v16.5.14

gravitational/teleportv16.5.14Jul 25, 2025by fheinecke

AI Summary

Teleport v16.5.14 is a patch release focused on bug fixes and minor improvements. Key fixes include web login second factor fallback, MacOS install script errors, and tbot SPIFFE SVID renewal issues. The release also adds a new `--listen` flag to `tsh proxy db` and updates Go to 1.23.11.

Key Highlights

  • Fixed web login fallback when second factor is set to 'on' but only OTP is configured
  • Added `--listen` flag to `tsh proxy db` for setting local listener address
  • Updated Go to 1.23.11 for improved performance and security
  • Fixed Teleport install scripts on MacOS to error instead of trying non-existing FIPS binaries
  • Fixed tbot SPIFFE Workload API failing to renew SPIFFE SVIDs

New Features

  • Added `--listen` flag to `tsh proxy db` for setting local listener address
  • tctl top now supports the local unix sock debug endpoint
  • Application APIs now use pagination to avoid exceeding message size limitations
  • Added support for Azure CLI version 2.73.0 and newer in tsh App Access commands

Full Release Notes

## Description

* Fixed fallback for web login when second factor is set to `on` but only OTP is configured. [#57160](https://github.com/gravitational/teleport/pull/57160)
* Removed unnecessary macOS entitlements from Teleport Connect subprocesses. [#57068](https://github.com/gravitational/teleport/pull/57068)
* Added `--listen` flag to `tsh proxy db` for setting local listener address. [#57032](https://github.com/gravitational/teleport/pull/57032)
* `tctl top` now supports the local unix sock debug endpoint. [#57026](https://github.com/gravitational/teleport/pull/57026)
* Updated Application APIs to use pagination to avoid exceeding message size limitations. [#56954](https://github.com/gravitational/teleport/pull/56954)
* Added support to `tsh` App Access commands for Azure CLI (`az`) version `2.73.0` and newer. [#56950](https://github.com/gravitational/teleport/pull/56950)
* Fixed a bug in the Teleport install scripts when running on MacOS. The install scripts now error instead of trying to install non existing MacOS FIPS binaries. [#56943](https://github.com/gravitational/teleport/pull/56943)
* Update pyroscope's default client timeout and upload rate. [#56733](https://github.com/gravitational/teleport/pull/56733)
* Updated Go to 1.23.11. [#56681](https://github.com/gravitational/teleport/pull/56681)
* Fix tbot SPIFFE Workload API failing to renew SPIFFE SVIDs. [#56664](https://github.com/gravitational/teleport/pull/56664)
* Fixed error on setting up Teleport Discovery Service step of the EC2 SSM web UI flow when admin action is enabled (webauthn). [#56571](https://github.com/gravitational/teleport/pull/56571)

## Download
Download the current and previous releases of Teleport at https://goteleport.com/download.

## Plugins

Download the current release of Teleport plugins from the links below.
* Slack [Linux amd64](https://cdn.teleport.dev/teleport-access-slack-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-slack-v16.5.14-linux-arm64-bin.tar.gz) 
* Mattermost [Linux amd64](https://cdn.teleport.dev/teleport-access-mattermost-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-mattermost-v16.5.14-linux-arm64-bin.tar.gz)
* Discord [Linux amd64](https://cdn.teleport.dev/teleport-access-discord-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-discord-v16.5.14-linux-arm64-bin.tar.gz)
* Terraform Provider [Linux amd64](https://cdn.teleport.dev/terraform-provider-teleport-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/terraform-provider-teleport-v16.5.14-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/terraform-provider-teleport-v16.5.14-darwin-amd64-bin.tar.gz) | [macOS arm64](https://cdn.teleport.dev/terraform-provider-teleport-v16.5.14-darwin-arm64-bin.tar.gz) | [macOS universal](https://cdn.teleport.dev/terraform-provider-teleport-v16.5.14-darwin-universal-bin.tar.gz)
* Event Handler [Linux amd64](https://cdn.teleport.dev/teleport-event-handler-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-event-handler-v16.5.14-linux-arm64-bin.tar.gz) | [macOS amd64](https://cdn.teleport.dev/teleport-event-handler-v16.5.14-darwin-amd64-bin.tar.gz)
* PagerDuty [Linux amd64](https://cdn.teleport.dev/teleport-access-pagerduty-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-pagerduty-v16.5.14-linux-arm64-bin.tar.gz)
* Jira [Linux amd64](https://cdn.teleport.dev/teleport-access-jira-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-jira-v16.5.14-linux-arm64-bin.tar.gz)
* Email [Linux amd64](https://cdn.teleport.dev/teleport-access-email-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-email-v16.5.14-linux-arm64-bin.tar.gz)
* Microsoft Teams [Linux amd64](https://cdn.teleport.dev/teleport-access-msteams-v16.5.14-linux-amd64-bin.tar.gz) | [Linux arm64](https://cdn.teleport.dev/teleport-access-msteams-v16.5.14-linux-arm64-bin.tar.gz)