You can now ask which data planes serve a project.
A data plane can now be labeled with the projects it serves, naming a data plane and a project rather than a gateway. Available once the data plane is on 0.7.0 or later.
Each project label now says when that data plane first answered a request for the project successfully, in a new verified_at field.
A rate-limit policy now carries a display_name, the public label a caller will see when that limit refuses a request.
An administrator can now give one project on one data plane its own endpoint or its own key for one provider, and every other project that data plane serves goes on calling the provider with the bundle endpoint and credential. Available once the data plane is on 0.7.0 or later.
You can now author a guardrail, a guardrail rule, a guardrail provider and a pattern for a whole organization rather than one project at a time.
A project now reads the organization's guardrails alongside its own, and every guardrail, pattern and provider reports the level it sits at.
A project's effective guardrail stack now reads as one list carrying both levels.
A guardrail apply can now state what it reconverges before you confirm it: how many projects it changes, how many distinct data planes re-pull, and how many of those projects are served nowhere.
A candidate guardrail rule can now be tested against a project's stack before it takes traffic.
Rollout progress now reads per data plane as a fraction of its labeled projects, and rolls up to a fleet figure such as 7 of 9 that counts a data plane only when every project on it holds its current revision.
You can now resolve a set of data planes to the projects served from them, so a region-bound rule attaches to those projects rather than to the infrastructure.
A project's gateway members now come back with where the project stands across the data planes serving it: the revision last minted for its configuration, how many labeled data planes have confirmed that revision, and how many carry the label at all.
Forgetting a data plane now leaves a zeroize directive waiting for it and soft-deletes its credential.
A project can now publish an OIDC contract, naming the issuer that mints its tokens, the audience and scope they must carry and an optional entitlement.
The management plane refuses to fetch an OIDC issuer's discovery document from a non-public address: loopback, link-local, private, carrier-grade NAT, unique-local, unspecified, or another range reserved from public routing, such as benchmarking.
GetBudgetConsumption reports what an Organization, or each project inside it, has consumed in the current period, in spend and in tokens, with the budget set at that scope when there is one.
A data plane can now repair itself when its doctor reports RBAC objects or CRDs its chart declares as missing or changed, writing back what the chart says. Available once the data plane is on 0.7.0 or later.
A project gateway can now declare the environment it serves in environment, and a gateway auth policy can name the token claim carrying a token's environment in environment_claim. Available once the data plane is on 0.7.0 or later.
A project's membership of a project gateway now accepts ACCEPTED_CREDENTIALS_TOKEN on Enterprise, so the gateway refuses API keys for that project and accepts only IdP tokens. Available once the data plane is on 0.7.0 or later.
Gateway
A data plane now builds one provider backend and security policy per project that has a provider override, so a request resolves the backend of the project its key names. Available once the data plane is on 0.7.0 or later.
The request log now records each request an API key's token rate limit refused, under llm_parameters.rate_limit: the limit, its window, the retry hint and the policy's label, plus the policy, scope and dimension when one ceiling is unambiguous. Available once the data plane is on 0.7.0 or later.
A data plane now reports its version each time it asks for configuration, and the management plane records it. Available once the data plane is on 0.7.0 or later.
Hosting several projects on one hostname now gives each project its own view of what that hostname serves: its own models, and its own MCP servers and profiles, rather than one project's configuration replacing another's. Available once the data plane is on 0.7.0 or later.
A data plane declares the hostnames it serves under global.gateway.hostnames in its serve-helm values and reports them to the management plane, which lists them read-only and lets a project select one. Available once the data plane is on 0.7.0 or later.
A data plane now reads the certificate serving each hostname its chart declares and reports what it found: the subject alternative names, the issuer, the fingerprint, the validity window, the address the handshake reached and the vantage point the reading came from. Available once the data plane is on 0.7.0 or later.
The management plane can now check every data plane's whitelisted configuration against the bundle it sent and against the other data planes serving each project, and it reports the result as a ConfigurationExplained condition on the data plane.
Admins can route project requests by caller-supplied X-Tars-Metadata values, with a default model when no rule matches. Available once the data plane is on 0.7.0 or later.
The serve chart can install an opt-in NetworkPolicy, off by default, that stops the gateway proxy pods from connecting to internal addresses outside the cluster, such as cloud metadata and RFC 1918 ranges.
A gateway's auth policies, identity mapping rules and each project's accepted credentials now reach every data plane serving the gateway, where they show in the Envoy config dump and in a gateway auth config loaded log line on each reload. Available once the data plane is on 0.7.0 or later.
Applications without an Agent Router API key can call models with a token from their own identity provider, sent in Authorization: Bearer with x-tars-project and verified against that project's gateway auth policy. Available once the data plane is on 0.7.0 or later.
tare CLI
tare doctor now checks the certificate serving this data plane against the hostnames the chart declares under gateway.hostnames, and warns for a declared name it does not cover.
Consoles
Each project label on a data plane's page now shows its progress in three steps: label applied, config pulled with the revision the data plane holds and the one it picks up next, and verified with when it first answered a request for that project.
Admin Console project screens now describe a project in the labels model: data planes carry its label and report the address apps call.
The Developer Console no longer shows a gateway id beside each MCP endpoint, the model picker says the data plane routes a model, and the API reference asks for the Agent Router API address.
The Developer Console lists the endpoints your project is served from, in place of the data plane picker it used to offer.
A project owner can star one of the addresses serving their project, and the console prints it wherever it shows a Base URL: the getting-started card, the worked example beside a new key and the model catalog bar.
Request logs label attribute routing as "Routing rule" or "Routing default", separate from "Budget fallback" and "Provider fallback", and show the routed model when a fallback then moved the request off it.
Guardrails
Every guardrail rule now carries a reference, a short read-only id such as GR-0142 that the database mints once and never rewrites.
