Skip to main content

v0.2.1

Released September 4, 2026. Supported until March 4, 2027.

v0.2.1 is a security patch on top of v0.2.0. Every data plane and management plane image is rebuilt on updated Go dependencies and a patched Go toolchain to clear reported vulnerabilities. Only dependency and toolchain versions change: the release carries no source, API, configuration, or behavior change, and contains no new features, bug fixes, or deprecations.

About these release notes

A fully detailed version of these release notes (including artifact versions) is included in the Admin Console.

Click here to learn how to bring up the full release notes.

Upgrade and rollback​

  • No breaking changes. No operator action is required before upgrading.
  • The upgrade rolls through without dropping traffic.
  • Rollback to v0.2.0 is unconditional.

Security updates​

Data plane images​

The gateway, the rate limit service, the AI gateway controller and its ext-proc, and the bundled kubectl and helm are rebuilt to clear reported vulnerabilities in their bundled Go dependencies:

Management plane and CLI images​

The management plane components, the tare CLI and liaison images, and the berglas secret resolver are rebuilt on updated golang.org/x/crypto, golang.org/x/net, golang.org/x/text, golang.org/x/mod (CVE-2026-56864, CVE-2026-56865), and google.golang.org/grpc, and on a patched Go toolchain that clears the Go standard library CVEs.

Telemetry​

The bundled OpenTelemetry collector image is updated to clear a high-severity issue in Apache Thrift (CVE-2026-43871).

Known issues​

Gateway​

A budget on a single API key does not survive a rotation of that key. The budget stays bound to the retired credential, so the replacement key runs with no budget while the policy still lists as active, and nothing warns that enforcement has stopped. On this release a key budget is unreliable on any credential with a rotation schedule, and the interim options are described under budget cap limitations and workarounds. Fixed in v0.3.0, where a key budget binds to the client behind the key and follows the rotation to the replacement key.