A guardrail trigger now reports one verdict for the whole event, which is blocked, redacted or would-have, resolved from its rule evaluations so an enforced block outranks an enforced redact and either outranks a monitor-mode hit that changed nothing.
Data plane
An application holding a token from your own identity provider can now call a project, by sending X-TARS-PROJECT-ID with the project's name alongside the token; an API key names one project already and needs no header. Available once the data plane is on 0.7.0 or later.
Bug fixes
Management plane API
Older management keys owned by an Organization admin without platform admin keep write, request log, metrics, user directory and guardrail access within their Organization, the same as newer keys, instead of dropping to read-only.
Removing the last project from a data plane that has a single gateway now takes the project's label off, reports served_nowhere and records PROJECT_SERVED_NOWHERE in the audit log.
Removing a project from a data plane now takes the label off even when the data plane's configuration update fails, so a response with removed=true no longer lists the label it removed.
Looking up a data plane address with an inference key now returns the key's own project's address on a data plane serving several projects, where it used to answer 400.
Listing attribute routing policies now rejects a scope_types or statuses filter it cannot apply, instead of ignoring it and returning a broader list than requested.
Deleting a project that shares a gateway with another project no longer stops that gateway serving the other project, and the deletion receipt now reports the data plane as cleared as soon as the data plane acknowledges configuration that no longer carries the deleted project.
Gateway
Labelling the first project on a data plane that serves no project no longer restarts the data plane's gateway, which answered 500 to the project's requests for up to a minute while it restarted.
A data plane now picks up a re-issued credential without restarting its gateway.
Fallback retries now apply only to the models a fallback policy covers.
A request that falls back to a gpt-5 or o-series model with max_tokens or max_completion_tokens set now succeeds instead of returning 400 unsupported_parameter, and x-model-effective names the fallback model on an upstream error.
An MCP profile change reaches its gateways in about a minute instead of waiting for the next half-hourly sync.
Connecting, disconnecting or refreshing an OAuth login for an MCP server now asks your project's gateways to rebuild straight away, instead of leaving the change to wait for the half-hourly sync.
Upgrading or installing the data plane no longer fails and rolls back on a cluster whose Gateway API is already fine; the version check misread the Envoy Gateway release from its image tag.
Attribute-based routing policies now take effect on the data plane without a restart.
Attribute-based routing policies scoped to an API key now work even when the project has no project-wide policy, so matching callers receive the configured routing and model rewrite.
Attribute routing can now target a specific provider when several providers serve the same model name.
Attribute-based routing now applies rules and defaults that name models such as gpt-4o-mini or gpt-4.1-mini on /v1/chat/completions and /v1/messages. Available once the data plane is on 0.7.0 or later.
GET /v1/status now answers from your own project's requests. Available once the data plane is on 0.7.0 or later.
The status endpoints now report the state of the hostname you called. Available once the data plane is on 0.7.0 or later.
Revoking a bring-your-own provider key now removes its stored credential from the data plane every time. Available once the data plane is on 0.7.0 or later.
Request logs no longer keep an IdP token from a gateway auth policy's extraction header, whether the request authenticates with that token or with an API key.
Consoles
The Playground and the console's Base URL now reach a data plane through its stored data plane URL when the data plane's default gateway has no URL of its own, instead of refusing with "serves on no known address".
A data plane whose health report carries only warnings now shows as Degraded in amber and counts as healthy on the data plane list, instead of showing as Unhealthy.
Model details are shown only for models available in the selected project, and the model list shows configured model names, Auto Fallback badges and alias grouping again.
Saving an attribute routing rule with an eq or ne condition on more than one value is now refused.
Project access checks now follow directory permissions without exposing member details.
Audit activity now follows the platform's administrator access controls.
MCP analytics now record calls for every MCP profile.
Data plane
The data plane Controller now requests 128Mi of memory instead of 64Mi, so its autoscaler no longer scales it out to maxReplicas under normal load and tare doctor no longer reports the data plane Degraded for exhausted autoscaling headroom.
tare CLI
tare install --image-sync --include-manage-images now mirrors all management-plane images required by the selected chart, so a management plane installed from a mirrored registry no longer leaves workloads unable to pull their images.
tare install --image-sync and tare upgrade --image-sync now mirror every data-plane image required by the selected chart at the tags it deploys, so a registry populated only by --image-sync no longer leaves workloads in ImagePullBackOff.
--chart-version now reads the fetched chart's own image tags, instead of falling back to the CLI's build.
Auth
Authentication role checks now stay aligned across shared databases during internal upgrades.
An administrator who signs in through single sign-on on a deployment with one organization now gets platform administrator access at once, so the model catalog, the MCP catalog and user creation no longer answer 403 until the management plane restarts.
Corporate login setup now accepts an OIDC client that only allows the browser sign-in flow.
Deprecations
Gateway
The guardrails filter now reads its OTLP exporter settings from TARS_GUARDRAILS_OTEL_EXPORTER_OTLP_* variables.
The egress.gateway.listeners Helm value is deprecated: the chart now provides the gateway's listener on port 10080 itself, because the gateway depends on that listener's name and port.
The your_hostnames list on the 403 a data plane sends when a key calls a hostname its project is not served from is deprecated, and 0.8.0 removes it.
The data_plane field in the status endpoint responses is deprecated and will be removed in v0.7.0. Available once the data plane is on 0.7.0 or later.
Management plane API
A project owner attaching a project to a gateway, detaching one or deleting a gateway is deprecated, and 0.9.0 requires a platform administrator for all three.
Setting a data plane's or a project gateway's address through the admin API is deprecated.
A catalog model list that sets only provider_id or include_disabled still returns the full catalog, but is deprecated and will return one page in a later release.